Back to Programs

Security

OWASP Foundation

No more insecure software.

Juice ShopZAPjavajavascriptpython

Participation history

10 GSoC years

2026

26 projects

Official year page

Payload Driven Recon Scans And New Module Workflows

This project focuses on enhancing the scanning capabilities of Nettacker by introducing payload-based probing techniques for service detection. By...

Intelligent Execution Engine, Adaptive Scheduling & Advanced Tooling Integration

OWTF's current architecture has four systemic bottlenecks: workers that sit idle between single-task fetches, a FIFO scheduler with no priority or...

Optimize Nest GraphQL API and CI/CD.

The project should fix the N+1 queries problems across the project with DataLoaders. The file run-ci-cd.yaml should will be split into 5 files and...

Build a cybersecurity guardian that protects a person’s digital life in real time

This project aims to evolve the BLT-Vanish existing privacy management platform into a proactive, real-time identity defense system. While the...

OWASP Pulse & OWASP Contributor Recognition Program

This project enhances OWASP Nest by improving visibility of activity and recognition of contributors. OWASP Pulse provides a near real-time feed that...

OWASP FinBot: Guardrail & Detection Framework for Agentic AI CTF

OWASP FinBot is a security learning tool that lets people practice attacking AI agent systems in a safe environment. Right now it only teaches how to...

Add the EoP Game to the card browser

Currently, the EoP deck is not browsable or accessible through Cornucopia's API, blocking integration with OWASP Threat Dragon. This project adds a...

OWASP Community Snapshots

The current OWASP Snapshot system is passive and requires manual updates, forcing community members to constantly check the website to see what has...

OpenCRE Noise & Relevance Filtering Pipeline

This project addresses the challenge of distinguishing meaningful security knowledge from noisy or irrelevant changes in OWASP repositories....

BLT Next

BLT-Next proposal covers the full migration from Django monolith to static frontend on GitHub Pages with Cloudflare Python Workers at the edge. The...

AI Agent for Security User Story Generation from Cornucopia

Development teams using OWASP Cornucopia for threat modelling have no automated way to turn played cards into actionable Jira user stories - this...

Automating Print-Ready PDF Generation for OWASP Cornucopia using Scribus

This proposal focuses on automating the generation of print-ready PDFs for OWASP Cornucopia by replacing the current InDesign-dependent workflow with...

FinBot CTF Guardrail and Detection Framework

FinBot CTF has no defensive layer, players can exploit agentic AI vulnerabilities but can't learn to stop them. This project fixes that gap. I'll...

OWASP FinBot Guardrail Framework and Realistic Agentic Security Scenarios

This project extends OWASP FinBot by implementing a guardrail and detection framework for agent based AI systems. The system will monitor tool usage,...

OWASP OpenCRE Module A: Incremental Information Harvesting Pipeline

OpenCRE currently lacks an automated mechanism to continuously monitor upstream security knowledge sources such as OWASP repositories and detect...

Community Driven Plugin Ecosystem for OWTF

OWTF right now has a fixed set of plugins. If a security researcher wants to add a new tool or technique, there is no way to do it without touching...

OWASP Agent - Module C: The Librarian (OpenCRE)

The OWASP Agent - Module C: The Librarian (OpenCRE) project makes it possible to use continuously changing OWASP guidance inside OpenCRE, while...

BLT: NetGuardian — Zero-trust finding ingestion, CVE-aware triage, and verified events

NetGuardian is a zero-trust ingestion and triage pipeline that connects distributed security producers to BLT. A Cloudflare Python Worker sits at the...

OWASP Web Application Honeypot - Adaptive Intelligence Platform

The OWASP Web Application Honeypot is the only open community project focused on the HTTP application layer, but it currently sits as a dormant...

FinBot CTF: A Pluggable Guardrail Framework & MCP-Based Defense Scenario Pack

FinBot CTF is OWASP's premier learning environment for agentic AI security, yet it currently operates solely as an offensive arena. Practitioners can...

Nest - OWASP Board Activity and Candidate Verification Framework

This project improves transparency in OWASP Board of Directors elections by implementing a verified candidate claims system with a structured...

BLT University: Interactive Security Labs with Vulnerability Insights

BLT University is an interactive security learning platform built on top of OWASP BLT that transforms existing labs into hands-on, code-driven...

PyGoat v3 – Microservices, Labs, and Learning Paths

This proposal outlines modernization of Pygoat, focusing on scalability and a future-proof curriculum. The top priority is a complete structural and...

MiTM Proxy Upgrade for OWTF

OWTF's proxy silently drops every HTTPS transaction, blocks the entire event loop during live interception, and is written in deprecated Tornado...

Modernizing the DSOMM Application: Angular 13 to 21

DSOMM's Angular frontend currently runs on Angular 13, a version that reached end-of-life in 2023 and is eight major versions behind the latest...

Guardrail Framework and Blue Track for OWASP FinBot CTF

FinBot CTF has 16 Red track challenges where players attack a live AI agent. There is no defense side. Players can learn to exploit the agent but...

2025

12 projects

Official year page

OWASP Contribution Hub Development

The Contribution Hub will be a platform that helps newcomers find mentors for open source projects. The system will let users log in with GitHub,...

Owasp Nest API and Schema Development

The OWASP Nest API and Schema Development project aims to enhance OWASP Nest API infrastructure by migrating to Django Ninja for optimized REST API...

Improving Recon Scan and Optimising Task Handling

This project aims to improve the reconnaissance scan features of Nettacker while also addressing the issues caused by high parallelization....

Pygoat v3: Architecture and Educational Experience Redefined

PyGoat is an intentionally vulnerable Python web application designed to teach web security through hands-on practice. The project aims to modernize...

Juice Shop side-project rennovation

The Juice Shop CTF Tool, currently made with vanilla JavaScript, needs to be upgraded to TypeScript to align with the main project for easier...

AI-Driven Blockchain Rewards System and Gamification (Ordinals and Solana)

The OWASP Bug Logging Tool (BLT) is adopting a gamified, AI-powered blockchain rewards system to incentivize open-source security contributions. This...

BugSim(Bug Simulator and Learning)

BugSim (Bug Simulator and Learning) is an advanced bug simulation platform integrated into OWASP BLT. It helps security researchers, ethical hackers,...

OWTF MiTM Proxy Modernization

OWTF's built-in MiTM proxy was developed nearly a decade ago and is currently outdated, limited in functionality, and hard to maintain. This project...

Optimizing OpenCRE: AI-Driven Gap Analysis, Frontend Enhancement and Graph Debugging for scalability

This project enhances OpenCRE’s cybersecurity compliance platform by addressing scalability, usability, and transparency gaps. The resource-intensive...

Improve Kubernetes Deployment and Introduce Azure Support for OWTF

OWASP OWTF supports use of terraform to deploy OWTF on AWS and manifests for Kubernetes. To improve its capabilities, I will introduce support of...

Organization Dashboard – Enhanced Vulnerability & Bug Management

Security teams and open-source organizations often struggle with managing vulnerability reports, bug bounties, and contributor performance...

AI-Powered Code Review & Smart Prioritization System for Maintainers

This project aims to build an AI-powered GitHub assistant that helps open-source maintainers review code, detect security issues, and prioritize...

2024

10 projects

Official year page

Blockchain Crypto Development and Wielding the Power of AI

"Blockchain Crypto Development and Wielding the Power of AI" is a Google Summer of Code 2024 project with OWASP-Foundations that aims to integrate...

Add a secureCodeBox CLI (scbctl)

The SecureCodeBox (SCB) project provides a powerful framework for automated security testing. Users currently face challenges in quickly initiating...

add threats by element for STRIDE/LINDDUN/PLOT4ai/CIA/DIE

Reinstating automated threat suggestion per element was a feature in the threat dragon threat model designing system. Hence, upon migration to Vue.JS...

OWASP OWTF - Comprehensive Upgrade For Modern Web Penetration Testing

The Offensive Web Testing Framework (OWTF) is a tool that allows penetration testers to quickly automate security tests that follows standards like...

Implementing new Features to Bug Logging Tool (BLT)

The goals of the Flutter implementation of BLT (Bug Logging Tool) are to enhance the user interface, provide visual representations and implement...

Adding important functionality to Nettacker

The proposal aims to add two new functionalities to the project Nettacker to increment the effectiveness of the tool and also enhance the user’s...

Enhancing OWASP's BLT with AI Capabilities

In an era where cybersecurity threats evolve rapidly, the Open Web Application Security Project (OWASP) Bug Logging Tool (BLT) serves as a crucial...

Design & implement deployment architecture for OWTF

The proposal's objective is to design and implement a deployment architecture for OWTF, with a particular focus on converting the monolithic...

Design & implement deployment architecture

In the rapidly evolving world of software development, efficient and reliable deployment architecture is crucial. The goal of this project is to...

BLT Website Design Enhancement

BLT website lags behind in modern design as compared to other websites. This proposal aims to enhance the current design of BLT website by completely...

2023

11 projects

Official year page

ZAP: Browser Recorder

This project aims to address the inconvenience users face when testing websites that require pre-task activities, such as logging in. The proposed...

CRS #3: WAF Performance Testing Framework

Performance evaluation is one of the concerns about using ModSecurity and Core Rule Sets. More specifically, people take different approaches to...

OWTF Typescript Migration and Web Interface Enhancement.

The proposal's objective is to complete the typescript migration of the OWTF, add new components to the front-end, fix errors in the authentication...

Improving OWASP wrongsecrets infrastructure

The wrongsecrets project is structured in two modes the standalone app and the CTF mode. Here we will focus on OWASP/wrongsecrets-ctf-party and how...

Companion Guide Tech Stack

The problem here is to migrate from gitbook to some other tool which provides us with the feature of generating website from some easy to use markup...

Deployment Of OWTF

I aim to deploy OWTF on AWS for easier use by users and to ease its development for developers. Also, I will improve its Docker installation, which I...

DSOMM

1. Adding Filters in the Matrix View: Updating the YAML file, and adding the tags title in task-description. After this, adding chip style filter...

Hacking the Blockchain: Building Web3 Challenges for OWASP Juice Shop

Juice Shop is an intentionally vulnerable web application designed for practicing security testing and improving security skills. Blockchain...

Implementing RateLimit Plugin for Coraza WAF

Rate limiting is a technique used by computer systems to control the rate of traffic sent or received by a particular entity (such as an application...

Bug Logging Tool

The primary objective of this proposal is to: 1. Enhance the user interface for new designs in Tailwind, thereby optimizing the user experience. In...

Postman Add-on for ZAP

The aim of this project is to develop an add-on for the OWASP ZAP that enables the import of Postman collections into ZAP. Currently, ZAP supports...

2022

15 projects

Official year page

OWTF Web Interface Enhancement

Create new user interface for the web application of OWASP OWTF, use SASS instead of CSS, remove the additional dependencies to make code more...

Bug Logging Tool (BLT)

This project aims to extend the existing BLT flutter app to be fully fledged to provide a seamless experience along with rewards to the users while...

Deep Learning for OWASP Maryam's NLP operations

Implementing deep neural networks for Natural Language Processing (NLP) operations (clustering, topic extraction, and relevant search) on OWASP...

ZAP add-on: Param Digger

The Param Digger add-on is a parameter discovery tool that can be used to find hidden or unlinked parameters which can be potentially used for...

update && upgrade OWASP PyGoat

PyGoat is a platform for developers and testers to learn how to test applications and code securely. PyGoat is written in python and Django web...

Python Honeypot Improvements

Remove circular imports, integrate sentry into the project, integrate Prometheus in API's to view metrics in grafana, add a new panel in the UI to...

Juice Shop: Replacement for Protractor end-to-end & Frisby API test suite to Cypress

Migration of the entire E2E test suite from the deprecated Protractor framework and the Frisby API test suite to the most widely used and community...

Improving SecureTea firewall, IDS, adding a persistent AntiVirus, remote monitoring and better GUI.

OWSAP SecureTea requires a few updates to its features. These are - 1. Improvements in IDS and FireWall 2. Complete Web GUI and Remote Monitoring 3....

Migration to Modern React with TypeScript & React Hooks

The OWTF web application has not been updated in a while and is missing some of the modern React advancements. Through this project, I want to work...

Reconstruction of DSOMM dashboard from scratch using Angular

The OWASP DevSecOps Maturity Model is used to assess and present the devsecops maturity of an organization. It consists of an application and...

SKF

The idea is to create a Video Editor, a web-based application that takes markdown files, PDFs or any asset file as an input and separates those...

Nettacker

Looking forward to add new modules and improvise the module structure, redesign reports which having different format support, moving Sqlalchemy to...

Maryam: Deep Neural Networks for Clustering, Topic Modeling and Similar Document retrieval [Iris]

To start with OWASP Maryam, it is a modular open-source framework based on OSINT (Open-source intelligence) designed specifically for robust data...

Machine Learning Plugin Integration

With the increase in use of technology and the internet, the risks associated with the internet are also increasing at a very high rate. Hence, it is...

Project Seaweed (CVE’d)

Whenever a new CVE is released, security solutions such as firewalls need to test if their product is able to detect the attack or lets it pass...

2021

14 projects

Official year page

Bug Logging Tool

Bugs or Issues are the vulnerabilities that you find on Websites or Applications when you expect some functionalities to occur but something else...

Improvements In WebUI for Nettacker

The current version of OWASP Nettacker needs some improvement in WebUI. I will make some changes to each page of the WebUI/API to make it look...

Improvise Python Honeypot

Migrate database from mongodb to ElasticSearch to use grafana dashboard along with the python honeypot web interface. Make REST API's compatible with...

Adding Out-of-band Application Testing (OAST) Support to ZAP

OAST stands for Out-of-band Application Security Testing and is used to detect Out-Of-Band (OOB) vulnerabilities, which is not possible to do with a...

Dark Web Exploration (for Cyber Threat Analysis) And Expansion of Data Sources

Primary objective is to design a smart dark web crawler, capable of mapping the darkest crevices of the dark web. Secondary objectives are to expand...

GSOC proposal for Nettacker

Nettacker is tool which can scan and find vulnerability from the target. This have numerous modules, like recent Microsoft Exchange vulnerability...

Extending the features of the vulnerable code snippets

In this project two new types of coding challenges for the vulnerable code snippets will be added, one for identifying the vulnerable lines in the...

Building a Web Application Firewall that uses Machine Learning .

The primary goal of my idea is to implement a WAF which uses Machine Learning to detect anomalies in web traffic. The proposed idea Since the...

SecureTea - Improvement in Features

SecureTea Project provides a one-stop security solution for various devices, I would like to contribute the following features to the Project to make...

Implement Retest Functionality

ZAP is a great tool to detect vulnerabilities of different kinds in web applications and generate alerts accordingly. However, it currently lacks a...

General Improvements

My project mainly deals with all the small but essential enhancements which are stated in the GitHub issues section. These are what I have...

SKF support for interactive vulnerability fixing.

To expand SFK labs impact I propose, inspired by the project authors, the addition of a component that allows the user to visualize the source code...

Login/Signup Implementation

The current web application of OWTF has no login/signup implementation. Through this project, I want to work on developing the login and signup...

DefectDojo Modern UI

Modern User Experience For OWASP DefectDojo With this proposal, I intend to shed light on the various areas which can be improved to better the user...

2020

12 projects

Official year page

Adding new vulnerability modules

This project I will work on during the GSOC consists on building many new vulnerability modules for web application pen-testing along with performing...

New Graphical User Interface

A new graphical user interface for the Security Knowledge Framework web application with Angular 8 and Bootstrap.

Juice-Shop ChatBot and general fixes

Making an NLP based responsive and challenge ready ChatBot for OWASP Juice-Shop, along with two unique challenges. Also do a thorough sweep of the...

Intelligent Intrusion Detection System

Developing an Intelligent Intrusion Detection System using AI technologies for detection. It will be be a complete Python based application which...

OWASP Python Honeypot

Adding the following features to the OWASP Python Honeypot project: add log explorer WebUI for a tabular view of the data stored in the database....

The Honeypot Project

This project focuses on the honeypot project by the OWASP foundation. The goal of the Project is to identify emerging attacks against web...

Bugheist

Bugheist

Building A Standalone Scanner to enhance Risk Assessment Framework

Building a Standalone Scanner for RAF to detect OWASP TOP 10 Vulnerabilities and building a plugin for IDE’s

Enhancements in OWASP PYTHON Honeypot

The idea is to Add a new Database honeypot module - as for now there are modules like ssh,ftp,https and ICS but no module for catching database...

OWASP OWTF - General Improvements

The current version of the OWTF framework in spite of having all the features and functionalities to make it the tool of choice for Pentesters and...

Add Support for GraphQL Security Testing in ZAP

GraphQL Schemas can be very large and testing them can be a very time-consuming, manual process. Currently, there is a lack of tools that allow...

SecureTea

One of my primary goals is to make securetea an industrially usable product. The major topics I am targeting are: Updating GUI Improving IDS Login...

2019

12 projects

Official year page

Improving and building Lab challenges and write-ups:

This project I will work on during the GSOC consists on building many new Lab challenges for web app pentesting and clear and easy-to-follow...

OWASP Risk Assessment Framework

Building an API to stage the results of Static Application Security Testing (SAST) tools.

OWASP OWTF-Web Interface Enhancements

The current web interface of OWTF is non-functional and some of its pages are not yet implemented. This project is about implementing a full...

Building a Web-based Honeypot & Reporting Threat Intelligence

The objective is to build a web-based Honeypot project by identifying the emerging attacks against web applications and report them to the community,...

OWASP Seraphimdroid

OWASP Seraphimdroid has previously applied a system, based on permissions, which is able to distinguish malicious apps from non-malicious. But it...

OWASP Juice Shop: Feature Pack 2019

This project aims at enhancing the Juice Shop application by drawing inspiration from modern e-commerce companies and incorporating sublime features...

Writing Functional and Unit Tests For Defect-Dojo Tools and Modules

OWASP DefectDojo is an open source vulnerability management tool and it's used as the backbone for security programs. It helps you keep proper record...

WebSocket Scanning

ZAP has good support for websockets, and allows them to be intercepted, changed and fuzzed. However, it doesn't currently support scanning, either...

OWASP SKF – Enhancing user experience on chatbots

Security Knowledge Framework (SKF) is intended to be a tool that is used as a guide for building and verifying secure software. It can also be used...

Scan2.0 and Writing Unittests for OWASP-Defectdojo

DefectDojo is a security tool that automates application security vulnerability management. DefectDojo streamlines the application security testing...

OWASP Honeypot GSOC 2019

OWASP Honeypot : The idea is to: -Test all the modules in the code (currently 4)and if there are bugs found to fix them. -After testing the...

Laying down base architecture

Laying down a strong foundation & base architecture for Intrusion detection & prevention system (IDS/IPS), intelligent log monitoring, antivirus that...

2018

8 projects

Official year page

OWASP Juice Shop : Frontend Technology Update

Juice shop uses AngularJS for it's frontend along with Bootstrap. Keeping the application up to date with the latest technologies is important to...

General Improvements and Bug Fixes for OWASP-Nettacker

OWASP Nettacker is a project that automatically gathers information, scans network for vulnerabilities and eventually generates a report for...

WebSockets Active Scanning

For my contribution to the ZAP I am going to implement an active web socket scan. Specifically, I will develop an extension for WebSocket add-on by...

OWASP SKF - New user experience based on chat bots

Security Knowledge Framework (SKF) is a tool that is used as a guide for building and verifying secure software.It can also be used to train...

Owasp-Nettacker Enhancements

OWASP-Nettacker currently is a project with less functionality compared to other network penetration testing tools like Nmap, Nessus. In this...

Authentication helper add-on for ZAP

ZAP allows the penetration tester to set up authentication for the web application being tested. This allows ZAP to run tests from the point of an...

Bug Logging Tool

BLT lets anyone report issues they find on the internet. It gives points to users for reporting bugs .But it lacks mobile portability that is the app...

OWASP Juice Shop : Challenge Pack 2018

This project will involve designing and implementing new vulnerable features and challenges around them which will successfully show how...

2016

5 projects

Official year page

Extending language support and adding OWASP Top 10 challenges to Container Engine

The project will implement the following features: Extended language support for container Engine: The current version of container engine can handle...

Educational Plugin for Seraphimdroid

Educating an amateur or an avid Android user with the threats they can face on their Droid and protecting it by building a Knowledge Base for...

OWASP OWTF - Health Monitor

OWASP OWTF is a great tool which automates the manual and non-creative work of penetration testing. It combines all required tools and features but...

OWASP ZSC - Shellcode for Windows and Code Obfuscation Modules

OWASP ZSC tool currently does not support generation of Shellcodes for Windows and it also has only few obfuscation modules. The two primary goals of...

Machine Learning Trend Monitoring Analysis Engine for AppSensor

Over the recent years, machine learning algorithms have been playing an important role in searching for patterns in data and developing innovative...