This serverless application demonstrates common serverless security flaws as described in the Serverless Security Top 10 Weaknesses guide. Teach developers & security practitioners about common serverless application layer risks and weaknesses. Educate on how serverless application layer weaknesses can be exploited. Teach developers & security practitioners about serverless security best-practices. You can find more information about WebGoat at: https://www.owasp.org/index.php/OWASP_Serverless_Goat
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A security-focused general purpose memory allocator providing the malloc API with hardening against heap corruption vulnerabilities.
A source code search engine for searching alphanumeric snippets, signatures, or keywords in web page HTML, JS, and CSS code.
A brute-force protection middleware for express routes that rate-limits incoming requests.
Integrates static APK analysis with Yara and requires re-compilation of Yara with the androguard module.
A PHP port of Rack::Honeypot, a spam trap that detects and blocks spambots
A tool for detecting capabilities in executable files, providing insights into a program's behavior and potential malicious activities.
A web application security testing platform that helps you test your knowledge on web application security through realistic scenarios with known vulnerabilities.
A Java API for searching and downloading Android applications from Google Play with additional check-in features for generating ANDROID-ID.
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.