Skip to content

OWASP

The Open Web Application Security Project: resources and guidelines for testing web application security, and the standard methodology for web app engagements.

Why It Matters

For any web application work, the OWASP Web Security Testing Guide is the reference methodology, and the Top 10 is the shared vocabulary clients already know. Framing web findings in OWASP terms makes them easy for a development team to understand and act on.

Reference

Key Resources

Resource Use
OWASP Top 10 The most critical web application risks; a shared language for findings
Web Security Testing Guide (WSTG) The step-by-step methodology for testing a web app
Cheat Sheet Series Focused guidance per topic
Juice Shop Deliberately vulnerable app for practice
ZAP OWASP's web app scanner and proxy

How I Use It

I follow the WSTG as the checklist for web app testing so coverage is consistent, and I report findings against the Top 10 categories so developers can map them to guidance they already use. Juice Shop is where I practice techniques before using them on a live target.

Resources