8 Lessons, Kick-start Your Cybersecurity Learning.
-
Updated
Dec 21, 2025 - HTML
8 Lessons, Kick-start Your Cybersecurity Learning.
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
ZAP Add-ons
A vulnerable version of Rails that follows the OWASP Top 10
In progress rough solutions to bWAPP / bee-box
OWASP Code Review Guide Web Repository
OWASP Zed Attack Proxy project landing page.
OWASP Foundation Threat Dragon Project Web Repository
The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
The source of ZAP website
Curated cyber security resources for blue team, red team, DFIR, OSINT, AppSec, cloud security, security logging, and training.
OWASP Citizen Development Top 10
Integrates OWASP Zed Attack Proxy reports into SonarQube
Agentic AI for DevSecOps: Transforming Security with GitHub Advanced Security and GitHub Copilot. GitHub Advanced Security - DevSecOps Guidelines - Unified visibility into DevOps security posture. DevSecOps E2E Demos.
osint tools, repo, and my projects
Add a description, image, and links to the appsec topic page so that developers can more easily learn about it.
To associate your repository with the appsec topic, visit your repo's landing page and select "manage topics."