awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

6 مستودعات

Awesome GitHub RepositoriesWeb Application Security Testing Guides

Comprehensive procedural frameworks and best practice guides for identifying vulnerabilities in web applications.

Distinct from Web Application Penetration Testing: Focuses on the comprehensive guide/standard itself rather than the active process of penetration testing

Explore 6 awesome GitHub repositories matching security & cryptography · Web Application Security Testing Guides. Refine with filters or upvote what's useful.

Awesome Web Application Security Testing Guides GitHub Repositories

اعثر على أفضل المستودعات باستخدام الذكاء الاصطناعي.سنبحث عن أفضل المستودعات المطابقة باستخدام الذكاء الاصطناعي.
  • owasp/wstgالصورة الرمزية لـ OWASP

    OWASP/wstg

    9,473عرض على GitHub↗

    The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software. The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerab

    Provides a comprehensive framework of procedures and best practices for identifying vulnerabilities in web applications and services.

    application-securityappsecbest-practices
    عرض على GitHub↗9,473
  • kathanp19/howtohuntالصورة الرمزية لـ KathanP19

    KathanP19/HowToHunt

    7,146عرض على GitHub↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    Provides a structured collection of procedural frameworks and test cases for web application penetration testing.

    bugbountybugbountytipsbughunting-methodology
    عرض على GitHub↗7,146
  • daffainfo/allaboutbugbountyالصورة الرمزية لـ daffainfo

    daffainfo/AllAboutBugBounty

    6,644عرض على GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    Serves as a comprehensive guide for web application security testing with curated payloads.

    bugbugbountybugbountytips
    عرض على GitHub↗6,644
  • lylemi/learn-web-hackingالصورة الرمزية لـ LyleMi

    LyleMi/Learn-Web-Hacking

    5,414عرض على GitHub↗

    Learn-Web-Hacking هو دليل دراسي منظم لأمن الويب وقاعدة معرفية لاختبار الاختراق. يوفر مجموعة من ملاحظات البحث التي تركز على تحديد واستغلال الثغرات في تطبيقات الويب وبروتوكولات الشبكة. يتضمن المشروع أطر عمل متخصصة لتقييم المخاطر الأمنية في النماذج اللغوية الكبيرة لمنع حقن الأوامر (prompt injection)، بالإضافة إلى أدلة لتعزيز البنية التحتية السحابية، بما في ذلك معايير الحاويات وأدوات التنسيق. كما يغطي تحليل معايير الهوية وبروتوكولات المصادقة. تغطي المواد نطاقاً واسعاً من القدرات الأمنية، بما في ذلك تحليل بروتوكولات الشبكة، وجمع المعلومات لرسم خرائط سطح الهجوم، واختراق الشبكات الداخلية بما في ذلك الحركة الجانبية والاستمرارية. كما يفصل الاستراتيجيات الدفاعية مثل معمارية الثقة الصفرية (zero-trust) وكشف التسلل.

    Provides a comprehensive study guide and research notes for identifying vulnerabilities in web applications and protocols.

    Pythonhackingpenetration-testingpentesting
    عرض على GitHub↗5,414
  • owasp/go-scpO

    OWASP/Go-SCP

    5,285عرض على GitHub↗

    Go-SCP هو دليل ترميز آمن وإطار عمل لمنع الثغرات للغة البرمجة Go. يعمل كدليل تقني لتنفيذ أنماط البرمجة الدفاعية ومعايير الأمان لمنع ثغرات البرمجيات الشائعة. يعمل المشروع كمرجع أمان ثابت، حيث يربط نقاط ضعف البرمجيات المعروفة بأنماط معالجة محددة في Go. ويوفر مستودعًا منسقًا لمعايير الترميز الآمن وممارسات التنفيذ المعتمدة التي تركز بشكل خاص على أمان تطبيقات الويب. يغطي إطار العمل تدقيق الأمان من خلال مقارنة الكود المصدري مقابل المعايير المحددة ويستخدم تعيين الثغرات القائم على الأنماط لتحديد عيوب البرمجة. يتم توزيع التوجيهات من خلال بنية مرجعية مهيكلة ومتاحة بتنسيقات محمولة مثل PDF وePub للرجوع إليها دون اتصال بالإنترنت.

    Provides a comprehensive technical manual and procedural framework for identifying and preventing vulnerabilities in web applications using Go.

    Go
    عرض على GitHub↗5,285
  • voorivex/pentest-guideالصورة الرمزية لـ Voorivex

    Voorivex/pentest-guide

    2,761عرض على GitHub↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    Offers a comprehensive procedural framework and structured methodology for identifying web application vulnerabilities.

    bugbountybypassowasp-tests
    عرض على GitHub↗2,761
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Security Testing and Auditing
  5. Security Testing
  6. Web Application Security Testing Guides