we45 / DVFaaS-Damn-Vulnerable-Functions-as-a-Service
Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities
☆135Updated last year
Related projects: ⓘ
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆132Updated 4 years ago
- A tool geared towards pentesting APIs using OpenAPI definitions.☆167Updated last year
- drHEADer helps with the audit of security headers received in response to a single request or a list of requests.☆105Updated this week
- Damn Vulnerable Cloud Application☆183Updated 6 years ago
- 🖇️ STRIDE vs. ASVS equivalence table☆74Updated 3 weeks ago
- GraphQL security testing tool☆113Updated 2 years ago
- The Pixi module is a MEAN Stack web app with wildly insecure APIs!☆110Updated last year
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆74Updated 2 years ago
- Cloud-related research releases from the Rhino Security Labs team.☆350Updated 4 years ago
- This is an offensive guide to securing AWS infrastructures. The hope is that by knowing how to take advantage of various types of AWS wea…☆166Updated 5 years ago
- Corsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).☆122Updated last year
- Fetch the details of assets hosted on AWS.☆85Updated 9 months ago
- ☆60Updated last year
- Some good resources for getting started with application security☆133Updated 3 years ago
- ☆222Updated 2 months ago
- Fast and stealthy Amazon S3 bucket enumeration tool for pentesters.☆215Updated 3 months ago
- This repo gives an overview of some GCP metadata API attack and defend patterns☆76Updated 4 years ago
- Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki☆201Updated 2 years ago
- A collection of response templates for invalid bug bounty reports.☆90Updated 6 years ago
- Repository for all the workshop content delivered at nullcon X on 1st of March 2019☆80Updated 5 years ago
- materials we hand out☆127Updated last week
- vulnerable single sign on☆144Updated last month
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆138Updated 3 years ago
- Presentations, training modules, and other education materials from Duo Security's Application Security team.☆69Updated 3 years ago
- Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.☆75Updated 3 years ago
- Intentionally Vulnerable Flask app for use in Demos☆28Updated 3 months ago
- Curated list of public penetration testing reports released by several consulting firms☆45Updated 6 years ago
- GCP GOAT is the vulnerable application for learn the GCP Security☆61Updated 11 months ago
- Damn Vulnerable Java (EE) Application☆129Updated 7 months ago
- OWASP Cloud Security - Enabling conversations through threat and control stories☆175Updated 5 years ago