F5 Distributed Cloud WAF
A deliberately vulnerable modern day app with lots of DOM related bugs
Secure your applications with robust security measures. Protect against vulnerabilities and threats effectively.
A deliberately vulnerable modern day app with lots of DOM related bugs
OpenRASP directly integrates its protection engine into the application server by instrumentation, providing context-aware protection and detailed stack trace logging.
A developer-first, API-driven platform that provides development teams with a suite of tools to improve code quality, security, and engineering performance, seamlessly integrated into their existing development workflows.
Emulates browser functionality to detect exploits targeting browser vulnerabilities.
Gitleaks is a SAST tool for detecting and preventing hardcoded secrets in git repos.
An Application Security Posture Management platform that provides visibility, security controls, and automated workflows across the software development lifecycle from code to cloud.
A comprehensive toolkit for web application security testing, offering a range of products and solutions for identifying vulnerabilities and improving security posture.
An insecure web application with multiple vulnerable web service components for learning real-world web service vulnerabilities.
A developer-first, API-driven platform that provides development teams with a suite of tools to improve code quality, security, and engineering performance, seamlessly integrated into their existing development workflows.
A simple, secure framework for building scalable applications
A fake Django admin login screen to detect and notify admins of attempted unauthorized access
A cloud-based web application firewall that provides protection against web attacks, DDoS mitigation, and performance optimization through CDN capabilities.
Kiterunner is a tool for lightning-fast traditional content discovery and bruteforcing API endpoints in modern applications.
BunkerWeb is a next-generation and open-source Web Application Firewall (WAF) with seamless integration and user-friendly customization options.
IronBee is an open source project building a universal web application security sensor.
A simple Swagger-ui scanner that detects old versions vulnerable to various XSS attacks
Statistical renaming, Type inference, and Deobfuscation tool for JavaScript code.
Scan files for viruses and malware with language-agnostic REST API
APKiD is a tool that identifies compilers, packers, obfuscators, and other weird stuff in APK files.