oshp / oshp-validatorLinks
Venom tests suite to validate an HTTP security response headers configuration against OSHP recommendation.
☆137Updated 2 weeks ago
Alternatives and similar repositories for oshp-validator
Users that are interested in oshp-validator are comparing it to the libraries listed below
Sorting:
- The OWASP Secure Headers Project☆177Updated this week
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆228Updated 3 weeks ago
- A Broken Application - Very Vulnerable!☆177Updated last week
- A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Sec…☆305Updated 3 months ago
- Docker toolbox for pentest of web based application.☆172Updated this week
- Security Auditor Utility for GraphQL APIs☆553Updated 3 weeks ago
- A humble, and 𝗳𝗮𝘀𝘁, security-oriented HTTP headers analyzer.☆348Updated this week
- ☆124Updated 2 years ago
- Runs a scan using Dastardly by Burp Suite against a target site and creates a JUnit XML report for the scan on completion.☆291Updated last year
- Secret Magpie - Secret Detection Tool☆246Updated last year
- The Pixi module is a MEAN Stack web app with wildly insecure APIs!☆134Updated 2 years ago
- A collection of awesome AWS S3 tools that collects and enumerates exposed S3 buckets☆397Updated last week
- ☆85Updated 2 years ago
- OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions☆104Updated 2 years ago
- SessionProbe is a multi-threaded tool designed for penetration testing and bug bounty hunting. It evaluates user privileges in web applic…☆462Updated last year
- GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations☆334Updated 5 months ago
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆314Updated 2 months ago
- BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for c…☆433Updated 3 weeks ago
- OWASP Code Review Guide Web Repository☆146Updated 3 years ago
- Websec interview questions by tib3rius answered☆308Updated 2 years ago
- GraphQL automated security testing toolkit☆332Updated last year
- Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.☆278Updated last year
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆121Updated 2 years ago
- openrisk is a tool that generates a risk score based on the results of a Nuclei scan.☆180Updated last week
- Host and manage multiple Juice Shop instances for security trainings and Capture The Flags☆301Updated this week
- A tool to scrape the AWS ranges looking for a keyword in SSL certificate data.☆236Updated last year
- 🕸️ Blazing fast GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce. 🕸️☆223Updated 2 years ago
- OWASP Project Developer Guide - Document and Project Web pages☆114Updated last week
- OWASP Foundation Web Respository☆22Updated 2 months ago
- S3 Account Search☆28Updated 4 months ago