Appsec Open Source Projects
Browse 104 Appsec open source projects, ranked by GitHub stars. Find the most popular Appsec tools and libraries.
OWASP/CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Metrics details
| Stars | 32,612 |
zaproxy/zaproxy
The ZAP by Checkmarx Core project
Metrics details
| Stars | 15,441 |
maurosoria/dirsearch
Web path scanner
Metrics details
| Stars | 14,521 |
juice-shop/juice-shop
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
Metrics details
| Stars | 13,520 |
OWASP/wstg
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
Metrics details
| Stars | 9,601 |
infoslack/awesome-web-hacking
A list of web application security
Metrics details
| Stars | 7,115 |
urbanadventurer/WhatWeb
Next generation web scanner
Metrics details
| Stars | 6,730 |
infobyte/faraday
Open Source Vulnerability Management Platform
Metrics details
| Stars | 6,660 |
OWASP/Go-SCP
Golang Secure Coding Practices guide
Metrics details
| Stars | 5,285 |
jassics/security-study-plan
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
Metrics details
| Stars | 5,009 |
andresriancho/w3af
w3af: web application attack and audit framework, the open source web vulnerability scanner.
Metrics details
| Stars | 4,897 |
DefectDojo/django-DefectDojo
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
Metrics details
| Stars | 4,843 |
projectdiscovery/interactsh
An OOB interaction gathering server and client library
Metrics details
| Stars | 4,448 |
openziti/ziti
The parent project for OpenZiti. Here you will find the executables for a fully zero-trust, programmable network @OpenZiti
Metrics details
| Stars | 4,300 |
DependencyTrack/dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
Metrics details
| Stars | 4,022 |
foospidy/payloads
Git All the Payloads! A collection of web attack payloads.
Metrics details
| Stars | 3,966 |
Bearer/bearer
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Metrics details
| Stars | 2,705 |
Checkmarx/kics
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Metrics details
| Stars | 2,673 |
cider-security-research/cicd-goat
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
Metrics details
| Stars | 2,279 |
trailofbits/publications
Publications from Trail of Bits
Metrics details
| Stars | 1,867 |
hysnsec/awesome-threat-modelling
A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
Metrics details
| Stars | 1,773 |
summitt/Nope-Proxy
TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.
Metrics details
| Stars | 1,663 |
openappsec/openappsec
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
Metrics details
| Stars | 1,652 |
webpwnized/mutillidae
OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, security enthusiasts, classrooms, CTF, and vulnerability assessment tool targets.
Metrics details
| Stars | 1,501 |
OWASP/www-community
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
Metrics details
| Stars | 1,382 |
roottusk/vapi
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
Metrics details
| Stars | 1,345 |
OWASP/www-project-top-10-for-large-language-model-applications
OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)
Metrics details
| Stars | 1,330 |
Simpsonpt/AppSecEzine
AppSec Ezine Public Repository.
Metrics details
| Stars | 1,221 |
httpvoid/writeups
Metrics details
| Stars | 1,199 |
ayoubfathi/leaky-paths
A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.
Metrics details
| Stars | 1,186 |
zaproxy/zap-extensions
ZAP Add-ons
Metrics details
| Stars | 938 |
Soluto/kamus
An open source, git-ops, zero-trust secret encryption and decryption solution for Kubernetes applications
Metrics details
| Stars | 934 |
OWASP/railsgoat
A vulnerable version of Rails that follows the OWASP Top 10
Metrics details
| Stars | 922 |
OWASP/OWASP-VWAD
:warning: This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory
Metrics details
| Stars | 884 |
ShiftLeftSecurity/sast-scan
Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and Git friendly.
Metrics details
| Stars | 884 |
numirias/security
Some of my security stuff and vulnerabilities. Nothing advanced. More to come.
Metrics details
| Stars | 866 |
DataDog/dd-trace-go
Datadog Go Library including APM tracing, profiling, and security monitoring.
Metrics details
| Stars | 849 |
blacklanternsecurity/badsecrets
A library for detecting known secrets across many web frameworks
Metrics details
| Stars | 815 |
MattKeeley/Spoofy
Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
Metrics details
| Stars | 769 |
oversecured/ovaa
Oversecured Vulnerable Android App
Metrics details
| Stars | 752 |
dependency-check/dependency-check-sonar-plugin
Integrates Dependency-Check reports into SonarQube
Metrics details
| Stars | 693 |
security-prince/Application-Security-Engineer-Interview-Questions
Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer
Metrics details
| Stars | 689 |
Anof-cyber/Application-Security
Resources for Application Security including Web, API, Android, iOS and Thick Client
Metrics details
| Stars | 687 |
Privado-Inc/privado
Open Source Static Scanning tool to detect data flows in your code, find data security vulnerabilities & generate accurate Play Store Data Safety Report.
Metrics details
| Stars | 651 |
TheHackerDev/race-the-web
Tests for race conditions in web applications. Includes a RESTful API to integrate into a continuous integration pipeline.
Metrics details
| Stars | 634 |
DataDog/dd-trace-php
Datadog PHP Clients
Metrics details
| Stars | 557 |
talsec/Free-RASP-Community
SDK providing threat detection & security monitoring for mobile devices. Works with Flutter, React Native, Android and iOS. Shield your app with free RASP. Detect reverse engineering, root (Magisk), jailbreak, Frida, emulators, bots, tampering and integrity issues, obfuscation, VPN usage, malware, and monitor device identification and fingerprint.
Metrics details
| Stars | 500 |
SasanLabs/VulnerableApp
OWASP VulnerableApp Project: Break it. Scan it. Reproduce it. Benchmark against it. Improve it.
Metrics details
| Stars | 442 |
ajinabraham/njsscan
njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.
Metrics details
| Stars | 436 |
OWASP/threat-model-cookbook
This project is about creating and publishing threat model examples.
Metrics details
| Stars | 429 |
JohnTroony/Blisqy
Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).
Metrics details
| Stars | 418 |
righettod/poc-graphql
Research on GraphQL from an AppSec point of view.
Metrics details
| Stars | 418 |
mtesauro/owasp-wte
Home of the developement for OWASP WTE - the Web Testing Environment, a collection of pre-packaged Linux AppSec tools, apps and documentation used to create pre-configured VMs or installed ala carte in the Linux of your choice..
Metrics details
| Stars | 408 |
volkandindar/agartha
A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It supports dynamic payload generation, including BCheck syntax, and can automatically generate Bambdas scripts. Additionally, it offers "Copy as JavaScript" to convert HTTP requests for enhanced XSS testing.
Metrics details
| Stars | 401 |
c0rdis/security-champions-playbook
Security Champions Playbook v 2.1
Metrics details
| Stars | 392 |
dub-flow/appsec-challenges
This repo contains the code for my appsec challenges
Metrics details
| Stars | 366 |
ispras/casr
Collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate severity.
Metrics details
| Stars | 357 |
mercedes-benz/sechub
SecHub provides a central API to test software with different security tools.
Metrics details
| Stars | 353 |
Orange-Cyberdefense/grepmarx
A source code static analysis platform for AppSec enthusiasts.
Metrics details
| Stars | 278 |
zaproxy/zap-hud
The ZAP Heads Up Display (HUD)
Metrics details
| Stars | 274 |
