Curiefense is a new application security platform that extends Envoy proxy to defend against a variety of threats, including SQL and command injection, cross site scripting (XSS), account takeovers (ATOs), application-layer DDoS, remote file inclusion (RFI), API abuse, and more. It offers Getting Started Documentation, Quick Start Guide, FAQ, Docker support, and a Video Overview. Community involvement can be through Twitter, CNCF Community Group, and Slack. The project is named after the famous scientist Marie Salomea Skłodowska Curie and was released on her birthday (November 7th).
FEATURES
ALTERNATIVES
Deliberately vulnerable web application for educational purposes.
A script that implements Cognito attacks such as Account Oracle or Priviledge Escalation
A software supply chain security platform that analyzes binaries and software components to detect malware, vulnerabilities, exposed secrets, and tampering throughout the development lifecycle.
An open-source web application security scanner framework that identifies vulnerabilities in web applications.
An insecure web application with multiple vulnerable web service components for learning real-world web service vulnerabilities.
ffufai is an AI-enhanced wrapper for ffuf that automatically suggests file extensions for web fuzzing based on the target URL and headers.
A fake Django admin login screen to detect and notify admins of attempted unauthorized access
PINNED

InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

CTIChef.com Detection Feeds
A tiered cyber threat intelligence service providing detection rules from public repositories with varying levels of analysis, processing, and guidance for security teams.

ImmuniWeb® Discovery
ImmuniWeb Discovery is an attack surface management platform that continuously monitors an organization's external digital assets for security vulnerabilities, misconfigurations, and threats across domains, applications, cloud resources, and the dark web.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.