• Stars
    star
    271
  • Rank 151,717 (Top 3 %)
  • Language
    Python
  • Created over 6 years ago
  • Updated 2 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration

ThreatPlaybook

This is version 3 (beta)

What it was:

A (relatively) Unopinionated framework that faciliates Threat Modeling as Code married with Application Security Automation on a single Fabric

What it is now:

A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration

Black Hat Arsenal USA

Documentation

Brought to you proudly by

More Repositories

1

DVFaaS-Damn-Vulnerable-Functions-as-a-Service

Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities
Python
135
star
2

ZAP-Mini-Workshop

Interactive IPython Notebook to demonstrate OWASP ZAP's API and Scripting Functions - OWASP ZAP 2.8.0
Jupyter Notebook
40
star
3

RoboZap

HTML
32
star
4

orchestron-community

Orchestron is an Application Vulnerability Management and Correlation Tool.Orchestron helps you solve one key problem "Find and fix vulnerabilities early in the lifecycle"
Vue
31
star
5

Vulnerable-Flask-App

Intentionally Vulnerable Flask app for use in Demos
Python
28
star
6

Serverless-Workshop

Serverless Workshop
Python
16
star
7

container_training

Container Security and Serverless Training
Python
13
star
8

defcon26

DEFCON-26 Workshop Lab Exercises
HTML
12
star
9

AppSecEssentials

JavaScript
12
star
10

Gauge-OWASP-ZAP

Example of using Gauge and OWASP ZAP for test automation
Python
10
star
11

AWS-KMS-Tour

AWS KMS Tour for secrets code
Jupyter Notebook
8
star
12

Cut-The-Funds-NodeJS

2018 - Vulnerable App for Demos/Training and Workshops
JavaScript
7
star
13

Robosec

Robot Framework Security Automation Script
HTML
7
star
14

Nightwatch-ZAP

Example of OWASP ZAP Integration with NightwatchJS Test
JavaScript
7
star
15

csp-flask

Python
6
star
16

Automation_Scripts

This directory is a repository of scripts written in Python that helps you automate different aspects of security testing in a testing cycle.
Python
6
star
17

ThreatPlaybook-Example

HTML
6
star
18

RoboBurp2

Robot Framework Library for BurpSuite 2.X
Python
5
star
19

AppSecEngineerCSPIntro

Introduction to Content-Security-Policy
5
star
20

RoboMobSF

Robot Framework Library for MobSF (SAST) Tool
HTML
3
star
21

terraform-check

Repo that uses Checkov with Github Actions as an example
HCL
3
star
22

RoboArachni

Robot Framework Arachni Scanner
Python
3
star
23

OWASP-ZAP-JSON-RPC-Service

Python
2
star
24

RoboBucketeer

Robot Framework Library for Buckteer - S3 Buckets & Subdomain Enumeration
HTML
2
star
25

container_security

2
star
26

RoboPyPipeline

Robot Framework Python Pipeline example
Python
2
star
27

kubernetes-ci

Python
2
star
28

zap-workshop

Jupyter Notebook
2
star
29

djangocon-2018

DjangoCon
RobotFramework
2
star
30

gitlab-pr-scanner

SAST and SCA Scanning tool for Gitlab Merge Requests
Python
2
star
31

ThreatPlaybook-Client

Python
2
star
32

RoboBandit

Robot Framework bindings for Python's Bandit SAST tool
Python
1
star
33

we45-Public-Presentations

Presentations of the we45 Team at various events around the world
1
star
34

xml-files

HTML
1
star
35

RoboDnsRecon

Robot Framework Library for DNS Recon
Python
1
star
36

python-step-functions-example

Python
1
star
37

RoboDepCheck

Robot Framework Library for OWASP Dependency Check
Python
1
star
38

RoboSslyze

Robot Framework Library for Python's SSlyze Library
Python
1
star
39

RoboNpmAudit

Robot Framework Library for NPM Audit Source Composition Analysis
Python
1
star
40

RoboTestSSL

Robot Framework Library for TestSSL
Python
1
star
41

DevSecCon2019

JavaScript
1
star
42

vulnerable_xss

JavaScript
1
star
43

orchy-webhook_burpextender

Burp Extender for Orchestron Webhook
Python
1
star
44

ringpass

Trivially Simple Password/Secrets Manager backed by Keyrings
Go
1
star
45

jenkins-secdevops

RobotFramework
1
star
46

RoboNodeJSScan

Robot Framework Library for NodeJSScan
Python
1
star
47

serverless-training-apps

Python
1
star
48

ThreatPlaybook-ClientV3

Golang client for ThreatPlaybookV3 and above
Go
1
star
49

oss-live-code

RobotFramework
1
star
50

serverless-ci

Python
1
star