> For the complete documentation index, see [llms.txt](https://recondock.gitbook.io/recondock/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://recondock.gitbook.io/recondock/projects.md).

# Projects

![image](https://user-images.githubusercontent.com/51442719/174681694-04ad9911-e9f9-4685-927d-5498ae59cf07.png)

### Projects for Good

We are a community of developers, technologists and evangelists improving the security of software. The OWASP Foundation gives aspiring open source projects a platform to improve the security of software with:

* Visibility: Our website gets more than six million visitors a year
* Credibility: OWASP is well known in the AppSec community
* Resources: Funding and Project Summits are available for qualifying Programs
* Community: Our Conferences and Local Chapters connect Projects with users

OWASP Projects are a collection of related tasks that have a defined roadmap and team members. Our projects are open source and are built by our community of volunteers - people just like you! OWASP project leaders are responsible for defining the vision, roadmap, and tasks for the project. The project leader also promotes the project and builds the team. OWASP currently has over 100 active projects, and new project applications are submitted every week.

Code, software, reference material, documentation, and community all working to secure the world's software.

Projects gives members an opportunity to freely test theories and ideas with the professional advice and support of the OWASP community. Every project minimally has their own webpage, mailing list, and Slack Channel. Most projects maintain their content in our [GitHub organization](https://github.com/OWASP).

### Who Should Start an OWASP Project?

* Application Developers
* Software Architects
* Information Security Authors
* Those who would like the support of a world wide professional community to develop or test an idea.

### OWASP Projects, the SDLC, and the Security Wayfinder

Thanks to the OWASP Integration Standards Project for mapping OWASP projects in a diagram of the Software Development LifeCycle. This resource should help you determine which projects fit into your SDLC.

Requirements

Design

Docs

Implementation

Guides

After *N* Iterations

Verification

Metrics

Training/Education

Iterate

Culture Building & Process Maturing

Guides

Policy Gap Evaluation

Tools

Frameworks

Threat Modeling

CheatSheet Series

Proactive Controls

Go SCP

ZAP

Amass

Nettacker

OWTF

Secure\
Libraries

Dependency Track

Dependency Check

ESAPI

CSRFGuard

Vulnerability\
Management

Glue

Dracon

Defect Dojo

ASVS

MASVS

Threat Dragon

Threat Modeling Talks

PyTM

**Application Security Wayfinder**

Security Champions Playbook

SAMM

Code Pulse

Operation

Mod Security CRS

Cornucopia

SecurityRAT

Top 10

Juice \
Shop

Security Shepherd

API Top 10

Mobile Top 10

WebGoat

PyGoat

Snakes & Ladders

WSTG

MSTG

SAMM

ASVS

MASVS

ASVS

MASVS

SKF

Brought to you by the Integration standards project

Linking requirements and guidance across standards through the Common Requirement Enumeration.

Dependencies

### OWASP Project Inventory (255)

All OWASP tools, document, and code library projects are organized into the following categories:

**Flagship Projects:** The OWASP Flagship designation is given to projects that have demonstrated strategic value to OWASP and application security as a whole.\
**Lab Projects:** OWASP Labs projects represent projects that have produced an OWASP reviewed deliverable of value.\
**Incubator Projects:** OWASP Incubator projects represent the experimental playground where projects are still being fleshed out, ideas are still being proven, and development is still underway.

#### List of Projects by Level or Type

#### Flagship Projects ![Flagship](https://owasp.org/assets/images/common/owasp_level_flagship.svg)

* [OWASP Amass](https://owasp.org/www-project-amass/)
* [OWASP Application Security Verification Standard](https://owasp.org/www-project-application-security-verification-standard/)
* [OWASP Cheat Sheet Series](https://owasp.org/www-project-cheat-sheets/)
* [OWASP CSRFGuard](https://owasp.org/www-project-csrfguard/)
* [OWASP CycloneDX](https://owasp.org/www-project-cyclonedx/)
* [OWASP Defectdojo](https://owasp.org/www-project-defectdojo/)
* [OWASP Dependency-Check](https://owasp.org/www-project-dependency-check/)
* [OWASP Dependency-Track](https://owasp.org/www-project-dependency-track/)
* [OWASP Juice Shop](https://owasp.org/www-project-juice-shop/)
* [OWASP Mobile Security Testing Guide](https://owasp.org/www-project-mobile-security-testing-guide/)
* [OWASP ModSecurity Core Rule Set](https://owasp.org/www-project-modsecurity-core-rule-set/)
* [OWASP OWTF](https://owasp.org/www-project-owtf/)
* [OWASP SAMM](https://owasp.org/www-project-samm/)
* [OWASP Security Knowledge Framework](https://owasp.org/www-project-security-knowledge-framework/)
* [OWASP Security Shepherd](https://owasp.org/www-project-security-shepherd/)
* [OWASP Top Ten](https://owasp.org/www-project-top-ten/)
* [OWASP Web Security Testing Guide](https://owasp.org/www-project-web-security-testing-guide/)
* [OWASP ZAP](https://owasp.org/www-project-zap/)

#### Lab Projects ![Lab](https://owasp.org/assets/images/common/owasp_level_labs.svg)

* [OWASP AntiSamy](https://owasp.org/www-project-antisamy/)
* [OWASP API Security Project](https://owasp.org/www-project-api-security/)
* [OWASP Attack Surface Detector](https://owasp.org/www-project-attack-surface-detector/)
* [OWASP Automated Threats to Web Applications](https://owasp.org/www-project-automated-threats-to-web-applications/)
* [OWASP Benchmark](https://owasp.org/www-project-benchmark/)
* [OWASP Code Pulse](https://owasp.org/www-project-code-pulse/)
* [OWASP Code Review Guide](https://owasp.org/www-project-code-review-guide/)
* [OWASP Coraza Web Application Firewall](https://owasp.org/www-project-coraza-web-application-firewall/)
* [OWASP Cornucopia](https://owasp.org/www-project-cornucopia/)
* [OWASP Devsecops Maturity Model](https://owasp.org/www-project-devsecops-maturity-model/)
* [OWASP Enterprise Security API (ESAPI)](https://owasp.org/www-project-enterprise-security-api/)
* [OWASP Find Security Bugs](https://owasp.org/www-project-find-security-bugs/)
* [OWASP Integration Standards](https://owasp.org/www-project-integration-standards/)
* [OWASP Internet of Things](https://owasp.org/www-project-internet-of-things/)
* [OWASP Java HTML Sanitizer](https://owasp.org/www-project-java-html-sanitizer/)
* [OWASP mobile security](https://owasp.org/www-project-mobile-security/)
* [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/)
* [OWASP Mutillidae II](https://owasp.org/www-project-mutillidae-ii/)
* [OWASP Podcast](https://owasp.org/www-project-podcast/)
* [OWASP Proactive Controls](https://owasp.org/www-project-proactive-controls/)
* [OWASP pytm](https://owasp.org/www-project-pytm/)
* [OWASP SamuraiWTF](https://owasp.org/www-project-samuraiwtf/)
* [OWASP Secure Coding Dojo](https://owasp.org/www-project-secure-coding-dojo/)
* [OWASP secureCodeBox](https://owasp.org/www-project-securecodebox/)
* [OWASP SecureTea Project](https://owasp.org/www-project-securetea/)
* [OWASP Security Pins](https://owasp.org/www-project-security-pins/)
* [OWASP Snakes And Ladders](https://owasp.org/www-project-snakes-and-ladders/)
* [OWASP Software Component Verification Standard](https://owasp.org/www-project-software-component-verification-standard/)
* [OWASP Threat Dragon](https://owasp.org/www-project-threat-dragon/)
* [OWASP Top 10 Privacy Risks](https://owasp.org/www-project-top-10-privacy-risks/)
* [OWASP TorBot](https://owasp.org/www-project-torbot/)
* [OWASP Vulnerable Web Applications Directory](https://owasp.org/www-project-vulnerable-web-applications-directory/)
* [OWASP WebGoat](https://owasp.org/www-project-webgoat/)
* [OWASP WrongSecrets](https://owasp.org/www-project-wrongsecrets/)

#### Incubator Projects ![Incubator](https://owasp.org/assets/images/common/owasp_level_incubator.svg)

* [OWASP .Net](https://owasp.org/www-project-.net/)
* [OWASP aegis4j](https://owasp.org/www-project-aegis4j/)
* [OWASP Android Security Inspector Toolkit](https://owasp.org/www-project-android-security-inspector-toolkit/)
* [OWASP APICheck](https://owasp.org/www-project-apicheck/)
* [OWASP Application Gateway](https://owasp.org/www-project-application-gateway/)
* [OWASP Application Security Awareness Campaigns](https://owasp.org/www-project-application-security-awareness-campaigns/)
* [OWASP Appsec Pipeline](https://owasp.org/www-project-appsec-pipeline/)
* [OWASP Barbarus](https://owasp.org/www-project-barbarus/)
* [OWASP Big Data Security Verification Standard](https://owasp.org/www-project-big-data/)
* [OWASP Bug Logging Tool](https://owasp.org/www-project-bug-logging-tool/)
* [OWASP Cloud-Native Security Project](https://owasp.org/www-project-cloud-native-security-project/)
* [OWASP Code the Flag](https://owasp.org/www-project-code-the-flag/)
* [OWASP Core Business Application Security](https://owasp.org/www-project-core-business-application-security/)
* [OWASP CSRFProtector Project](https://owasp.org/www-project-csrfprotector/)
* [OWASP Cyber Controls Matrix (OCCM)](https://owasp.org/www-project-cyber-controls-matrix/)
* [OWASP Cyber Defense Framework](https://owasp.org/www-project-cyber-defense-framework/)
* [OWASP Cyber Defense Matrix](https://owasp.org/www-project-cyber-defense-matrix/)
* [OWASP Cyber Scavenger Hunt](https://owasp.org/www-project-cyber-scavenger-hunt/)
* [OWASP D4N155](https://owasp.org/www-project-d4n155/)
* [OWASP Data Security Top 10](https://owasp.org/www-project-data-security-top-10/)
* [OWASP Desktop App Security Top 10](https://owasp.org/www-project-desktop-app-security-top-10/)
* [OWASP AppSec Days Developer Outreach Program](https://owasp.org/www-project-developer-outreach-program/)
* [OWASP DevSlop](https://owasp.org/www-project-devslop/)
* [OWASP Docker Top 10](https://owasp.org/www-project-docker-top-10/)
* [OWASP DPD (DDOS Prevention using DPI)](https://owasp.org/www-project-dpd/)
* [OWASP G0rKing](https://owasp.org/www-project-g0rking/)
* [OWASP Go Secure Coding Practices Guide](https://owasp.org/www-project-go-secure-coding-practices-guide/)
* [OWASP Honeypot](https://owasp.org/www-project-honeypot/)
* [OWASP How to Get Into AppSec](https://owasp.org/www-project-how-to-get-into-appsec/)
* [OWASP Information Security Metrics Bank](https://owasp.org/www-project-information-security-metrics-bank/)
* [OWASP Kubernetes Top Ten](https://owasp.org/www-project-kubernetes-top-ten/)
* [OWASP Maryam](https://owasp.org/www-project-maryam/)
* [OWASP Mobile Audit](https://owasp.org/www-project-mobile-audit/)
* [OWASP Nettacker](https://owasp.org/www-project-nettacker/)
* [OWASP Nightingale](https://owasp.org/www-project-nightingale/)
* [OWASP Node.js Goat](https://owasp.org/www-project-node.js-goat/)
* [OWASP O-Saft](https://owasp.org/www-project-o-saft/)
* [OWASP Ontology Driven Threat Modeling Framework](https://owasp.org/www-project-ontology-driven-threat-modeling-framework/)
* [OWASP Open Source Security Application Platform](https://owasp.org/www-project-open-source-security-application-platform/)
* [OWASP Patton](https://owasp.org/www-project-patton/)
* [OWASP Penetration Testing Kit](https://owasp.org/www-project-penetration-testing-kit/)
* [OWASP PenText](https://owasp.org/www-project-pentext/)
* [OWASP Port and Service Information](https://owasp.org/www-project-port-and-service-information/)
* [OWASP PurpleTeam](https://owasp.org/www-project-purpleteam/)
* [OWASP Pygoat](https://owasp.org/www-project-pygoat/)
* [OWASP Raider](https://owasp.org/www-project-raider/)
* [OWASP Risk Assessment Framework](https://owasp.org/www-project-risk-assessment-framework/)
* [OWASP Sectudo](https://owasp.org/www-project-sectudo/)
* [OWASP Secure Headers Project](https://owasp.org/www-project-secure-headers/)
* [OWASP Secure Logging Benchmark](https://owasp.org/www-project-secure-logging-benchmark/)
* [OWASP SecureFlag Open Platform](https://owasp.org/www-project-secureflag-open-platform/)
* [OWASP Security Culture](https://owasp.org/www-project-security-culture/)
* [OWASP Security Qualitative Metrics](https://owasp.org/www-project-security-qualitative-metrics/)
* [OWASP SecurityRAT](https://owasp.org/www-project-securityrat/)
* [OWASP Serverless Top 10](https://owasp.org/www-project-serverless-top-10/)
* [OWASP SideKEK](https://owasp.org/www-project-sidekek/)
* [OWASP Snow](https://owasp.org/www-project-snow/)
* [OWASP Project Spotlight Series](https://owasp.org/www-project-spotlight-series/)
* [OWASP Single Sign-On](https://owasp.org/www-project-sso/)
* [OWASP Thick Client Security Testing Guide](https://owasp.org/www-project-thick-client-security-testing-guide/)
* [OWASP Threat and Safeguard Matrix (TaSM)](https://owasp.org/www-project-threat-and-safeguard-matrix/)
* [OWASP Threat Modeling Project](https://owasp.org/www-project-threat-model/)
* [OWASP Threat Model Cookbook](https://owasp.org/www-project-threat-model-cookbook/)
* [OWASP Threat Modeling Playbook (OTMP)](https://owasp.org/www-project-threat-modeling-playbook/)
* [OWASP TimeGap Theory](https://owasp.org/www-project-timegap-theory/)
* [OWASP Top 10 Card Game](https://owasp.org/www-project-top-10-card-game/)
* [OWASP Top 10 Client-Side Security Risks](https://owasp.org/www-project-top-10-client-side-security-risks/)
* [OWASP Top 10 Low-Code/No-Code Security Risks](https://owasp.org/www-project-top-10-low-code-no-code-security-risks/)
* [OWASP Vulnerability Management Center](https://owasp.org/www-project-vulnerability-management-center/)
* [OWASP Vulnerability Management Guide](https://owasp.org/www-project-vulnerability-management-guide/)
* [OWASP VulnerableApp](https://owasp.org/www-project-vulnerableapp/)
* [OWASP VulnerableApp-Facade](https://owasp.org/www-project-vulnerableapp-facade/)
* [OWASP Web Application Firewall Evaluation Criteria Project (WAFEC)](https://owasp.org/www-project-wafec/)
* [OWASP Web Mapper](https://owasp.org/www-project-web-mapper/)
* [OWASP Web Testing Environment](https://owasp.org/www-project-web-testing-environment/)

#### Projects Needing Website Update

* [OWASP Access Log Parser](https://owasp.org/www-project-access-log-parser/)
* [OWASP AndroGoat](https://owasp.org/www-project-androgoat/)
* [OWASP Anti-Ransomware Guide](https://owasp.org/www-project-anti-ransomware-guide/)
* [OWASP Application Security Curriculum](https://owasp.org/www-project-application-security-curriculum/)
* [OWASP Application Security Hardening](https://owasp.org/www-project-application-security-hardening/)
* [OWASP AppSec Minimum Requirements](https://owasp.org/www-project-appsec-minimum-requirements/)
* [OWASP Auth](https://owasp.org/www-project-auth/)
* [OWASP belva](https://owasp.org/www-project-belva/)
* [OWASP Best Practices In Vulnerability Disclosure And Bug Bounty Programs](https://owasp.org/www-project-best-practices-in-vulnerability-disclosure-and-bug-bounty-programs/)
* [OWASP Blend](https://owasp.org/www-project-blend/)
* [OWASP Blockchain Distributed Infrastructure](https://owasp.org/www-project-blockchain-distributed-infrastructure/)
* [OWASP Broken Web Applications](https://owasp.org/www-project-broken-web-applications/)
* [OWASP ChainGoat](https://owasp.org/www-project-chaingoat/)
* [OWASP cloud security](https://owasp.org/www-project-cloud-security/)
* [OWASP Cloud Security Mentor](https://owasp.org/www-project-cloud-security-mentor/)
* [OWASP Cloud Security Testing Guide](https://owasp.org/www-project-cloud-security-testing-guide/)
* [OWASP Cloud Testing Guide](https://owasp.org/www-project-cloud-testing-guide/)
* [OWASP CloudSheep](https://owasp.org/www-project-cloudsheep/)
* [OWASP Container Security Verification Standard](https://owasp.org/www-project-container-security-verification-standard/)
* [OWASP Ctf](https://owasp.org/www-project-ctf/)
* [OWASP Cyber Security Enterprise Operations Architecture](https://owasp.org/www-project-cyber-security-enterprise-operations-architecture/)
* [OWASP Cybersecurity Risk Register](https://owasp.org/www-project-cybersecurity-risk-register/)
* [OWASP Damn Vulnerable Crypto Wallet](https://owasp.org/www-project-damn-vulnerable-crypto-wallet/)
* [OWASP Damn Vulnerable Thick Client Application](https://owasp.org/www-project-damn-vulnerable-thick-client-application/)
* [OWASP deepviolet-tls-ssl-scanner](https://owasp.org/www-project-deepviolet-tls-ssl-scanner/)
* [OWASP DevSecOps Verification Standard](https://owasp.org/www-project-devsecops-verification-standard/)
* [OWASP Drill](https://owasp.org/www-project-drill/)
* [OWASP Ende](https://owasp.org/www-project-ende/)
* [OWASP Financial Systems Security](https://owasp.org/www-project-financial-systems-security/)
* [OWASP Game Security Framework](https://owasp.org/www-project-game-security-framework/)
* [OWASP Glue Tool](https://owasp.org/www-project-glue-tool/)
* [OWASP hacking-lab](https://owasp.org/www-project-hacking-lab/)
* [OWASP Igoat Tool](https://owasp.org/www-project-igoat-tool/)
* [OWASP Incident Response](https://owasp.org/www-project-incident-response/)
* [OWASP InjectBot](https://owasp.org/www-project-injectbot/)
* [OWASP internet of things top 10](https://owasp.org/www-project-internet-of-things-top-10/)
* [OWASP Iot Analytics 4Industry4](https://owasp.org/www-project-iot-analytics-4industry4/)
* [OWASP JavaScript Security](https://owasp.org/www-project-javascript-security/)
* [OWASP Joomscan](https://owasp.org/www-project-joomscan/)
* [OWASP Jotp](https://owasp.org/www-project-jotp/)
* [OWASP Json Sanitizer](https://owasp.org/www-project-json-sanitizer/)
* [OWASP jvmxray](https://owasp.org/www-project-jvmxray/)
* [OWASP Knowledge Based Authentication Performance Metrics](https://owasp.org/www-project-knowledge-based-authentication-performance-metrics/)
* [OWASP Laravel Goat](https://owasp.org/www-project-laravel-goat/)
* [OWASP Learning Gateway](https://owasp.org/www-project-learning-gateway/)
* [OWASP little web application firewall](https://owasp.org/www-project-little-web-application-firewall/)
* [OWASP Lock It](https://owasp.org/www-project-lock-it/)
* [OWASP Low Code Security](https://owasp.org/www-project-low-code-security/)
* [OWASP Machine Learning Security Top 10](https://owasp.org/www-project-machine-learning-security-top-10/)
* [OWASP Mth3L3M3Nt Framework](https://owasp.org/www-project-mth3l3m3nt-framework/)
* [OWASP Nasi Lemak](https://owasp.org/www-project-nasi-lemak/)
* [OWASP O2 Platform](https://owasp.org/www-project-o2-platform/)
* [OWASP Off The Record 4 Java](https://owasp.org/www-project-off-the-record-4-java/)
* [OWASP Online Academy](https://owasp.org/www-project-online-academy/)
* [OWASP Open AppSec Tooling API](https://owasp.org/www-project-open-appsec-tooling-api/)
* [OWASP Passfault](https://owasp.org/www-project-passfault/)
* [OWASP Php](https://owasp.org/www-project-php/)
* [OWASP Php Security Training](https://owasp.org/www-project-php-security-training/)
* [OWASP Python Honeypot](https://owasp.org/www-project-python-honeypot/)
* [OWASP Python Security](https://owasp.org/www-project-python-security/)
* [OWASP Pyttacker](https://owasp.org/www-project-pyttacker/)
* [OWASP Qrljacker](https://owasp.org/www-project-qrljacker/)
* [OWASP rat](https://owasp.org/www-project-rat/)
* [OWASP Redteam Toolkit](https://owasp.org/www-project-redteam-toolkit/)
* [OWASP Revelo](https://owasp.org/www-project-revelo/)
* [OWASP Reverse Engineering And Code Modification Prevention](https://owasp.org/www-project-reverse-engineering-and-code-modification-prevention/)
* [OWASP Seclists](https://owasp.org/www-project-seclists/)
* [OWASP Secure Coding Practices-Quick Reference Guide](https://owasp.org/www-project-secure-coding-practices-quick-reference-guide/)
* [OWASP Secure Medical Device Deployment Standard](https://owasp.org/www-project-secure-medical-device-deployment-standard/)
* [OWASP Security Busters](https://owasp.org/www-project-security-busters/)
* [OWASP Security Champions Guidebook](https://owasp.org/www-project-security-champions-guidebook/)
* [OWASP Security Integration System](https://owasp.org/www-project-security-integration-system/)
* [OWASP Security Logging](https://owasp.org/www-project-security-logging/)
* [OWASP Security Resource Framework](https://owasp.org/www-project-security-resource-framework/)
* [OWASP SEDATED®](https://owasp.org/www-project-sedated/)
* [OWASP Seeker](https://owasp.org/www-project-seeker/)
* [OWASP Software Composition Security](https://owasp.org/www-project-software-composition-security/)
* [OWASP SupplyChainGoat](https://owasp.org/www-project-supplychaingoat/)
* [OWASP Threatspec](https://owasp.org/www-project-threatspec/)
* [OWASP TOCTOURex](https://owasp.org/www-project-toctourex/)
* [OWASP Top 10 Fuer Entwickler](https://owasp.org/www-project-top-10-fuer-entwickler/)
* [OWASP University Challenge](https://owasp.org/www-project-university-challenge/)
* [OWASP Vbscan](https://owasp.org/www-project-vbscan/)
* [OWASP Vicnum](https://owasp.org/www-project-vicnum/)
* [OWASP Virtual Patching Best Practices](https://owasp.org/www-project-virtual-patching-best-practices/)
* [OWASP VITCC Open Source Initiative](https://owasp.org/www-project-vitcc-open-source-initiative/)
* [OWASP Voice Automated Application Security](https://owasp.org/www-project-voice-automated-application-security/)
* [OWASP Vue 3 Password Input](https://owasp.org/www-project-vue-3-password-input/)
* [OWASP Vulnerable Web Application](https://owasp.org/www-project-vulnerable-web-application/)
* [OWASP webgoat php](https://owasp.org/www-project-webgoat-php/)
* [OWASP Webspa](https://owasp.org/www-project-webspa/)
* [OWASP Wpbullet](https://owasp.org/www-project-wpbullet/)
* [OWASP Zsc Tool](https://owasp.org/www-project-zsc-tool/)

### Standards Projects

### Tool Projects

* [OWASP Amass](https://owasp.org/www-project-amass/)
* [OWASP CSRFGuard](https://owasp.org/www-project-csrfguard/)
* [OWASP Defectdojo](https://owasp.org/www-project-defectdojo/)
* [OWASP Dependency-Check](https://owasp.org/www-project-dependency-check/)
* [OWASP Dependency-Track](https://owasp.org/www-project-dependency-track/)
* [OWASP Juice Shop](https://owasp.org/www-project-juice-shop/)
* [OWASP OWTF](https://owasp.org/www-project-owtf/)
* [OWASP Security Knowledge Framework](https://owasp.org/www-project-security-knowledge-framework/)
* [OWASP Security Shepherd](https://owasp.org/www-project-security-shepherd/)
* [OWASP ZAP](https://owasp.org/www-project-zap/)
* [OWASP AntiSamy](https://owasp.org/www-project-antisamy/)
* [OWASP Attack Surface Detector](https://owasp.org/www-project-attack-surface-detector/)
* [OWASP Benchmark](https://owasp.org/www-project-benchmark/)
* [OWASP Code Pulse](https://owasp.org/www-project-code-pulse/)
* [OWASP Find Security Bugs](https://owasp.org/www-project-find-security-bugs/)
* [OWASP Java HTML Sanitizer](https://owasp.org/www-project-java-html-sanitizer/)
* [OWASP pytm](https://owasp.org/www-project-pytm/)
* [OWASP secureCodeBox](https://owasp.org/www-project-securecodebox/)
* [OWASP SecureTea Project](https://owasp.org/www-project-securetea/)
* [OWASP Threat Dragon](https://owasp.org/www-project-threat-dragon/)
* [OWASP WebGoat](https://owasp.org/www-project-webgoat/)
* [OWASP WrongSecrets](https://owasp.org/www-project-wrongsecrets/)
* [OWASP APICheck](https://owasp.org/www-project-apicheck/)
* [OWASP Application Gateway](https://owasp.org/www-project-application-gateway/)
* [OWASP Bug Logging Tool](https://owasp.org/www-project-bug-logging-tool/)
* [OWASP G0rKing](https://owasp.org/www-project-g0rking/)
* [OWASP Maryam](https://owasp.org/www-project-maryam/)
* [OWASP Mobile Audit](https://owasp.org/www-project-mobile-audit/)
* [OWASP Nettacker](https://owasp.org/www-project-nettacker/)
* [OWASP Nightingale](https://owasp.org/www-project-nightingale/)
* [OWASP O-Saft](https://owasp.org/www-project-o-saft/)
* [OWASP Ontology Driven Threat Modeling Framework](https://owasp.org/www-project-ontology-driven-threat-modeling-framework/)
* [OWASP Patton](https://owasp.org/www-project-patton/)
* [OWASP PenText](https://owasp.org/www-project-pentext/)
* [OWASP PurpleTeam](https://owasp.org/www-project-purpleteam/)
* [OWASP Raider](https://owasp.org/www-project-raider/)
* [OWASP Risk Assessment Framework](https://owasp.org/www-project-risk-assessment-framework/)
* [OWASP SecureFlag Open Platform](https://owasp.org/www-project-secureflag-open-platform/)
* [OWASP SecurityRAT](https://owasp.org/www-project-securityrat/)
* [OWASP Single Sign-On](https://owasp.org/www-project-sso/)
* [OWASP Web Testing Environment](https://owasp.org/www-project-web-testing-environment/)
* [OWASP AWScanner](https://owasp.org/www-project-awscanner/)
* [OWASP crAPI](https://owasp.org/www-project-crapi/)
* [OWASP SecureBank](https://owasp.org/www-project-securebank/)
* [OWASP WinFIM.NET](https://owasp.org/www-project-winfim.net/)
* [OWASP Intelligent Intrusion Detection System](https://owasp.org/www-project-intelligent-intrusion-detection-system/)
* [OWASP Jupiter](https://owasp.org/www-project-jupiter/)
* [OWASP Seraphimdroid](https://owasp.org/www-project-seraphimdroid/)
* [OWASP belva](https://owasp.org/www-project-belva/)
* [OWASP Broken Web Applications](https://owasp.org/www-project-broken-web-applications/)
* [OWASP Damn Vulnerable Crypto Wallet](https://owasp.org/www-project-damn-vulnerable-crypto-wallet/)
* [OWASP Ende](https://owasp.org/www-project-ende/)
* [OWASP Glue Tool](https://owasp.org/www-project-glue-tool/)
* [OWASP Igoat Tool](https://owasp.org/www-project-igoat-tool/)
* [OWASP Jotp](https://owasp.org/www-project-jotp/)
* [OWASP Mth3L3M3Nt Framework](https://owasp.org/www-project-mth3l3m3nt-framework/)
* [OWASP O2 Platform](https://owasp.org/www-project-o2-platform/)
* [OWASP Passfault](https://owasp.org/www-project-passfault/)
* [OWASP Php Security Training](https://owasp.org/www-project-php-security-training/)
* [OWASP Python Honeypot](https://owasp.org/www-project-python-honeypot/)
* [OWASP Python Security](https://owasp.org/www-project-python-security/)
* [OWASP Pyttacker](https://owasp.org/www-project-pyttacker/)
* [OWASP Qrljacker](https://owasp.org/www-project-qrljacker/)
* [OWASP rat](https://owasp.org/www-project-rat/)
* [OWASP Revelo](https://owasp.org/www-project-revelo/)
* [OWASP Security Integration System](https://owasp.org/www-project-security-integration-system/)
* [OWASP Seeker](https://owasp.org/www-project-seeker/)
* [OWASP Vbscan](https://owasp.org/www-project-vbscan/)
* [OWASP Vicnum](https://owasp.org/www-project-vicnum/)
* [OWASP Voice Automated Application Security](https://owasp.org/www-project-voice-automated-application-security/)
* [OWASP webgoat php](https://owasp.org/www-project-webgoat-php/)
* [OWASP Webspa](https://owasp.org/www-project-webspa/)
* [OWASP Wpbullet](https://owasp.org/www-project-wpbullet/)
* [OWASP Zsc Tool](https://owasp.org/www-project-zsc-tool/)

### Documentation Projects

* [OWASP Cheat Sheet Series](https://owasp.org/www-project-cheat-sheets/)
* [OWASP Mobile Security Testing Guide](https://owasp.org/www-project-mobile-security-testing-guide/)
* [OWASP SAMM](https://owasp.org/www-project-samm/)
* [OWASP Top Ten](https://owasp.org/www-project-top-ten/)
* [OWASP Web Security Testing Guide](https://owasp.org/www-project-web-security-testing-guide/)
* [OWASP API Security Project](https://owasp.org/www-project-api-security/)
* [OWASP Automated Threats to Web Applications](https://owasp.org/www-project-automated-threats-to-web-applications/)
* [OWASP Code Review Guide](https://owasp.org/www-project-code-review-guide/)
* [OWASP Cornucopia](https://owasp.org/www-project-cornucopia/)
* [OWASP Devsecops Maturity Model](https://owasp.org/www-project-devsecops-maturity-model/)
* [OWASP Integration Standards](https://owasp.org/www-project-integration-standards/)
* [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/)
* [OWASP Proactive Controls](https://owasp.org/www-project-proactive-controls/)
* [OWASP Security Pins](https://owasp.org/www-project-security-pins/)
* [OWASP Snakes And Ladders](https://owasp.org/www-project-snakes-and-ladders/)
* [OWASP Software Component Verification Standard](https://owasp.org/www-project-software-component-verification-standard/)
* [OWASP Top 10 Privacy Risks](https://owasp.org/www-project-top-10-privacy-risks/)
* [OWASP TorBot](https://owasp.org/www-project-torbot/)
* [OWASP Vulnerable Web Applications Directory](https://owasp.org/www-project-vulnerable-web-applications-directory/)
* [OWASP .Net](https://owasp.org/www-project-.net/)
* [OWASP Application Security Awareness Campaigns](https://owasp.org/www-project-application-security-awareness-campaigns/)
* [OWASP Appsec Pipeline](https://owasp.org/www-project-appsec-pipeline/)
* [OWASP Cloud-Native Security Project](https://owasp.org/www-project-cloud-native-security-project/)
* [OWASP Cyber Controls Matrix (OCCM)](https://owasp.org/www-project-cyber-controls-matrix/)
* [OWASP Cyber Defense Matrix](https://owasp.org/www-project-cyber-defense-matrix/)
* [OWASP Data Security Top 10](https://owasp.org/www-project-data-security-top-10/)
* [OWASP Desktop App Security Top 10](https://owasp.org/www-project-desktop-app-security-top-10/)
* [OWASP DevSlop](https://owasp.org/www-project-devslop/)
* [OWASP Docker Top 10](https://owasp.org/www-project-docker-top-10/)
* [OWASP Go Secure Coding Practices Guide](https://owasp.org/www-project-go-secure-coding-practices-guide/)
* [OWASP Honeypot](https://owasp.org/www-project-honeypot/)
* [OWASP Information Security Metrics Bank](https://owasp.org/www-project-information-security-metrics-bank/)
* [OWASP Secure Headers Project](https://owasp.org/www-project-secure-headers/)
* [OWASP Secure Logging Benchmark](https://owasp.org/www-project-secure-logging-benchmark/)
* [OWASP Security Culture](https://owasp.org/www-project-security-culture/)
* [OWASP Security Qualitative Metrics](https://owasp.org/www-project-security-qualitative-metrics/)
* [OWASP Serverless Top 10](https://owasp.org/www-project-serverless-top-10/)
* [OWASP Threat and Safeguard Matrix (TaSM)](https://owasp.org/www-project-threat-and-safeguard-matrix/)
* [OWASP Threat Modeling Project](https://owasp.org/www-project-threat-model/)
* [OWASP Threat Model Cookbook](https://owasp.org/www-project-threat-model-cookbook/)
* [OWASP Threat Modeling Playbook (OTMP)](https://owasp.org/www-project-threat-modeling-playbook/)
* [OWASP Top 10 Card Game](https://owasp.org/www-project-top-10-card-game/)
* [OWASP Top 10 Client-Side Security Risks](https://owasp.org/www-project-top-10-client-side-security-risks/)
* [OWASP Top 10 Low-Code/No-Code Security Risks](https://owasp.org/www-project-top-10-low-code-no-code-security-risks/)
* [OWASP Vulnerability Management Guide](https://owasp.org/www-project-vulnerability-management-guide/)
* [OWASP Web Mapper](https://owasp.org/www-project-web-mapper/)
* [OWASP AppSensor](https://owasp.org/www-project-appsensor/)
* [OWASP Cloud-Native Application Security Top 10](https://owasp.org/www-project-cloud-native-application-security-top-10/)
* [OWASP DevSecOps Guideline](https://owasp.org/www-project-devsecops-guideline/)
* [OWASP Embedded Application Security](https://owasp.org/www-project-embedded-application-security/)
* [OWASP Software Security 5D Framework](https://owasp.org/www-project-software-security-5d-framework/)
* [OWASP Anti-Ransomware Guide](https://owasp.org/www-project-anti-ransomware-guide/)
* [OWASP Application Security Curriculum](https://owasp.org/www-project-application-security-curriculum/)
* [OWASP Best Practices In Vulnerability Disclosure And Bug Bounty Programs](https://owasp.org/www-project-best-practices-in-vulnerability-disclosure-and-bug-bounty-programs/)
* [OWASP cloud security](https://owasp.org/www-project-cloud-security/)
* [OWASP Cloud Testing Guide](https://owasp.org/www-project-cloud-testing-guide/)
* [OWASP Container Security Verification Standard](https://owasp.org/www-project-container-security-verification-standard/)
* [OWASP Ctf](https://owasp.org/www-project-ctf/)
* [OWASP Game Security Framework](https://owasp.org/www-project-game-security-framework/)
* [OWASP hacking-lab](https://owasp.org/www-project-hacking-lab/)
* [OWASP Incident Response](https://owasp.org/www-project-incident-response/)
* [OWASP internet of things top 10](https://owasp.org/www-project-internet-of-things-top-10/)
* [OWASP Iot Analytics 4Industry4](https://owasp.org/www-project-iot-analytics-4industry4/)
* [OWASP Knowledge Based Authentication Performance Metrics](https://owasp.org/www-project-knowledge-based-authentication-performance-metrics/)
* [OWASP Machine Learning Security Top 10](https://owasp.org/www-project-machine-learning-security-top-10/)
* [OWASP Php](https://owasp.org/www-project-php/)
* [OWASP Reverse Engineering And Code Modification Prevention](https://owasp.org/www-project-reverse-engineering-and-code-modification-prevention/)
* [OWASP Seclists](https://owasp.org/www-project-seclists/)
* [OWASP Secure Coding Practices-Quick Reference Guide](https://owasp.org/www-project-secure-coding-practices-quick-reference-guide/)
* [OWASP Secure Medical Device Deployment Standard](https://owasp.org/www-project-secure-medical-device-deployment-standard/)
* [OWASP Security Busters](https://owasp.org/www-project-security-busters/)
* [OWASP Software Composition Security](https://owasp.org/www-project-software-composition-security/)
* [OWASP Top 10 Fuer Entwickler](https://owasp.org/www-project-top-10-fuer-entwickler/)
* [OWASP University Challenge](https://owasp.org/www-project-university-challenge/)
* [OWASP Virtual Patching Best Practices](https://owasp.org/www-project-virtual-patching-best-practices/)

### Code Projects

* [OWASP ModSecurity Core Rule Set](https://owasp.org/www-project-modsecurity-core-rule-set/)
* [OWASP Coraza Web Application Firewall](https://owasp.org/www-project-coraza-web-application-firewall/)
* [OWASP Enterprise Security API (ESAPI)](https://owasp.org/www-project-enterprise-security-api/)
* [OWASP Mutillidae II](https://owasp.org/www-project-mutillidae-ii/)
* [OWASP SamuraiWTF](https://owasp.org/www-project-samuraiwtf/)
* [OWASP Secure Coding Dojo](https://owasp.org/www-project-secure-coding-dojo/)
* [OWASP aegis4j](https://owasp.org/www-project-aegis4j/)
* [OWASP Barbarus](https://owasp.org/www-project-barbarus/)
* [OWASP CSRFProtector Project](https://owasp.org/www-project-csrfprotector/)
* [OWASP Cyber Scavenger Hunt](https://owasp.org/www-project-cyber-scavenger-hunt/)
* [OWASP Node.js Goat](https://owasp.org/www-project-node.js-goat/)
* [OWASP Penetration Testing Kit](https://owasp.org/www-project-penetration-testing-kit/)
* [OWASP SideKEK](https://owasp.org/www-project-sidekek/)
* [OWASP TimeGap Theory](https://owasp.org/www-project-timegap-theory/)
* [OWASP VulnerableApp](https://owasp.org/www-project-vulnerableapp/)
* [OWASP VulnerableApp-Facade](https://owasp.org/www-project-vulnerableapp-facade/)
* [ASVS-Graph](https://owasp.org/www-project-asvs-graph/)
* [OWASP DVSA](https://owasp.org/www-project-dvsa/)
* [OWASP Java Encoder](https://owasp.org/www-project-java-encoder/)
* [OWASP Zezengorri Code](https://owasp.org/www-project-zezengorri-code/)
* [OWASP Auth](https://owasp.org/www-project-auth/)
* [OWASP Cloud Security Mentor](https://owasp.org/www-project-cloud-security-mentor/)
* [OWASP deepviolet-tls-ssl-scanner](https://owasp.org/www-project-deepviolet-tls-ssl-scanner/)
* [OWASP Json Sanitizer](https://owasp.org/www-project-json-sanitizer/)
* [OWASP Learning Gateway](https://owasp.org/www-project-learning-gateway/)
* [OWASP little web application firewall](https://owasp.org/www-project-little-web-application-firewall/)
* [OWASP Lock It](https://owasp.org/www-project-lock-it/)
* [OWASP Off The Record 4 Java](https://owasp.org/www-project-off-the-record-4-java/)
* [OWASP Online Academy](https://owasp.org/www-project-online-academy/)
* [OWASP Security Logging](https://owasp.org/www-project-security-logging/)
* [OWASP SEDATED®](https://owasp.org/www-project-sedated/)
* [OWASP Threatspec](https://owasp.org/www-project-threatspec/)
* [OWASP Vulnerable Web Application](https://owasp.org/www-project-vulnerable-web-application/)

### Other Projects

* [OWASP Podcast](https://owasp.org/www-project-podcast/)
* [OWASP Project Spotlight Series](https://owasp.org/www-project-spotlight-series/)
* [OWASP Enterprise DevSecOps](https://owasp.org/www-project-enterprise-devsecops/)

$(function(){ $('#projects-type').click(function(){ $('#project-list-level').hide(); $('#project-list-type').show(); $('#projects-level').removeClass('active'); $('#projects-type').addClass('active'); $('#projects-level').addClass('inactive'); $('#projects-type').removeClass('inactive'); }); $('#projects-level').click(function(){ $('#project-list-type').hide(); $('#project-list-level').show(); $('#projects-type').removeClass('active'); $('#projects-level').addClass('active'); $('#projects-level').removeClass('inactive'); $('#projects-type').addClass('inactive'); }); });

***

### Flagship Projects

#### Projects that have demonstrated strategic value to OWASP and application security as a whole

***

#### Standards Projects

#### [OWASP Application Security Verification Standard](https://owasp.org/www-project-application-security-verification-standard/)

The OWASP Application Security Verification Standard (ASVS) Project is a framework of security requirements that focus on defining the security controls required when designing, developing and testing modern web applications and web services.

#### [OWASP CycloneDX](https://owasp.org/www-project-cyclonedx/)

CycloneDX is a lightweight software bill of materials (SBOM) standard designed for use in application security contexts and supply chain component analysis.

#### Tool Projects

#### [OWASP Amass](https://owasp.org/www-project-amass/)

An advanced open source tool to help information security professionals perform network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques!

#### [OWASP CSRFGuard](https://owasp.org/www-project-csrfguard/)

OWASP CSRFGuard is a library that implements a variant of the synchronizer token pattern to mitigate the risk of Cross-Site Request Forgery (CSRF) attacks.

#### [OWASP Defectdojo](https://owasp.org/www-project-defectdojo/)

The leading open source application vulnerability management tool built for DevOps and continuous security integration.

#### [OWASP Dependency-Check](https://owasp.org/www-project-dependency-check/)

Dependency-Check is a Software Composition Analysis (SCA) tool suite that identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities.

#### [OWASP Dependency-Track](https://owasp.org/www-project-dependency-track/)

Intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

#### [OWASP Juice Shop](https://owasp.org/www-project-juice-shop/)

Probably the most modern and sophisticated insecure web application for security trainings, awareness demos and CTFs. Also great voluntary guinea pig for your security tools and DevSecOps pipelines!

#### [OWASP OWTF](https://owasp.org/www-project-owtf/)

Offensive Web Testing Framework (OWTF), is an OWASP+PTES focused try to unite great tools and make pen testing more efficient, written mostly in Python.

#### [OWASP Security Knowledge Framework](https://owasp.org/www-project-security-knowledge-framework/)

The OWASP Security Knowledge Framework is an open source web application that explains secure coding principles in multiple programming languages. The goal of OWASP-SKF is to help you learn and integrate security by design in your software development and build applications that are secure by design.

#### [OWASP Security Shepherd](https://owasp.org/www-project-security-shepherd/)

OWASP Security Shepherd is a web and mobile application security training platform. Security Shepherd has been designed to foster and improve security awareness among a varied skill-set demographic. The aim of this project is to take AppSec novices or experienced engineers and sharpen their penetration testing skillset to security expert status.

#### [OWASP ZAP](https://owasp.org/www-project-zap/)

The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by a dedicated international team of volunteers. Great for pentesters, devs, QA, and CI/CD integration.

#### Documentation Projects

#### [OWASP Cheat Sheet Series](https://owasp.org/www-project-cheat-sheets/)

The OWASP Cheat Sheet Series project provides a set of concise good practice guides for application developers and defenders to follow.

#### [OWASP Mobile Security Testing Guide](https://owasp.org/www-project-mobile-security-testing-guide/)

The OWASP Mobile Security Testing Guide project consists of a series of documents that establish a security standard for mobile apps and a comprehensive testing guide that covers the processes, techniques, and tools used during a mobile app security test, as well as an exhaustive set of test cases that enables testers to deliver consistent and complete results.

#### [OWASP SAMM](https://owasp.org/www-project-samm/)

A Software Assurance Maturity Model (SAMM) that provides an effective and measurable way for all types of organizations to analyse and improve their software security posture.

#### [OWASP Top Ten](https://owasp.org/www-project-top-ten/)

The OWASP Top 10 is the reference standard for the most critical web application security risks. Adopting the OWASP Top 10 is perhaps the most effective first step towards changing your software development culture focused on producing secure code.

#### [OWASP Web Security Testing Guide](https://owasp.org/www-project-web-security-testing-guide/)

The Web Security Testing Guide (WSTG) Project produces the premier cybersecurity testing resource for web application developers and security professionals.

#### Code Projects

#### [OWASP ModSecurity Core Rule Set](https://owasp.org/www-project-modsecurity-core-rule-set/)

The OWASP ModSecurity Core Rule Set (CRS) is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls. The CRS aims to protect web applications from a wide range of attacks, including the OWASP Top Ten, with a minimum of false alerts.
