owasp-change / owasp-change.github.ioLinks
An Open Letter to the OWASP Board
☆107Updated 2 years ago
Alternatives and similar repositories for owasp-change.github.io
Users that are interested in owasp-change.github.io are comparing it to the libraries listed below
Sorting:
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆229Updated 2 weeks ago
- A project to visualize the software supply chain☆58Updated 2 years ago
- Holds the public Hacking the Cloud CTFs.☆63Updated last year
- An open-source collection of API key rotation tutorials.☆76Updated 5 months ago
- This repo scans pypi for AWS keys☆106Updated last year
- ☆114Updated 2 years ago
- Private key usage verification☆432Updated 10 months ago
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆159Updated last year
- Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration☆304Updated 2 weeks ago
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.☆35Updated last month
- Vandalize old emails. Like an NFT that's easy to prove ownership of.☆35Updated 2 years ago
- Cracking the Security Engineer Interviews☆55Updated 3 years ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆139Updated 4 years ago
- boostsecurityio/lotp☆138Updated 2 weeks ago
- 🖇️ equivalence table between OWASP ASVS standard and STRIDE threat modeling methodology.☆76Updated last year
- boostsecurityio/poutine☆361Updated last week
- An open source intelligence tool to crawl the graph of certificate Alternate Names☆366Updated 5 months ago
- drHEADer helps with the audit of security headers received in response to a single request or a list of requests.☆112Updated last year
- Minimum Viable Secure Product mvsp.dev☆204Updated last year
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆42Updated last year
- A small collection of potentially useful contract templates☆418Updated last month
- Venom tests suite to validate an HTTP security response headers configuration against OSHP recommendation.☆138Updated 2 weeks ago
- Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.☆278Updated last year
- Host and manage multiple Juice Shop instances for security trainings and Capture The Flags☆308Updated this week
- AI featured threat modeling and security review action☆45Updated last year
- a hackbot proof-of-concept☆41Updated last year
- A small tool to help developers understand a huge set of security requirements from appsec teams☆46Updated 3 years ago
- A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Sec…☆319Updated 5 months ago
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆122Updated 2 years ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆142Updated 11 months ago