Other Projects
Lab Projects: OWASP Labs projects represent projects that have produced an OWASP reviewed deliverable of value.
Incubator Projects: OWASP Incubator projects represent the experimental playground where projects are still being fleshed out, ideas are still being proven, and development is still underway.
Lab Projects
- OWASP AntiSamy
- OWASP API Security Project
- OWASP Attack Surface Detector
- OWASP Automated Threats to Web Applications
- OWASP Benchmark
- OWASP Code Pulse
- OWASP Code Review Guide
- OWASP Coraza Web Application Firewall
- OWASP Cornucopia
- OWASP Devsecops Maturity Model
- OWASP Enterprise Security API (ESAPI)
- OWASP Find Security Bugs
- OWASP Integration Standards
- OWASP Internet of Things
- OWASP Java HTML Sanitizer
- OWASP Mobile Top 10
- OWASP Mutillidae II
- OWASP Podcast
- OWASP Proactive Controls
- OWASP pytm
- OWASP SamuraiWTF
- OWASP Secure Coding Dojo
- OWASP Secure Headers Project
- OWASP secureCodeBox
- OWASP SecureTea Project
- OWASP Security Pins
- OWASP Snakes And Ladders
- OWASP Software Component Verification Standard
- OWASP Threat Dragon
- OWASP Top 10 CI/CD Security Risks
- OWASP Low-Code/No-Code Top 10
- OWASP Top 10 Privacy Risks
- OWASP TorBot
- OWASP Vulnerable Web Applications Directory
- OWASP WebGoat
- OWASP WrongSecrets
Incubator Projects
- OWASP .Net
- OWASP aegis4j
- OWASP AI Security and Privacy Guide
- OWASP Android Security Inspector Toolkit
- OWASP APICheck
- OWASP Application Gateway
- OWASP Application Security Awareness Campaigns
- OWASP Appsec Pipeline
- OWASP AppSensor
- OWASP ASVS-Graph
- OWASP Automotive EMB 60
- OWASP AWScanner
- OWASP Barbarus
- OWASP Big Data Security Verification Standard
- OWASP Bug Logging Tool
- OWASP Cervantes
- OWASP Cloud-Native Application Security Top 10
- OWASP Cloud-Native Security Project
- OWASP Cloud Tenant Isolation
- OWASP Code the Flag
- OWASP Continuous Penetration Testing Framework
- OWASP Core Business Application Security
- OWASP crAPI
- OWASP CSRFProtector Project
- OWASP CWE Toolkit
- OWASP Cyber Controls Matrix (OCCM)
- OWASP Cyber Defense Framework
- OWASP Cyber Defense Matrix
- OWASP Cyber Scavenger Hunt
- OWASP D4N155
- OWASP Damn Vulnerable Web Sockets
- OWASP Data Security Top 10
- OWASP Desktop App Security Top 10
- OWASP Developer Guide
- OWASP AppSec Days Developer Outreach Program
- OWASP DevSecOps Guideline
- OWASP DevSecOps Top 10
- OWASP DevSecOps Verification Standard
- OWASP DevSlop
- OWASP Docker Top 10
- OWASP Domain Protect
- OWASP DPD (DDOS Prevention using DPI)
- OWASP eBPFShield
- OWASP Enterprise DevSecOps
- OWASP Forensics Testing Guide
- OWASP G0rKing
- OWASP Go Secure Coding Practices Guide
- OWASP Honeypot
- OWASP How to Get Into AppSec
- OWASP IDE-VulScanner
- OWASP Information Security Metrics Bank
- OWASP Intelligent Intrusion Detection System
- OWASP IoT Security Verification Standard
- OWASP KubeLight
- OWASP Kubernetes Security Testing Guide
- OWASP Kubernetes Top Ten
- OWASP Maryam
- OWASP Machine Learning Security Verification Standard
- OWASP Mobile Audit
- OWASP Nettacker
- OWASP Nightingale
- OWASP Node.js Goat
- OWASP O-Saft
- OWASP Ontology Driven Threat Modeling Framework
- OWASP Open Source Security Applications Platform
- OWASP Patton
- OWASP Penetration Testing Kit
- OWASP PenText
- OWASP Port and Service Information
- OWASP PurpleTeam
- OWASP Pygoat
- OWASP Raider
- OWASP Risk Assessment Framework
- OWASP safetypes
- OWASP Scan IT
- OWASP ScrapPy
- OWASP Sectudo
- OWASP Secure Coding Practices-Quick Reference Guide
- OWASP Secure Logging Benchmark
- OWASP SecureBank
- OWASP SecureFlag Open Platform
- OWASP Security Champions Guide
- OWASP Security Culture
- OWASP Security Qualitative Metrics
- OWASP SecurityRAT
- OWASP Serverless Top 10
- OWASP SideKEK
- OWASP Snow
- OWASP Software Pre-Execution Security Review
- OWASP Software Security 5D Framework
- OWASP Project Spotlight Series
- OWASP Single Sign-On
- OWASP State of AppSec Survey
- OWASP Testability Patterns for Web Applications
- OWASP Thick Client Security Testing Guide
- OWASP Thick Client Top 10 Project
- OWASP Threat and Safeguard Matrix (TaSM)
- OWASP Threat Modeling Project
- OWASP Threat Model Cookbook
- OWASP Threat Modeling Playbook (OTMP)
- OWASP TimeGap Theory
- OWASP Top 10 Card Game
- OWASP Top 10 Client-Side Security Risks
- OWASP Vulnerability Management Center
- OWASP Vulnerability Management Guide
- OWASP Vulnerable Container Hub
- OWASP Vulnerable Flask App
- OWASP VulnerableApp
- OWASP VulnerableApp-Facade
- OWASP Web Application Firewall Evaluation Criteria Project (WAFEC)
- OWASP Web Mapper
- OWASP Web Testing Environment
- OWASP WinFIM.NET
Projects Needing Website Update
- OWASP Access Log Parser
- OWASP AndroGoat
- OWASP Anti-Ransomware Guide
- OWASP Application Security Curriculum
- OWASP Application Security Hardening
- OWASP Application Security Monitoring Standard
- OWASP Application Security Playbook
- OWASP AppSec Minimum Requirements
- OWASP Auth
- OWASP belva
- OWASP Best Practices In Vulnerability Disclosure And Bug Bounty Programs
- OWASP Blend
- OWASP Blockchain Distributed Infrastructure
- OWASP Broken Web Applications
- OWASP ChainGoat
- OWASP cloud security
- OWASP Cloud Security Mentor
- OWASP Cloud Security Testing Guide
- OWASP Cloud Testing Guide
- OWASP CloudSheep
- OWASP Cognito Catastrophe
- OWASP Container Security Verification Standard
- OWASP Ctf
- OWASP Cyber Security Enterprise Operations Architecture
- OWASP Cybersecurity Risk Register
- OWASP Damn Vulnerable Crypto Wallet
- OWASP Damn Vulnerable Thick Client Application
- OWASP deepviolet-tls-ssl-scanner
- OWASP Ende
- OWASP Financial Systems Security
- OWASP Game Security Framework
- OWASP Glue Tool
- OWASP hacking-lab
- OWASP Igoat Tool
- OWASP Incident Response
- OWASP InjectBot
- OWASP internet of things top 10
- OWASP Iot Analytics 4Industry4
- OWASP JavaScript Security
- OWASP Joomscan
- OWASP Jotp
- OWASP Json Sanitizer
- OWASP jvmxray
- OWASP Knowledge Based Authentication Performance Metrics
- OWASP Laravel Goat
- OWASP Learning Gateway
- OWASP little web application firewall
- OWASP Lock It
- OWASP Machine Learning Security Top 10
- OWASP Mimosa
- OWASP Mth3L3M3Nt Framework
- OWASP Nasi Lemak
- OWASP O2 Platform
- OWASP Off The Record 4 Java
- OWASP Online Academy
- OWASP Open AppSec Tooling API
- OWASP Passfault
- OWASP Php
- OWASP Php Security Training
- OWASP Python Honeypot
- OWASP Python Security
- OWASP Pyttacker
- OWASP Qrljacker
- OWASP rat
- OWASP Revelo
- OWASP Reverse Engineering And Code Modification Prevention
- OWASP Seclists
- OWASP Secure Medical Device Deployment Standard
- OWASP Security Busters
- OWASP Security Integration System
- OWASP Security Logging
- OWASP Security Resource Framework
- OWASP SEDATED®
- OWASP Seeker
- OWASP Smart Contract Security Top 10
- OWASP Software Composition Security
- OWASP SupplyChainGoat
- OWASP Threatspec
- OWASP TOCTOURex
- OWASP Top 10 Fuer Entwickler
- OWASP Top 25 Parameters
- OWASP University Challenge
- OWASP Vbscan
- OWASP Vicnum
- OWASP Virtual Patching Best Practices
- OWASP VITCC Open Source Initiative
- OWASP Voice Automated Application Security
- OWASP Vue 3 Password Input
- OWASP Vulnerable Web Application
- OWASP webgoat php
- OWASP Webspa
- OWASP Wpbullet
- OWASP Zsc Tool
Flagship Projects
Projects that have demonstrated strategic value to OWASP and application security as a whole
Standards Projects
OWASP Application Security Verification Standard
The OWASP Application Security Verification Standard (ASVS) Project is a framework of security requirements that focus on defining the security controls required when designing, developing and testing modern web applications and web services.
OWASP CycloneDX
OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction.
Tool Projects
OWASP Amass
An advanced open source tool to help information security professionals perform network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques!
OWASP CSRFGuard
OWASP CSRFGuard is a library that implements a variant of the synchronizer token pattern to mitigate the risk of Cross-Site Request Forgery (CSRF) attacks.
OWASP Defectdojo
The leading open source application vulnerability management tool built for DevOps and continuous security integration.
OWASP Dependency-Check
Dependency-Check is a Software Composition Analysis (SCA) tool suite that identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities.
OWASP Dependency-Track
Intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
OWASP Juice Shop
Probably the most modern and sophisticated insecure web application for security trainings, awareness demos and CTFs. Also great voluntary guinea pig for your security tools and DevSecOps pipelines!
OWASP OWTF
Offensive Web Testing Framework (OWTF), is an OWASP+PTES focused try to unite great tools and make pen testing more efficient, written mostly in Python.
OWASP Security Knowledge Framework
The OWASP Security Knowledge Framework is an open source web application that explains secure coding principles in multiple programming languages. The goal of OWASP-SKF is to help you learn and integrate security by design in your software development and build applications that are secure by design.
OWASP Security Shepherd
OWASP Security Shepherd is a web and mobile application security training platform. Security Shepherd has been designed to foster and improve security awareness among a varied skill-set demographic. The aim of this project is to take AppSec novices or experienced engineers and sharpen their penetration testing skillset to security expert status.
OWASP ZAP
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by a dedicated international team of volunteers. Great for pentesters, devs, QA, and CI/CD integration.
Documentation Projects
OWASP Cheat Sheet Series
The OWASP Cheat Sheet Series project provides a set of concise good practice guides for application developers and defenders to follow.
OWASP Mobile Application Security
The OWASP Mobile Application Security (MAS) project consists of a series of documents that establish a security standard for mobile apps and a comprehensive testing guide that covers the processes, techniques, and tools used during a mobile application security assessment, as well as an exhaustive set of test cases that enables testers to deliver consistent and complete results.
OWASP SAMM
A Software Assurance Maturity Model (SAMM) that provides an effective and measurable way for all types of organizations to analyse and improve their software security posture.
OWASP Top Ten
The OWASP Top 10 is the reference standard for the most critical web application security risks. Adopting the OWASP Top 10 is perhaps the most effective first step towards changing your software development culture focused on producing secure code.
OWASP Web Security Testing Guide
The Web Security Testing Guide (WSTG) Project produces the premier cybersecurity testing resource for web application developers and security professionals.
Code Projects
OWASP ModSecurity Core Rule Set
The OWASP ModSecurity Core Rule Set (CRS) is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls. The CRS aims to protect web applications from a wide range of attacks, including the OWASP Top Ten, with a minimum of false alerts.