Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

https://github.com/kingthorin/neonmarker

Continuation of the ZAP Neonmarker add-on previously by Juha Kivekäs

appsec dast hacktoberfest pentest pentest-tool pentesting pentesting-tools webappsec zap zaproxy

Last synced: 25 Jun 2024

https://github.com/secdec/attack-surface-detector-zap

The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters

dast pentesting security vulnerability

Last synced: 25 Jun 2024

https://github.com/projectdiscovery/fuzzing-templates

Community curated list of nuclei templates for finding "unknown" security vulnerabilities.

api dast fuzzing nuclei security

Last synced: 22 Jun 2024

https://github.com/zaproxy/community-scripts

A collection of ZAP scripts and tips provided by the community - pull requests very welcome!

appsec dast scripts tips webappsec zaproxy

Last synced: 21 Jun 2024

https://github.com/zaproxy/action-baseline

A GitHub Action for running the ZAP Baseline scan

actions dast devsecops github-actions security

Last synced: 21 Jun 2024

https://github.com/zaproxy/action-full-scan

A GitHub Action for running the ZAP Full scan

actions dast devsecops github-actions security

Last synced: 21 Jun 2024

https://github.com/we45/ThreatPlaybook

A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration

application-security dast devsecops python sast threat-model

Last synced: 06 Jun 2024

https://github.com/SasanLabs/owasp-zap-fileupload-addon

OWASP ZAP add-on for finding vulnerabilities in File Upload functionality.

dast fileupload hacktoberfest java sasanlabs scanner security security-tools zap zaproxy

Last synced: 12 May 2024

https://github.com/hahwul/mzap

⚡️ Multiple target ZAP Scanning

bugbounty dast hacking security zaproxy zaproxy-automation

Last synced: 01 May 2024

https://github.com/secdec/attack-surface-detector-burp

The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters

dast pentesting security vulnerability

Last synced: 07 Apr 2024

https://github.com/Zigrin-Security/CakeFuzzer

Cake Fuzzer is a project that is meant to help automatically and continuously discover vulnerabilities in web applications created based on specific frameworks with very limited false positives.

cybersecurity dast hacking iast sast

Last synced: 29 Mar 2024

https://github.com/analysis-tools-dev/dynamic-analysis

⚙️ A curated list of dynamic analysis tools and linters for all programming languages, binaries, and more.

analysis dast dynamic dynamic-analysis dynamic-code-analysis

Last synced: 21 Mar 2024