appsec
Tracked open-source repos tagged appsec, sorted by stars.
Related topics
Topics that frequently appear alongside appsec on the same repo.
Recent risers
Repos created in the last 90 days, tagged appsec.
- #1
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
★ 47,620+335Star change over the last 7 days - #2★ 38,347+39Star change over the last 7 days
- #3
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
★ 33,054+37Star change over the last 7 days - #4
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
★ 22,480+15Star change over the last 7 days - #5★ 15,724+18Star change over the last 7 days
- #6★ 14,684+13Star change over the last 7 days
- #7
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
★ 13,771+31Star change over the last 7 days - #8
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
★ 9,779+16Star change over the last 7 days - #9
A list of web application security
★ 7,256+7Star change over the last 7 days - #10
8 Lessons, Kick-start Your Cybersecurity Learning.
★ 6,859+17Star change over the last 7 days - #11★ 6,809+6Star change over the last 7 days
- #12★ 6,705+7Star change over the last 7 days
- #13★ 5,290+5Star change over the last 7 days
- #14
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
★ 5,054+4Star change over the last 7 days - #15
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
★ 4,919+6Star change over the last 7 days - #16
An OOB interaction gathering server and client library
★ 4,514+2Star change over the last 7 days - #17
The parent project for OpenZiti. Here you will find the executables for a fully zero-trust, programmable network @OpenZiti
★ 4,374+14Star change over the last 7 days - #18
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
★ 4,170+14Star change over the last 7 days - #19
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
★ 2,740+1Star change over the last 7 days - #20
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
★ 2,698+2Star change over the last 7 days - #21★ 2,549+2Star change over the last 7 days
- #22
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
★ 2,297+0Star change over the last 7 days - #23
Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...
★ 2,062+7Star change over the last 7 days - #24
A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
★ 1,805+2Star change over the last 7 days - #25★ 1,791+2Star change over the last 7 days
- #26
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
★ 1,695+4Star change over the last 7 days - #27
TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.
★ 1,664+1Star change over the last 7 days - #28
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.
★ 1,643+11Star change over the last 7 days - #29
OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, security enthusiasts, classrooms, CTF, and vulnerability assessment tool targets.
★ 1,514+1Star change over the last 7 days - #30
Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more
★ 1,477+40Star change over the last 7 days