Application Security Open Source Projects
Browse 84 Application Security open source projects, ranked by GitHub stars. Find the most popular Application Security tools and libraries.
OWASP/CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Metrics details
| Stars | 32,612 |
juice-shop/juice-shop
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
Metrics details
| Stars | 13,520 |
OWASP/wstg
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
Metrics details
| Stars | 9,601 |
infoslack/awesome-web-hacking
A list of web application security
Metrics details
| Stars | 7,115 |
paragonie/awesome-appsec
A curated list of resources for learning about application security
Metrics details
| Stars | 6,994 |
urbanadventurer/WhatWeb
Next generation web scanner
Metrics details
| Stars | 6,730 |
jassics/security-study-plan
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
Metrics details
| Stars | 5,009 |
ComplianceAsCode/content
Security automation content in SCAP, Bash, Ansible, and other formats
Metrics details
| Stars | 2,769 |
user1342/Awesome-Android-Reverse-Engineering
A curated list of awesome Android Reverse Engineering training, resources, and tools.
Metrics details
| Stars | 2,540 |
payloadbox/command-injection-payload-list
🎯 Command Injection Payload List
Metrics details
| Stars | 2,375 |
hahwul/DevSecOps
♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎
Metrics details
| Stars | 2,144 |
m14r41/PentestingEverything
Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...
Metrics details
| Stars | 1,878 |
metlo-labs/metlo
Metlo is an open-source API security platform.
Metrics details
| Stars | 1,780 |
s4n7h0/xvwa
XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
Metrics details
| Stars | 1,762 |
harsh-bothra/learn365
This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.
Metrics details
| Stars | 1,704 |
TaptuIT/awesome-devsecops
Curating the best DevSecOps resources and tooling.
Metrics details
| Stars | 1,703 |
Safe3/uuWAF
一款社区驱动的免费、高性能、高扩展顶级Web应用和API安全防护产品-南墙
Metrics details
| Stars | 1,680 |
openappsec/openappsec
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
Metrics details
| Stars | 1,652 |
Janusec/janusec
JANUSEC Application Gateway provides secure access, including reverse proxy, K8S Ingress Controller, Automatic ACME Certificate, WAF, 5-Second Shield, CC Defense, OAuth2 Authentication, Global Server Load Balance, and Cookie Compliance etc. JANUSEC应用网关,提供安全的接入,包括反向代理、K8S Ingress Controller、自动化ACME证书、WAF、5秒盾、CC防御、OAuth2身份认证、GSLB负载均衡与Cookie合规等。
Metrics details
| Stars | 1,202 |
Quitten/Autorize
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
Metrics details
| Stars | 1,168 |
sh4hin/Androl4b
A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis
Metrics details
| Stars | 1,163 |
guardrailsio/awesome-php-security
Awesome PHP Security Resources 🕶🐘🔐
Metrics details
| Stars | 1,036 |
secureCodeBox/secureCodeBox
secureCodeBox (SCB) - continuous secure delivery out of the box
Metrics details
| Stars | 985 |
appsecco/breaking-and-pwning-apps-and-servers-aws-azure-training
Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!
Metrics details
| Stars | 952 |
bloodzer0/ossa
Open-Source Security Architecture | 开源安全架构
Metrics details
| Stars | 942 |
wallarm/awesome-nginx-security
🔥 A curated list of awesome links related to application security related to the environments with NGINX or Kubernetes Ingres Controller (based on NGINX)
Metrics details
| Stars | 783 |
MattKeeley/Spoofy
Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
Metrics details
| Stars | 769 |
rewanthtammana/Damn-Vulnerable-Bank
Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.
Metrics details
| Stars | 756 |
olacabs/jackhammer
Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.
Metrics details
| Stars | 741 |
security-prince/Application-Security-Engineer-Interview-Questions
Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer
Metrics details
| Stars | 689 |
Anof-cyber/Application-Security
Resources for Application Security including Web, API, Android, iOS and Thick Client
Metrics details
| Stars | 687 |
Cy-clon3/awesome-ios-security
A curated list of awesome iOS application security resources.
Metrics details
| Stars | 666 |
brcyrr/PracticalCyberSecurityResources
This repository contains a curated list of resources I suggest on LinkedIn and Twitter.📝🌝
Metrics details
| Stars | 665 |
factionsecurity/faction
Pen Test Report Generation and Assessment Collaboration
Metrics details
| Stars | 596 |
0xn3va/cheat-sheets
A list of cheat sheets for application security
Metrics details
| Stars | 521 |
talsec/Free-RASP-Community
SDK providing threat detection & security monitoring for mobile devices. Works with Flutter, React Native, Android and iOS. Shield your app with free RASP. Detect reverse engineering, root (Magisk), jailbreak, Frida, emulators, bots, tampering and integrity issues, obfuscation, VPN usage, malware, and monitor device identification and fingerprint.
Metrics details
| Stars | 500 |
SmileZXLee/ZXHookDetection
【iOS应用安全、安全攻防】hook及越狱的基本防护与检测(动态库注入检测、hook检测与防护、越狱检测、签名校验、汇编分析、IDA反编译分析加密协议Demo);【数据传输安全】浅谈http、https与数据加密;代码加密&混淆;防抓包、http-dns解决方案,防止DNS劫持等
Metrics details
| Stars | 482 |
juice-shop/juice-shop-ctf
Tool to export Juice Shop challenges and hints in data format compatible with CTFd, RootTheBox or FBCTF
Metrics details
| Stars | 474 |
jassics/security-interview-questions
Security interview questions with possible explanation for roles in AppSec, Pentesting, Cloud Security, DevSecOps, Network Security and so on
Metrics details
| Stars | 470 |
enkomio/Taipan
Web application vulnerability scanner
Metrics details
| Stars | 463 |
jassics/security-skills-career-roadmap
Skills and career roadmap for various security roles like appsec, cloud security, devsecops, security engineer, security researchers, pentesting, api security, network security, mobile security and so on.with helpful resources, guidelines
Metrics details
| Stars | 432 |
flipkart-incubator/watchdog
Watchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.
Metrics details
| Stars | 431 |
paragonie/airship
Secure Content Management for the Modern Web - "The sky is only the beginning"
Metrics details
| Stars | 414 |
lukeFalsina/Grab-n-Run
Grab’n Run, a simple and effective Java Library for Android projects to secure dynamic code loading.
Metrics details
| Stars | 406 |
volkandindar/agartha
A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It supports dynamic payload generation, including BCheck syntax, and can automatically generate Bambdas scripts. Additionally, it offers "Copy as JavaScript" to convert HTTP requests for enhanced XSS testing.
Metrics details
| Stars | 401 |
satishpatnayak/AndroGoat
AndroGoat
Metrics details
| Stars | 379 |
tegal1337/0l4bs
Cross-site scripting labs for web application security enthusiasts
Metrics details
| Stars | 345 |
mishmashclone/swisskyrepo-PayloadsAllTheThings
https://github.com/swisskyrepo/PayloadsAllTheThings
Metrics details
| Stars | 339 |
adeyosemanputra/pygoat
intentionally vuln web Application Security in django
Metrics details
| Stars | 337 |
Autodesk/continuous-threat-modeling
A Continuous Threat Modeling methodology
Metrics details
| Stars | 329 |
SpamScope/spamscope
Fast Advanced Spam Analysis Tool
Metrics details
| Stars | 312 |
we45/ThreatPlaybook
A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration
Metrics details
| Stars | 282 |
OWASP/RiskAssessmentFramework
The Secure Coding Framework
Metrics details
| Stars | 272 |
Karmaz95/crimson
Web Application Security Testing Tools
Metrics details
| Stars | 253 |
dn0m1n8tor/learn365
This repository is about @AnubhavSingh_'s 365 days of Learning Tweets collection.
Metrics details
| Stars | 229 |
spring-guides/top-spring-security-architecture
Spring Security Architecture:: Topical guide to Spring Security, how the bits fit together and how they interact with Spring Boot
Metrics details
| Stars | 227 |
abhi-r3v0/EVABS
An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.
Metrics details
| Stars | 224 |
payloadbox/rfi-lfi-payload-list
🎯 RFI/LFI Payload List
Metrics details
| Stars | 224 |
simioni87/auth_analyzer
Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.
Metrics details
| Stars | 223 |
Anof-cyber/PyCript
Burp Suite extension to decrypt/encrypt any encrypted traffic (AES/RSA/Encodings and more) with custom code in any language
Metrics details
| Stars | 220 |
