OWASP AspGoat

OWASP AspGoat - An OWASP incubator project

About OWASP AspGoat

Road Map

• Q1: Launch initial release with core OWASP Top 10 (and more) vulnerabilities, Docker setup, and documentation. • Q2: Add advanced vulnerabilities (JWT, GraphQL, SSTI, OAuth, LLM Vulnerabilities). • Q3: STRIDE Threat Modeling overlays for each vulnerability class to highlight architectural risks. • Q4: Integrate ModSecurity WAF module in order to make the challenges harder (with a switch to hard mode button). • Future Extension: Integrate a .NET Vulnerable API as a part of this project or by creating a separate project.

Project Information

Incubator Project
Classification
Incubator
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP AspGoat