An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with appsec

A curated list of projects in awesome lists tagged with appsec .

https://github.com/owasp/cheatsheetseries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

application-security appsec best-practices cheatsheets code owasp security

Last synced: 02 Mar 2026

https://github.com/OWASP/CheatSheetSeries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

application-security appsec best-practices cheatsheets code owasp security

Last synced: 12 Mar 2025

https://github.com/chaitin/safeline

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

api-gateway application-security appsec blueteam bruteforce captcha cve cybersecurity firewall hackers http-flood security self-hosted sql-injection vulnerability waf web-application-firewall web-security websecurity xss

Last synced: 14 May 2025

https://github.com/chaitin/SafeLine

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

api-gateway application-security appsec blueteam bruteforce captcha cve cybersecurity firewall hackers http-flood security self-hosted sql-injection vulnerability waf web-application-firewall web-security websecurity xss

Last synced: 25 Mar 2025

https://github.com/juice-shop/juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

24pullrequests application-security appsec ctf hacking hacktoberfest javascript owasp owasp-top-10 owasp-top-ten pentesting security vulnapp vulnerable

Last synced: 13 May 2025

https://bkimminich.github.io/juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

24pullrequests application-security appsec ctf hacking hacktoberfest javascript owasp owasp-top-10 owasp-top-ten pentesting security vulnapp vulnerable

Last synced: 20 Mar 2025

https://github.com/owasp/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

application-security appsec best-practices bugbounty guide hacking hacktoberfest owasp penetration-testing pentesting security

Last synced: 24 Feb 2026

https://github.com/OWASP/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

application-security appsec best-practices bugbounty guide hacking hacktoberfest owasp penetration-testing pentesting security

Last synced: 30 Mar 2025

https://github.com/owasp/go-scp

Golang Secure Coding Practices guide

appsec golang

Last synced: 14 May 2025

https://github.com/OWASP/Go-SCP

Golang Secure Coding Practices guide

appsec golang

Last synced: 01 Apr 2025

https://github.com/jassics/security-study-plan

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...

api-security application-security appsec appsec-tutorials aws-security azure-security cybersecurity cybersecurity-education devsecops-university gcp-security infosec pentesting security-testing study-guide study-plan study-planner

Last synced: 09 Feb 2026

https://github.com/andresriancho/w3af

w3af: web application attack and audit framework, the open source web vulnerability scanner.

appsec cross-site-scripting scanner security sql-injection

Last synced: 14 May 2025

https://github.com/projectdiscovery/interactsh

An OOB interaction gathering server and client library

appsec bugbounty dns golang hacktoberfest http ldap oast oob security smtp

Last synced: 12 Nov 2025

https://github.com/openziti/ziti

The parent project for OpenZiti. Here you will find the executables for a fully zero trust, application embedded, programmable network @OpenZiti

appsec golang mesh netsec network networking overlay overlay-network secure-networking vpn vpn-2 zero-trust zero-trust-cloud zero-trust-network zero-trust-network-access zero-trust-security zerotrust ztaa ztha ztna

Last synced: 02 Apr 2026

https://github.com/foospidy/payloads

Git All the Payloads! A collection of web attack payloads.

appsec cybersecurity hacking passwords payload payloads pentest sqli web-attack-payloads xss

Last synced: 14 May 2025

https://github.com/dependencytrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

appsec bill-of-materials bom component-analysis cyclonedx devsecops hacktoberfest nvd ossindex owasp package-url purl sbom sca security security-automation software-composition-analysis software-security vulnerabilities vulnerability-detection

Last synced: 12 Jun 2026

https://github.com/DependencyTrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

appsec bill-of-materials bom component-analysis cyclonedx devsecops hacktoberfest nvd ossindex owasp package-url purl sbom sca security security-automation software-composition-analysis software-security vulnerabilities vulnerability-detection

Last synced: 30 Mar 2025

https://github.com/cider-security-research/cicd-goat

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

appsec cicd ctf devops devsecops gitlab infosec jenkins security

Last synced: 04 Apr 2025

https://github.com/Checkmarx/kics

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

appsec cloudnative devsecops golang hacktoberfest iac infrastructure-as-code open-policy-agent security security-tools vulnerability-detection vulnerability-scanners

Last synced: 14 Mar 2025

https://github.com/checkmarx/kics

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

appsec cloudnative devsecops golang hacktoberfest iac infrastructure-as-code open-policy-agent security security-tools vulnerability-detection vulnerability-scanners

Last synced: 09 Jan 2026

https://github.com/OWASP/www-community

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

appsec community-project owasp

Last synced: 07 Jul 2026

https://github.com/webpwnized/mutillidae

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, security enthusiasts, classrooms, CTF, and vulnerability assessment tool targets.

10 application appsec cybersecurity owasp owasp-top-10 penetration-testing security top training web

Last synced: 14 May 2025

https://github.com/roottusk/vapi

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

api apitop10 appsec appsec-tutorials bugbounty cors docker exercises hacktoberfest hacktoberfest-accepted owasp owasp-top-10 owasp-top-ten php postman vulnerable-application

Last synced: 14 May 2025

https://github.com/owasp/www-community

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

appsec community-project owasp

Last synced: 14 May 2025

https://github.com/openappsec/openappsec

open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.

api-security application-security appsec devsecops kong kubernetes nginx nginx-proxy-manager owasp owasp-top-ten rate-limiting security-tools threat-prevention waf web-application-firewall

Last synced: 29 Dec 2025

https://github.com/Soluto/kamus

An open source, git-ops, zero-trust secret encryption and decryption solution for Kubernetes applications

appsec devops gitops kms kubernetes kubernetes-secrets soluto-open-source

Last synced: 30 Mar 2025

https://github.com/ayoubfathi/leaky-paths

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.

appsec axiom bugbounty dirbuster dirsearch ffuf fuzzing hacktoberfest meg nuclei penetration-testing pentest recon redteam redteaming security security-tools subfinder wayback-machine wordlist

Last synced: 11 Jul 2025

https://github.com/owasp/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

appsec owasp-top rails ruby ruby-on-rails security vulnerabilities

Last synced: 11 Apr 2025

https://github.com/numirias/security

Some of my security stuff and vulnerabilities. Nothing advanced. More to come.

appsec pentesting security

Last synced: 12 Feb 2026

https://github.com/OWASP/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

appsec owasp-top rails ruby ruby-on-rails security vulnerabilities

Last synced: 16 Mar 2025

https://github.com/OWASP/OWASP-VWAD

The OWASP Vulnerable Web Applications Directory project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.

appsec owasp vulnerable vulnerable-web-app vulnerable-web-application

Last synced: 22 Apr 2025

https://github.com/owasp/owasp-vwad

The OWASP Vulnerable Web Applications Directory project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.

appsec owasp vulnerable vulnerable-web-app vulnerable-web-application

Last synced: 02 Apr 2025

https://github.com/zaproxy/community-scripts

A collection of ZAP scripts and tips provided by the community - pull requests very welcome!

appsec dast scripts tips webappsec zaproxy

Last synced: 10 May 2025

https://github.com/ShiftLeftSecurity/sast-scan

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and Git friendly.

appsec dependency-scan devsecops license-scan sast scanners workflow

Last synced: 07 Apr 2025

https://github.com/six2dez/burp-ai-agent

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

ai appsec bugbounty burp burp-extensions burp-plugin burp-suite hacking kotlin llm mcp pentesting security web-security

Last synced: 07 Mar 2026

https://github.com/DataDog/dd-trace-go

Datadog Go Library including APM tracing, profiling, and security monitoring.

apm appsec datadog distributed-tracing monitoring opentelemetry opentracing otel performance profiling tracing

Last synced: 28 Mar 2025

https://github.com/datadog/dd-trace-go

Datadog Go Library including APM tracing, profiling, and security monitoring.

apm appsec datadog distributed-tracing monitoring opentelemetry opentracing otel performance profiling tracing

Last synced: 14 May 2025

https://github.com/mobsf/mobsfscan

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.

android appsec codereview ios java kotlin mobile-sast objective-c sast security static-analysis swift

Last synced: 14 May 2025

https://github.com/security-prince/Application-Security-Engineer-Interview-Questions

Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer

application-security appsec devsecops infosec interview-questions sdlc security-engineer-interview security-engineering security-team vulnerability webappsec websec websecurity websecurity-reference xss

Last synced: 17 Apr 2025

https://github.com/MobSF/mobsfscan

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.

android appsec codereview ios java kotlin mobile-sast objective-c sast security static-analysis swift

Last synced: 01 Apr 2025

https://github.com/TheHackerDev/race-the-web

Tests for race conditions in web applications. Includes a RESTful API to integrate into a continuous integration pipeline.

appsec devops-tools infosec race-conditions security security-tools

Last synced: 02 Apr 2025

https://github.com/Privado-Inc/privado

Open Source Static Scanning tool to detect data flows in your code, find data security vulnerabilities & generate accurate Play Store Data Safety Report.

android-privacy-tools appsec compliance devprivops devsecops gdpr gdpr-compliant hacktoberfest play-store-data-safety privacy-by-design privacy-engineering privacy-labels privacy-policy static-analysis

Last synced: 30 Mar 2025

https://github.com/aeria-org/aeria

A language designed for the web that integrates with TypeScript

aeria appsec bun deno javascript low-code mongodb node odm orm prisma rapid-development strong-typed typescript vibe-coding

Last synced: 23 May 2026

https://github.com/ajinabraham/njsscan

njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.

appsec codereview codescanner devsecops expressjs jslint lint linter njsscan nodejs nodejsscan nodesecurity python sast security security-tools semantic static-analysis static-analyzer staticanalysis

Last synced: 14 May 2025

https://github.com/OWASP/threat-model-cookbook

This project is about creating and publishing threat model examples.

appsec threat-model threat-modeling threat-modelling threat-models

Last synced: 18 Apr 2025

https://github.com/talsec/Free-RASP-Community

SDK providing app protection and threat monitoring for mobile devices. Works with Flutter, React Native, Android and iOS. Shield your app with free RASP. Detect reverse engineering, root (Magisk), jailbreak, Frida, emulators, bots, tampering and integrity issues, obfuscation, VPN usage, malware, and monitor device identification and fingerprint.

app-shielding application-security appsec attack-detection cloning flutter-rasp flutter-security fraud-detection freerasp frida-detection hooking rasp rasp-library repackaging-detection reverse-engineering security-hardening security-tools shadow-detection tampering-detection

Last synced: 03 Apr 2025

https://github.com/talsec/free-rasp-community

SDK providing app protection and threat monitoring for mobile devices. Works with Flutter, React Native, Android and iOS. Shield your app with free RASP. Detect reverse engineering, root (Magisk), jailbreak, Frida, emulators, bots, tampering and integrity issues, obfuscation, VPN usage, malware, and monitor device identification and fingerprint.

app-shielding application-security appsec attack-detection cloning flutter-rasp flutter-security fraud-detection freerasp frida-detection hooking rasp rasp-library repackaging-detection reverse-engineering security-hardening security-tools shadow-detection tampering-detection

Last synced: 30 Oct 2025

https://github.com/volkandindar/agartha

A Burp extension helps identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations, while also converting HTTP requests to JavaScript for enhanced XSS exploitation.

application-security appsec burp-extensions burpsuite cybersecurity hacking hacking-tool offensivesecurity offsec penetration-testing pentesting

Last synced: 13 May 2025

https://github.com/JohnTroony/Blisqy

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

appsec blind-sql-injection blisqy database-security exploitation john-ombagi sql sql-injection sql-payloads

Last synced: 12 Jul 2025

https://github.com/m14r41/PentestingEverything

Penetration Testing For - Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting, etc...

active-directory-security api-pentesting application-security appsec docker-security forensic-analysis infrastucture iot-security-testing mobile-pentesting network-security source-code thick-client wifi-hacking

Last synced: 18 Jul 2025

https://github.com/ispras/casr

Collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate severity.

afl aflplusplus apport appsec coredump crash crash-reporting devsecops dynamic-analysis exploitable fuzzing gdb libfuzzer rust sdl security ssdlc testing triage vulnerability-management

Last synced: 12 Apr 2025

https://github.com/owasp/cve-lite-cli

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.

appsec cve javascript nodejs owasp security security-tools

Last synced: 27 May 2026

https://github.com/Eyadkelleh/awesome-skills-security

Security testing toolkit for AI Agent: curated SecLists wordlists, injection payloads, and expert agents for authorized pentesting, CTFs, and bug bounties

agent-skills agentic-ai appsec ctfs hacking-tool pentest-tool pentesting seclists seclists-download security

Last synced: 23 Jun 2026

https://github.com/Orange-Cyberdefense/grepmarx

A source code static analysis platform for AppSec enthusiasts.

appsec sast sca security

Last synced: 19 Jun 2026

https://github.com/zaproxy/zap-hud

The ZAP Heads Up Display (HUD)

appsec hacktoberfest hud zap

Last synced: 06 Oct 2025

https://github.com/albuch/sbt-dependency-check

SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). :rainbow:

appsec cve devops devsecops infosec nvd owasp owasp-dependencycheck sbt sbt-plugin scala security security-audit security-automation software-composition-analysis software-security static-analysis vulnerabilities vulnerability-scanners

Last synced: 12 Jan 2026

https://github.com/dschadow/JavaSecurity

Java web and command line applications demonstrating various security topics

appsec cryptography csp csrf esapi google-tink java java-security java-web owasp security security-topics spring spring-boot spring-security xss

Last synced: 09 Aug 2025

https://github.com/stevespringett/nist-data-mirror

A simple Java command-line utility to mirror the CVE JSON data from NIST.

appsec cpe cve java nist nvd sca software-composition-analysis software-security

Last synced: 14 Jan 2026

https://github.com/enemy-submarine/pidrila

Python Interactive Deepweb-oriented Rapid Intelligent Link Analyzer

appsec bug-bounty dirbuster hacking netstalking penetration-testing pentest pentesting python scanner scanner-web security

Last synced: 28 Mar 2025

https://github.com/tprynn/web-methodology

Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki

application-security appsec documentation security security-testing web web-application web-application-security

Last synced: 13 Feb 2026

https://github.com/awslabs/threat-designer

Threat Designer is a GenerativeAI application designed to automate and streamline the threat modeling process for secure system design.

agentic-ai appsec cybersecurity devsecops generativeai threat-modeling threat-modeling-tool threatmodeling threatmodelling

Last synced: 22 Feb 2026

https://github.com/juxhindb/oob-server

A Bind9 server for pentesters to use for Out-of-Band vulnerabilities

appsec infosec

Last synced: 31 Jul 2025

https://github.com/manuelberrueta/flowanalyzer

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

appsec identity oauth oauth2 oidc openid openid-connect redteam security security-tools

Last synced: 23 Jun 2025

https://github.com/ManuelBerrueta/FlowAnalyzer

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

appsec identity oauth oauth2 oidc openid openid-connect redteam security security-tools

Last synced: 03 Apr 2025