Explore 18 curated tools and resources
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.
A cloud-native web application and API security solution that uses contextual AI to protect against known and zero-day threats without signature-based detection.
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
A Python-based web application scanner for OSINT and fuzzing OWASP vulnerabilities
OWASP Project for making vulnerability management easier.
A deliberately insecure web application for teaching web application security lessons maintained by OWASP.
The best security training environment for Developers and AppSec Professionals.
A presentation about the OWASP Top 10, a list of the most critical security risks to web applications.
Node package for preparing CTF events with OWASP Juice Shop challenges for popular CTF frameworks.
The OWASP AppSec Europe '16 Conference is a leading gathering in web application security, featuring keynote speakers and in-depth trainings in application security topics.
A comprehensive checklist for securing Android apps
A comprehensive online resource for application security knowledge
Markdown version of OWASP Testing Checklist v4 for various platforms.
OWASP OWTF is a penetration testing framework focused on efficiency and alignment with security standards.
A serverless application that demonstrates common serverless security flaws and weaknesses
Comprehensive manual for mobile app security testing and reverse engineering with technical processes for verifying controls.
A vulnerable by design infrastructure on Azure featuring the latest released OWASP Top 10 web application security risks (2021) and other misconfigurations.
A non-profit organization focused on improving the security of software through resources and training.
OWASP offers essential resources and community support to enhance application security.
WackoPicko is a vulnerable website with known vulnerabilities, now available as a Docker image and included in the OWASP Broken Web Applications Project.