The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
-
Updated
Apr 4, 2026 - Python
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Web path scanner
Open Source Vulnerability Management Platform
w3af: web application attack and audit framework, the open source web vulnerability scanner.
CTF challenge (mostly pwn) files, scripts etc
OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)
Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and Git friendly.
A library for detecting known secrets across many web frameworks
MCP server for AI-driven security pipelines
Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.
Open Source Static Scanning tool to detect data flows in your code, find data security vulnerabilities & generate accurate Play Store Data Safety Report.
This project is about creating and publishing threat model examples.
Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).
A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It supports dynamic payload generation, including BCheck syntax, and can automatically generate Bambdas scripts. Additionally, it offers "Copy as JavaScript" to convert HTTP requests for enhanced XSS testing.
AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)
Threat Designer is a GenerativeAI application designed to automate and streamline the threat modeling process for secure system design.
Python Interactive Deepweb-oriented Rapid Intelligent Link Analyzer
Add a description, image, and links to the appsec topic page so that developers can more easily learn about it.
To associate your repository with the appsec topic, visit your repo's landing page and select "manage topics."