The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
-
Updated
Sep 30, 2026 - Python
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
Automated Security Testing For REST API's
The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp
Maryam: Open-source Intelligence(OSINT) Framework
The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.
APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.
The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving towards completion.
OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
OWASP Honeypot, Automated Deception Framework.
Red-teaming and evaluation framework for AI agents, built around an OWASP-inspired ASI01–ASI10 taxonomy
Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt injection, supply chain etc in a local dashboard. Agent agnostic (Claude, codex, langchain etc.)
OWASP Domain Protect - prevent subdomain takeover
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
To associate your repository with the owasp topic, visit your repo's landing page and select "manage topics."