155 results for “topic:dast”
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
The ZAP by Checkmarx Core project
⚙️ A curated list of dynamic analysis tools and linters for all programming languages, binaries, and more.
ZAP Add-ons
A collection of ZAP scripts and tips provided by the community - pull requests very welcome!
AI-powered workflow automation and AI Agents platform for AppSec, Fuzzing & Offensive Security. Automate vulnerability discovery with intelligent fuzzing, AI-driven analysis, and a marketplace of security tools.
xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".
A GitHub Action for running the ZAP Full scan
SecHub provides a central API to test software with different security tools.
A GitHub Action for running the ZAP Baseline scan
Runs a scan using Dastardly by Burp Suite against a target site and creates a JUnit XML report for the scan on completion.
A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration
API Security Vulnerability Scanner designed to help you secure your APIs.
OWASP PTK - application security browser extension.
Sasori is a dynamic web crawler powered by Puppeteer, designed for lightning-fast endpoint discovery.
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
⚡️ Multiple target ZAP Scanning
Cake Fuzzer is a project that is meant to help automatically and continuously discover vulnerabilities in web applications created based on specific frameworks with very limited false positives.
Udemy Course on DevSecOps
:zap: Fast Web Security Scanner written in Rust based on Lua Scripts :waning_gibbous_moon: :crab:
Community curated list of nuclei templates for finding "unknown" security vulnerabilities.
Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities to assist and automate pentesting workflows.
The source of ZAP website
Security operations toolkit for AI coding agents. Give Claude Code 25+ skills to catch vulnerabilities, scan containers, detect secrets, and enforce policies automatically.
A GitHub Action for running the ZAP API scan
Curated list of security tools
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
Application security best practices and code implementations for Java developers. This project is intended for didactic purposes only, supporting my training course.
Security tools report parsers for Faradaysec.com
An implementation of infrastructure-as-code scanning using dynamic tooling.