oshp / oshp-validator
Venom tests suite to validate an HTTP security response headers configuration against OSHP recommendation.
☆100Updated last month
Related projects ⓘ
Alternatives and complementary repositories for oshp-validator
- OWASP Foundation Web Respository☆19Updated last month
- OWASP Code Review Guide Web Repository☆122Updated 2 years ago
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆196Updated last month
- A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Sec…☆274Updated 7 months ago
- The OWASP Secure Headers Project☆135Updated this week
- Security Auditor Utility for GraphQL APIs☆384Updated 2 months ago
- A Broken Application - Very Vulnerable!☆131Updated last week
- boostsecurityio/poutine☆232Updated this week
- ☆121Updated last year
- 🧮 An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessment☆152Updated 3 years ago
- Find secrets in your codebase☆119Updated 2 weeks ago
- drHEADer helps with the audit of security headers received in response to a single request or a list of requests.☆105Updated 3 weeks ago
- ☆110Updated last year
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.☆104Updated 10 months ago
- ☆71Updated last year
- boostsecurityio/lotp☆101Updated 7 months ago
- Check any website (or set of websites) for insecure security headers.☆245Updated last year
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆110Updated last year
- The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use …☆61Updated 5 months ago
- Python script to check HTTP security headers☆59Updated 3 weeks ago
- Damn Vulnerable Java (EE) Application☆130Updated 9 months ago
- OWASP Domain Protect - prevent subdomain takeover☆398Updated last month
- A small tool to help developers understand a huge set of security requirements from appsec teams☆45Updated 2 years ago
- GCP GOAT is the vulnerable application for learn the GCP Security☆62Updated last year
- ☆75Updated 2 years ago
- Discover vulnerabilities and container image misconfiguration in production environments.☆53Updated 2 months ago
- A tool to quickly do keyword searches over Gitlab and Github for OSINT & bug bounty recon☆228Updated last year
- OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions☆104Updated last year
- Docker toolbox for pentest of web based application.☆141Updated this week
- A tool to uncover undocumented APIs from the AWS Console.☆83Updated this week