OWASP Flagship Projects

Eleven of OWASP's flagship projects — the standards, guides and tools that define modern application security. Search or filter by category, then open any card for a detailed bilingual breakdown.

11Flagship projects
4Categories
25Years of OWASP

11 project(s)

Guides & Standards

OWASP Top 10

The data-driven awareness list of the ten most critical web application security risks.

webappsecawarenessrisks
Guides & Standards

OWASP Application Security Verification Standard (ASVS)

A community-driven catalog of testable security requirements for designing, building, and verifying web apps.

verificationstandardrequirementsappsec
Guides & Standards

OWASP Web Security Testing Guide (WSTG)

The premier methodology and checklist for testing the security of web applications and web services.

pentestmethodologychecklistweb-appsec
Guides & Standards

OWASP Mobile Application Security (MAS)

The industry standard for mobile app security: MASVS standard, MASTG testing guide, and MAS Checklist for iOS & Android.

mobileiosandroidmasvs
Guides & Standards

OWASP SAMM

An open, measurable framework to assess and improve an organization's secure software development lifecycle.

maturity-modelsdlcappsecgovernance
AI Security

OWASP GenAI Security Project

Community guidance for securing LLM & generative AI apps, home of the Top 10 for LLM Applications.

llmgenaiai-securitytop-10
AI Security

OWASP AI Exchange

The world's open-source AI security & privacy guide and connective tissue to global AI standards.

ai-securityai-privacythreat-modelstandards
Supply Chain / SBOM

OWASP CycloneDX

Full-stack Bill of Materials standard for software supply chain security and risk reduction.

sbomsupply-chainvexecma-424
Tools

OWASP Dependency-Track

Continuous SCA platform that consumes CycloneDX SBOMs to cut software supply chain risk across a portfolio.

scasbomcyclonedxsupply-chain
Tools

OWASP Juice Shop

Probably the most modern and sophisticated insecure web app for security training and CTFs.

web-securitytrainingctfowasp-top-10
Tools

OWASP CRS (Core Rule Set)

Generic, engine-agnostic attack-detection rules that give web app firewalls a first line of defense.

wafrulesmodsecuritycoraza