OWASP projects
Flagship standards, documentation, and training platforms that map cleanly to bug bounty methodology.
documentation
- documentation
OWASP Cheat Sheet Series
flagshipConcise best-practice guides for common AppSec topics (auth, , , etc.).
- documentation
OWASP GenAI Security Project
flagshipLLM and generative AI security guidance including Top 10 for LLMs and red teaming.
- documentation
OWASP Mobile Application Security
flagship+ — standards and testing guide for mobile app security.
- documentation
OWASP Top 10
flagshipThe definitive list of the most critical web application security risks. Baseline knowledge for every hunter.
- documentation
OWASP Web Security Testing Guide
flagshipComprehensive manual testing methodology for web applications and APIs.
- documentation
OWASP API Security Top 10
Top 10 security risks specific to APIs — , broken auth, excessive data exposure.
standard
- standard
OWASP ASVS
flagshipApplication Security Verification Standard — detailed security requirements and verification levels.
- standard
OWASP CycloneDX
flagshipFull-stack Bill of Materials (BOM) standard for software supply chain risk reduction.
- standard
OWASP SAMM
flagshipSoftware Assurance Maturity Model for measuring and improving org AppSec posture.
tool
- tool
OWASP DefectDojo
flagshipOpen-source vulnerability management and orchestration platform.
- tool
OWASP Dependency-Check
flagshipSCA tool that identifies project dependencies with known CVEs.
- tool
OWASP Dependency-Track
flagshipContinuous SBOM analysis platform for supply chain risk.
- tool
OWASP OWTF
flagshipOffensive Web Testing Framework aligning + PTES tooling automation.
- tool
OWASP Security Shepherd
flagshipWeb and mobile security training platform with progressive challenges.