This serverless application demonstrates common serverless security flaws as described in the Serverless Security Top 10 Weaknesses guide. Teach developers & security practitioners about common serverless application layer risks and weaknesses. Educate on how serverless application layer weaknesses can be exploited. Teach developers & security practitioners about serverless security best-practices. You can find more information about WebGoat at: https://www.owasp.org/index.php/OWASP_Serverless_Goat
FEATURES
ALTERNATIVES
A command-line tool that scans NPM packages and ZIP files to detect exposed secrets and sensitive credentials in source code and configuration files.
Pint is a PIN tool that exposes the PIN API to lua scripts, allowing dynamic instrumentation of binaries.
FingerprintJS is a client-side browser fingerprinting library that provides a unique visitor identifier unaffected by incognito mode.
EvoMaster is an open-source tool that automatically generates system-level test cases for web APIs using AI-driven techniques.
Guidelines for secure coding in Java SE to avoid bugs that could weaken security and open holes in Java's security features.
A simple Swagger-ui scanner that detects old versions vulnerable to various XSS attacks
Static security code scanner (SAST) for Node.js applications with Docker support and integrations with Slack.
A vulnerable by design infrastructure on Azure featuring the latest released OWASP Top 10 web application security risks (2021) and other misconfigurations.
PINNED

InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

System Two Security
An AI-powered platform that automates threat hunting and analysis by processing cyber threat intelligence and generating customized hunt packages for SOC teams.

Aikido Security
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.

Permiso
Permiso is an Identity Threat Detection and Response platform that provides comprehensive visibility and protection for identities across multiple cloud environments.

Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.

Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.