Application Security focuses on identifying and mitigating vulnerabilities within web and software applications. This category includes tools, techniques, and methodologies for assessing input validation, authentication, access control, and other common security flaws across web, API, and desktop environments. Topics like OWASP Top 10, SAST/DAST tools, secure coding, and automated scanners fall under this domain.

Offline security checklist & report generator with 200+ tests across web, cloud, WiFi, firmware, and AI security domains.

SecLists is a collection of multiple types of lists used during security assessments, collected in one place for easy access.

ShipSec Studio is an open-source security workflow orchestration platform designed for building, executing, and monitoring automated security workflows at scale.

Tenable's exposure management platform helps organizations find, prioritize, and fix cyber risks across IT, cloud, OT, and identity environments.

Agentic AI-powered continuous penetration testing as a service (PTaaS) platform that combines AI scale with human supervision.

WPScan is a vulnerability database and security scanner for WordPress, helping users identify and address security risks in their WP sites.