Vulnerable app with examples showing how to not use secrets
Platform-Agnostic Security Tokens
A list of useful payloads and bypass for Web Application Security
ezXSS is an easy way for penetration testers and bug bounty hunters
A single archive of public exploit PoCs and vulnerability research
A suite of Tools to aid Incidence Response and Live Forensics
CASL is an isomorphic authorization JavaScript library
All-in-one OSINT tool for analysing any website
Easy-to-use and powerful homomorphic encryption library
Skills for threat modeling, scanning, triage, patching, etc.
GTFOBins is a curated list of Unix binaries
A generic, spec-compliant, thorough implementation of the OAuth
Unlocking _everything_ on the CPU with DRAM scrambling
Cyberspace asset mapping and vulnerability scanning platform
High-level cryptography interface powered by libsodium
The safest & truly intuitive templates for PHP
Your web application for managing personal data
Generate probable usernames from LinkedIn company employee lists
OSS-Fuzz - continuous fuzzing for open source software
Open-source observability for microservices
A spec compliant, secure by default
Network security scanner for detecting severity vulnerabilities
Automate search engine dorking across hundreds of websites
Fast open source tool for discovering and monitoring domain subdomains
OAuth2 goodies for the Djangonauts!