appsec
Tracked open-source repos tagged appsec, sorted by stars.
- #31
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
★ 1,407+5Star change over the last 7 days - #32
OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)
★ 1,383+5Star change over the last 7 days - #33
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
★ 1,349+0Star change over the last 7 days - #34
A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.
★ 1,193+0Star change over the last 7 days - #35
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
★ 1,074+26Star change over the last 7 days - #36
A curated list of tools officially presented at Black Hat events
★ 980+8Star change over the last 7 days - #37
Security automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks.
★ 957+5Star change over the last 7 days - #38
ZAP Add-ons
★ 947+2Star change over the last 7 days - #39★ 923+1Star change over the last 7 days
- #40
A collection of ZAP scripts and tips provided by the community - pull requests very welcome!
★ 893+0Star change over the last 7 days - #41
:warning: This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory
★ 885-2Star change over the last 7 days - #42★ 883+0Star change over the last 7 days
- #43★ 872+1Star change over the last 7 days
- #44
Datadog Go Library including APM tracing, profiling, and security monitoring.
★ 853+0Star change over the last 7 days - #45
A library for detecting known secrets across many web frameworks
★ 823+2Star change over the last 7 days - #46
mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.
★ 783+2Star change over the last 7 days - #47
Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
★ 772-2Star change over the last 7 days - #48
Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.
★ 759+102Star change over the last 7 days - #49★ 756+2Star change over the last 7 days
- #50★ 754+137Star change over the last 7 days
- #51
Integrates Dependency-Check reports into SonarQube
★ 694+1Star change over the last 7 days - #52
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
★ 691+7Star change over the last 7 days - #53
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
★ 688+5Star change over the last 7 days - #54
Open Source Static Scanning tool to detect data flows in your code, find data security vulnerabilities & generate accurate Play Store Data Safety Report.
★ 656+2Star change over the last 7 days - #55
Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
★ 630+2Star change over the last 7 days - #56
Datadog PHP Clients
★ 558+0Star change over the last 7 days - #57
jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security vulnerabilities, making it an essential resource for and bug bounty hunters and security researchers.
★ 534+1Star change over the last 7 days - #58
SDK providing threat detection & security monitoring for mobile devices. Works with Flutter, React Native, Android and iOS. Shield your app with free RASP. Detect reverse engineering, root (Magisk), jailbreak, Frida, emulators, bots, tampering and integrity issues, obfuscation, VPN usage, malware, and monitor device identification and fingerprint.
★ 513+3Star change over the last 7 days