awesome-repositories.com
Blog
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektÜber unsRanking-MethodikPresseMCP-Server
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
OWASP avatar

OWASP/wstg

0
View on GitHub↗
9,473 Stars·1,627 Forks·CC-BY-SA-4.0·3 Aufrufeowasp.org/www-project-web-security-testing-guide↗

Wstg

The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software.

The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerability classification and modular domain decomposition, splitting the testing process into distinct focus areas such as authentication and input validation.

The framework covers broad capability areas including web application security testing, web service security auditing, and API security testing. It integrates scenario-based security testing and guideline-based remediation mapping to connect identified vulnerabilities to specific mitigation strategies.

Features

  • Web Security Auditing - Provides a comprehensive set of procedures and frameworks for systematically auditing the security of web applications.
  • Security Audit Workflows - Provides structured sequences of verification steps for conducting systematic security audits of web applications.
  • Web Security Audit - Implements a repeatable sequence of discovery and exploitation steps to identify weaknesses in web services.
  • Vulnerability Assessment and Testing - Provides a structured methodology for identifying security gaps through repeatable scenarios and verification steps.
  • API Security Checklists - Provides detailed checklists and methodologies specifically for evaluating the security posture of APIs.
  • Security Testing - Defines specific attack patterns and expected outcomes to verify the security posture of web applications.
  • Vulnerability Assessment Frameworks - Provides a systematic framework to discover and document security risks in web applications.
  • Web Application Penetration Testing - Offers a standardized approach for identifying and validating security flaws in web services.
  • Web Application Security Testing Guides - Provides a comprehensive framework of procedures and best practices for identifying vulnerabilities in web applications and services.
  • API Security Audit Frameworks - Provides a dedicated framework of methodologies and checklists for evaluating API security postures.
  • Remediation Guides - Provides actionable documentation and guidance for resolving identified security vulnerabilities using industry best practices.
  • Software Security Standards - Serves as a community-driven standard for conducting consistent and thorough audits of web-based software.
  • Classification Taxonomies - Uses a hierarchical classification system to organize security tests for systematic auditing.
  • Application Security - Comprehensive guide for testing web application security.
  • Security Testing - Comprehensive guide for web application security testing.

Star-Verlauf

Star-Verlauf für owasp/wstgStar-Verlauf für owasp/wstg

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Start searching with AI

Open-Source-Alternativen zu Wstg

Ähnliche Open-Source-Projekte, sortiert nach der Anzahl der gemeinsamen Funktionen mit Wstg.
  • voorivex/pentest-guideAvatar von Voorivex

    Voorivex/pentest-guide

    2,761Auf GitHub ansehen↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    bugbountybypassowasp-tests
    Auf GitHub ansehen↗2,761
  • fallibleinc/security-guide-for-developersAvatar von FallibleInc

    FallibleInc/security-guide-for-developers

    21,090Auf GitHub ansehen↗

    This project is a web application security guide and developer training resource. It serves as a secure coding framework and vulnerability remediation manual, providing software engineers with the tools to identify, prioritize, and fix common security holes across different application layers. The resource utilizes a structured verification framework and security audit checklists to systematically find vulnerabilities. It features a technical reference that maps specific security flaws to step-by-step instructions for remediation, supported by vulnerability statistics to help determine which

    Auf GitHub ansehen↗21,090
  • shieldfy/api-security-checklistAvatar von shieldfy

    shieldfy/API-Security-Checklist

    23,258Auf GitHub ansehen↗

    This project is a comprehensive API security audit checklist and vulnerability audit framework. It provides a structured guide of security countermeasures for designing, testing, and deploying secure APIs across various protocols. The framework includes specialized guides for securing OAuth 2.0 authorization flows, implementing zero trust networking for service-to-service communication, and protecting GraphQL endpoints from resource exhaustion and information leakage. It also provides standards for integrating static analysis, dynamic scanning, and secret detection into CI/CD delivery pipelin

    apijwtoauth2
    Auf GitHub ansehen↗23,258
  • daffainfo/allaboutbugbountyAvatar von daffainfo

    daffainfo/AllAboutBugBounty

    6,644Auf GitHub ansehen↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    bugbugbountybugbountytips
    Auf GitHub ansehen↗6,644
Alle 30 Alternativen zu Wstg anzeigen→

Häufig gestellte Fragen

Was macht owasp/wstg?

The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software.

Was sind die Hauptfunktionen von owasp/wstg?

Die Hauptfunktionen von owasp/wstg sind: Web Security Auditing, Security Audit Workflows, Web Security Audit, Vulnerability Assessment and Testing, API Security Checklists, Security Testing, Vulnerability Assessment Frameworks, Web Application Penetration Testing.

Welche Open-Source-Alternativen gibt es zu owasp/wstg?

Open-Source-Alternativen zu owasp/wstg sind unter anderem: voorivex/pentest-guide — This project is a comprehensive web application penetration testing guide and vulnerability research framework. It… fallibleinc/security-guide-for-developers — This project is a web application security guide and developer training resource. It serves as a secure coding… shieldfy/api-security-checklist — This project is a comprehensive API security audit checklist and vulnerability audit framework. It provides a… daffainfo/allaboutbugbounty — AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing.… kathanp19/howtohunt — HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It… samsar4/ethical-hacking-labs — Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning…