Top #appsec Tools & Software

Explore 17 hand-picked tools and software tagged with appsec — ranked by popularity and community signals.

CheatSheetSeries

github

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Security Python
★ 31,782

SafeLine

github

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

Security Go
★ 21,217

zaproxy

github

The ZAP by Checkmarx Core project

Security Java
★ 15,083

dirsearch

github

Web path scanner

Security Python
★ 14,236

juice-shop

github

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

Security TypeScript
★ 13,068

wstg

github

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Security
★ 9,179

awesome-web-hacking

github

A list of web application security

Security
★ 6,819

WhatWeb

github

Next generation web scanner

Security Ruby
★ 6,562

Security-101

github

8 Lessons, Kick-start Your Cybersecurity Learning.

Security
★ 6,438

faraday

github

Open Source Vulnerability Management Platform

Security Python
★ 6,333

w3af

github

w3af: web application attack and audit framework, the open source web vulnerability scanner.

Security Python
★ 4,867

django-DefectDojo

github

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Security
★ 4,677

interactsh

github

An OOB interaction gathering server and client library

Security Go
★ 4,303

dependency-track

github

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Security Java
★ 3,788

bearer

github

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Security Go
★ 2,641

kics

github

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

Security
★ 2,629

cicd-goat

github

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

DevOps Python
★ 2,227