oshp / oshp-validator
Venom tests suite to validate an HTTP security response headers configuration against OSHP recommendation.
☆108Updated last month
Alternatives and similar repositories for oshp-validator:
Users that are interested in oshp-validator are comparing it to the libraries listed below
- ☆110Updated last year
- boostsecurityio/lotp☆111Updated last month
- The OWASP Secure Headers Project☆145Updated this week
- ☆122Updated last year
- ☆74Updated last year
- An open-source collection of API key rotation tutorials.☆63Updated last month
- drHEADer helps with the audit of security headers received in response to a single request or a list of requests.☆110Updated 3 weeks ago
- 🖇️ STRIDE vs. ASVS equivalence table☆75Updated 5 months ago
- A Broken Application - Very Vulnerable!☆137Updated last week
- OWASP Foundation Web Respository☆19Updated 3 weeks ago
- Nuclei plugins to audit Chrome extensions☆64Updated 6 months ago
- A blazing-fast, thread-safe, straightforward and zero memory allocations tool to swiftly generate alternative IP(v4) address representati…☆85Updated last year
- A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.☆111Updated this week
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆98Updated 2 months ago
- The Pixi module is a MEAN Stack web app with wildly insecure APIs!☆119Updated 2 years ago
- The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use …☆62Updated 7 months ago
- NextJS-based single-page application for completing and reviewing SAMM assessments☆70Updated last year
- Find secrets in your codebase☆122Updated 3 weeks ago
- ☆161Updated 4 months ago
- ☆91Updated 2 months ago
- Security Auditor Utility for GraphQL APIs☆409Updated this week
- API Security Vulnerability Scanner designed to help you secure your APIs.☆110Updated this week
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆113Updated last year
- ☆82Updated 3 years ago
- A small tool to help developers understand a huge set of security requirements from appsec teams☆45Updated 2 years ago
- A tool to scrape the AWS ranges looking for a keyword in SSL certificate data.☆229Updated last year
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆266Updated 2 months ago
- Web Application Security Checklist☆121Updated 3 years ago
- Recon tool for cloud provider attribution. Supports AWS, Azure, Google, Cloudflare, and Digital Ocean.☆164Updated 3 months ago
- Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.☆267Updated 4 months ago