<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>owasp</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/682/feed"/>
    <updated>2026-06-15T08:42:05+00:00</updated>
    <id>https://links.biapy.com/guest/tags/682/feed</id>
            <entry>
            <id>https://links.biapy.com/links/12804</id>
            <title type="text"><![CDATA[DockSec]]></title>
            <link rel="alternate" href="https://github.com/OWASP/DockSec" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12804"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI-Powered Docker Security Analyzer.

AI-powered Docker security scanner that explains vulnerabilities in plain English]]>
            </summary>
            <updated>2026-05-21T11:59:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12512</id>
            <title type="text"><![CDATA[hadrian]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/hadrian" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12512"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open-Source API Security Testing Framework.

API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven templates.

Hadrian is an open-source API security testing framework that detects OWASP API Top 10 vulnerabilities in REST, GraphQL, and gRPC APIs. It uses role-based authorization testing and YAML-driven templates to automatically find broken object-level authorization (BOLA), broken function-level authorization (BFLA), broken authentication, and other critical API security flaws — without writing custom test code.]]>
            </summary>
            <updated>2026-04-10T11:34:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12480</id>
            <title type="text"><![CDATA[Agent Governance Toolkit]]></title>
            <link rel="alternate" href="https://github.com/microsoft/agent-governance-toolkit" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12480"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10. 

Runtime governance for AI agents — the only toolkit covering all 10 OWASP Agentic risks with 9,500+ tests. Governs what agents do, not just what they say — deterministic policy enforcement, zero-trust identity, execution sandboxing, and SRE — Python · TypeScript · .NET · Rust · Go

Related contents:

- [Introducing the Agent Governance Toolkit: Open-source runtime security for AI agents @ Microsoft Open Source Blog](https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents/).
- [Microsoft&amp;#039;s Newest Open-Source Project: Runtime Security For AI Agents @ Phoronix](https://www.phoronix.com/news/Microsoft-AI-Agent-Governance).
- [Episode 661: Sink Your Claws In @ Linux Unplugged](https://linuxunplugged.com/661).]]>
            </summary>
            <updated>2026-04-09T06:18:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10647</id>
            <title type="text"><![CDATA[CycloneDX]]></title>
            <link rel="alternate" href="https://cyclonedx.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10647"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[CycloneDX Bill of Materials Standard.

CycloneDX is a modern standard for the software supply chain.

The International Standard for Bill of Materials (ECMA-424)
The OWASP Foundation and Ecma International Technical Committee for Software &amp;amp; System Transparency (TC54) drive the continued advancement of the specification.

- [CycloneDX BOM Standard @ GitHub](https://github.com/CycloneDX).

Related contents:

- [CycloneDX PHP Composer Plugin @ GitHub](https://github.com/CycloneDX/cyclonedx-php-composer).]]>
            </summary>
            <updated>2025-10-14T09:44:18+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10419</id>
            <title type="text"><![CDATA[bluemonday]]></title>
            <link rel="alternate" href="https://github.com/microcosm-cc/bluemonday" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10419"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS.

bluemonday takes untrusted user generated content as an input, and will return HTML that has been sanitised against an allowlist of approved HTML elements and attributes so that you can safely include the content in your web page.

Related contents:

- [Episode 132 @ Linux Dev Time](https://www.linuxdevtime.com/linux-dev-time-episode-132/).]]>
            </summary>
            <updated>2025-09-27T16:13:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10190</id>
            <title type="text"><![CDATA[TheAuditor]]></title>
            <link rel="alternate" href="https://github.com/TheAuditorTool/Auditor" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10190"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Antidote to VibeCoding.
Offline-First, AI-Centric SAST &amp;amp; Code Intelligence Platform.

Unlike traditional SAST tools, TheAuditor is designed specifically for AI-assisted development workflows, providing ground truth that both developers and AI assistants can trust.

Related contents:

- [TheAuditor - L&amp;#039;outil de sécurité qui rend vos assistants IA moins laxistes sur la sécurité de votre code @ Korben :fr:](https://korben.info/theauditor-outil-securite-sast-ia.html).]]>
            </summary>
            <updated>2025-09-15T08:46:45+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/567</id>
            <title type="text"><![CDATA[OWASP Nettacker]]></title>
            <link rel="alternate" href="https://owasp.org/www-project-nettacker/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/567"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management.

OWASP Nettacker project was created to automate information gathering, vulnerability scanning and in general to aid penetration testing engagements. Nettacker is able to run various scans using a variety of methods and generate scan reports(in HTML/TXT/JSON/CSV format) for applications and networks, including discovering open ports, services, bugs, vulnerabilities, misconfigurations, default credentials, subdomains, etc. Nettacker can be run as a command-line utility (including running as a Docker container), API, Web GUI mode or as Maltego transforms.

- [OWASP Nettacker @ GitHub](https://github.com/OWASP/Nettacker).]]>
            </summary>
            <updated>2025-08-28T17:32:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2247</id>
            <title type="text"><![CDATA[🔒 Patterns: OWASP CRS and Bad Bot Detection for Web Servers]]></title>
            <link rel="alternate" href="https://github.com/fabriziosalmi/patterns" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2247"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automated OWASP CRS and Bad Bot Detection for Caddy, Nginx, Apache, Traefik and HaProxy.

Automate the scraping of OWASP Core Rule Set (CRS) patterns and convert them into Apache, Nginx, Caddy, Traefik, and HAProxy WAF configurations.
Additionally, Bad Bot/User-Agent detection is integrated to block malicious web crawlers and scrapers.]]>
            </summary>
            <updated>2025-08-28T22:10:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3266</id>
            <title type="text"><![CDATA[Dependency-Track]]></title>
            <link rel="alternate" href="https://dependencytrack.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3266"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Software Bill of Materials (SBOM) Analysis.

- [Dependency-Track @ GitHub](https://github.com/DependencyTrack/dependency-track).
- [Démarrer avec Dependency Track @ Culture et Outils DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/analyser-code/dependency-track/).]]>
            </summary>
            <updated>2025-08-29T01:00:52+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4043</id>
            <title type="text"><![CDATA[OWASP Dependency-Check]]></title>
            <link rel="alternate" href="https://owasp.org/www-project-dependency-check/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4043"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Dependency-Check is a Software Composition Analysis (SCA) tool that attempts to detect publicly disclosed vulnerabilities contained within a project’s dependencies. It does this by determining if there is a Common Platform Enumeration (CPE) identifier for a given dependency. If found, it will generate a report linking to the associated CVE entries.

- [Dependency-Check @ GitHub](https://github.com/dependency-check/DependencyCheck).]]>
            </summary>
            <updated>2025-08-29T03:10:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4433</id>
            <title type="text"><![CDATA[PSCF - OWASP Product Security Capability Framework]]></title>
            <link rel="alternate" href="https://prods.ec/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4433"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[No more insecure software. Make sure your software delivery organization has the capabilities required to deliver secure products.

The OWASP Product Security Capability Framework (PSCF) is a comprehensive guide designed to frame and enhance the security of software products. By leveraging a structured approach to identify, implement, and manage security capabilities, the PSCF aims to improve product security and ensure compliance with regulatory and industry standards.

- [OWASP PSCF @ GitHub](https://github.com/OWASP/PSCF).
- [Reasonable 🔐AppSec \#43 - The Symbiotic Relationship Between Attack Trees and Threat Modeling, Five Security Articles, and Podcast Corner @ Reasonable Application Security](https://appsec.beehiiv.com/p/reasonable-appsec-43-symbiotic-relationship-attack-trees-threat-modeling-five-security-articles-podc).]]>
            </summary>
            <updated>2025-08-29T04:15:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4616</id>
            <title type="text"><![CDATA[shcheck]]></title>
            <link rel="alternate" href="https://github.com/santoru/shcheck" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4616"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A basic tool to check security headers of a website]]>
            </summary>
            <updated>2025-08-29T04:46:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4618</id>
            <title type="text"><![CDATA[OSTE meta scanner]]></title>
            <link rel="alternate" href="https://github.com/OSTEsayed/OSTE-Meta-Scan" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4618"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The OSTE meta scanner is a comprehensive web vulnerability scanner that combines multiple DAST scanners, including Nikto Scanner, OWASP ZAP, Nuclei, SkipFish, and Wapiti.]]>
            </summary>
            <updated>2025-08-29T04:46:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4652</id>
            <title type="text"><![CDATA[OWASP dep-scan]]></title>
            <link rel="alternate" href="https://github.com/owasp-dep-scan/dep-scan" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4652"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration with ASPM/VM platforms and in CI environments.]]>
            </summary>
            <updated>2025-08-29T04:51:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4702</id>
            <title type="text"><![CDATA[SessionProbe]]></title>
            <link rel="alternate" href="https://github.com/dub-flow/sessionprobe" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4702"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[SessionProbe is a multi-threaded tool designed for penetration testing and bug bounty hunting. It evaluates user privileges in web applications by taking a session token and checking access across a list of URLs, highlighting potential authorization issues. 

- [SessionProbe: Open-source multi-threaded pentesting tool @ Help Net Security](https://www.helpnetsecurity.com/2023/12/05/sessionprobe-open-source-multi-threaded-pentesting-tool/).]]>
            </summary>
            <updated>2025-08-29T05:00:52+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4887</id>
            <title type="text"><![CDATA[VAmPI]]></title>
            <link rel="alternate" href="https://github.com/erev0s/VAmPI" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4887"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Vulnerable REST API with OWASP top 10 vulnerabilities for security testing.

VAmPI is a vulnerable API made with Flask and it includes vulnerabilities from the OWASP top 10 vulnerabilities for APIs. It was created as I wanted a vulnerable API to evaluate the efficiency of tools used to detect security issues in APIs. It includes a switch on/off to allow the API to be vulnerable or not while testing. This allows to cover better the cases for false positives/negatives. VAmPI can also be used for learning/teaching purposes. You can find a bit more details about the vulnerabilities in erev0s.com.]]>
            </summary>
            <updated>2025-08-29T05:31:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4969</id>
            <title type="text"><![CDATA[OWASP Foundation]]></title>
            <link rel="alternate" href="https://owasp.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4969"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[the Open Source Foundation for Application Security.

- [OWASP Top 10 : comment (vraiment) sécuriser son API ? @ AXOPEN podcast :fr:](https://podcast.ausha.co/axopen/comment-vraiment-securiser-son-api-top-10-des-principes-de-l-owasp).]]>
            </summary>
            <updated>2025-08-29T05:45:14+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4998</id>
            <title type="text"><![CDATA[OWASP Amass]]></title>
            <link rel="alternate" href="https://owasp.org/www-project-amass/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4998"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The OWASP Amass Project performs network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.

The OWASP Amass Project has developed a framework to help information security professionals perform network mapping of attack surfaces and external asset discovery using open source intelligence gathering and reconnaissance techniques.

- [OWASP Amass](https://github.com/owasp-amass/amass).]]>
            </summary>
            <updated>2026-03-20T08:26:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5009</id>
            <title type="text"><![CDATA[OWASP Cheat Sheet Series]]></title>
            <link rel="alternate" href="https://cheatsheetseries.owasp.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5009"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics. These cheat sheets were created by various application security professionals who have expertise in specific topics.

[OWASP Cheat Sheet Series @ GitHub](https://github.com/OWASP/CheatSheetSeries).]]>
            </summary>
            <updated>2025-08-29T05:51:23+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6940</id>
            <title type="text"><![CDATA[OWASP WebGoat]]></title>
            <link rel="alternate" href="https://owasp.org/www-project-webgoat/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6940"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[WebGoat is a deliberately insecure application that allows interested developers just like you to test vulnerabilities commonly found in Java-based applications that use common and popular open source components.

- [OWASP WebGoat @ GitHub](https://github.com/WebGoat/WebGoat).

Related contents:

- [WebGoat - Pour vous former au hacking éthique @ Korben :fr:](https://korben.info/webgoat-owasp-apprendre-hacking-ethique.html).]]>
            </summary>
            <updated>2025-09-29T10:19:08+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7099</id>
            <title type="text"><![CDATA[OWASP ZAP]]></title>
            <link rel="alternate" href="https://www.zaproxy.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7099"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The world&amp;#039;s most widely used web app scanner. Free and open source. Actively maintained by a dedicated international team of volunteers.

- [ZAP @ GitHub](https://github.com/zaproxy/zaproxy).

Related  contents:

- [Automating OWASP PTK with ZAP (Phase 1) @ ZAP](https://www.zaproxy.org/blog/2026-05-06-automating-owasp-ptk-with-zap-phase-1/).
- [Automating OWASP PTK with ZAP (Phase 2) @ ZAP](https://www.zaproxy.org/blog/2026-06-05-automating-owasp-ptk-with-zap-phase-2/).
- [Building a Scanner and a Community with Zed Attack Proxy - Simon Bennetts - ASW #254  @ YouTube](https://www.youtube.com/watch?v=alIBoz7AooI).
- [Strengthening Your Web Application Security: Integrating OWASP ZAP with GitHub Actions @ System Weakness](https://systemweakness.com/strengthening-your-web-application-security-integrating-owasp-zap-with-github-actions-2c177545f21d).]]>
            </summary>
            <updated>2026-06-11T06:09:27+00:00</updated>
        </entry>
    </feed>
