awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

6 repositorios

Awesome GitHub RepositoriesWeb Application Security Testing Guides

Comprehensive procedural frameworks and best practice guides for identifying vulnerabilities in web applications.

Distinct from Web Application Penetration Testing: Focuses on the comprehensive guide/standard itself rather than the active process of penetration testing

Explore 6 awesome GitHub repositories matching security & cryptography · Web Application Security Testing Guides. Refine with filters or upvote what's useful.

Awesome Web Application Security Testing Guides GitHub Repositories

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • owasp/wstgAvatar de OWASP

    OWASP/wstg

    9,473Ver en GitHub↗

    The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software. The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerab

    Provides a comprehensive framework of procedures and best practices for identifying vulnerabilities in web applications and services.

    application-securityappsecbest-practices
    Ver en GitHub↗9,473
  • kathanp19/howtohuntAvatar de KathanP19

    KathanP19/HowToHunt

    7,146Ver en GitHub↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    Provides a structured collection of procedural frameworks and test cases for web application penetration testing.

    bugbountybugbountytipsbughunting-methodology
    Ver en GitHub↗7,146
  • daffainfo/allaboutbugbountyAvatar de daffainfo

    daffainfo/AllAboutBugBounty

    6,644Ver en GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    Serves as a comprehensive guide for web application security testing with curated payloads.

    bugbugbountybugbountytips
    Ver en GitHub↗6,644
  • lylemi/learn-web-hackingAvatar de LyleMi

    LyleMi/Learn-Web-Hacking

    5,414Ver en GitHub↗

    Learn-Web-Hacking es una guía de estudio estructurada sobre seguridad web y una base de conocimientos de pruebas de penetración. Proporciona una colección de notas de investigación centradas en identificar y explotar vulnerabilidades en aplicaciones web y protocolos de red. El proyecto incluye frameworks especializados para evaluar riesgos de seguridad en modelos de lenguaje extensos (LLM) para prevenir la inyección de prompts, así como guías para el endurecimiento (hardening) de infraestructura cloud-native, incluyendo estándares de contenedores y herramientas de orquestación. También cubre el análisis de estándares de identidad y protocolos de autenticación. El material abarca una amplia gama de capacidades de seguridad, incluyendo análisis de protocolos de red, recopilación de información para el mapeo de superficies de ataque y pruebas de penetración en redes internas que involucran movimiento lateral y persistencia. Además, detalla estrategias defensivas como arquitecturas de confianza cero (zero-trust) y detección de intrusiones.

    Provides a comprehensive study guide and research notes for identifying vulnerabilities in web applications and protocols.

    Pythonhackingpenetration-testingpentesting
    Ver en GitHub↗5,414
  • owasp/go-scpO

    OWASP/Go-SCP

    5,285Ver en GitHub↗

    Go-SCP es una guía de codificación segura y framework de prevención de vulnerabilidades para el lenguaje de programación Go. Sirve como un manual técnico para implementar patrones de programación defensiva y benchmarks de seguridad para prevenir vulnerabilidades de software comunes. El proyecto funciona como una referencia de seguridad estática, mapeando debilidades de software conocidas a patrones de remediación específicos de Go. Proporciona un repositorio curado de estándares de codificación segura y prácticas de implementación validadas centradas específicamente en la seguridad de aplicaciones web. El framework cubre la auditoría de seguridad comparando el código fuente con benchmarks establecidos y utiliza el mapeo de vulnerabilidades basado en patrones para identificar fallos de programación. La guía se distribuye a través de una arquitectura de referencia estructurada y está disponible en formatos portátiles como PDF y ePub para referencia offline.

    Provides a comprehensive technical manual and procedural framework for identifying and preventing vulnerabilities in web applications using Go.

    Go
    Ver en GitHub↗5,285
  • voorivex/pentest-guideAvatar de Voorivex

    Voorivex/pentest-guide

    2,761Ver en GitHub↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    Offers a comprehensive procedural framework and structured methodology for identifying web application vulnerabilities.

    bugbountybypassowasp-tests
    Ver en GitHub↗2,761
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Security Testing and Auditing
  5. Security Testing
  6. Web Application Security Testing Guides