Skip to content

SecuritySilverbacks/www-project-core-business-application-security

 
 

Repository files navigation

OWASP CBAS Project Structure

<script type="text/javascript" src="https://app.diagrams.net/js/viewer-static.min.js"></script>

Introduction

As SAP systems manage the most sensitive and mission-critical data for organizations worldwide, they present an appealing target for threat actors. Traditional defenses often overlook the unique challenges in SAP landscapes, such as complex authorization models, a broad attack surface, and proprietary protocols.

The OWASP Core Business Application Security project is dedicated to provide a comprehensive approach to SAP security by focusing on critical aspects of proactive defense and resilience in SAP landscapes. This initiative brings together innovative techniques and tools to address major topics of cyersecurity such as deception, adversary simulations, detection engineering, attack surface management, security posture validation & baseline controls, and technical assessements tailored specifically for SAP environments.

Projects

Deception and Adversary Simulation

We create tools that emulate advanced threat tactics, techniques, and procedures (TTPs) in SAP systems, helping teams to stay one step ahead by visualizing attack patterns and preparing adaptive responses.

Attack Surface Management

Understanding your SAP attack surface enables you to better prioritze and apply security controls that help mature your SAP security posture. The below tools are designed to identify and provide you with possible threats and attack vectors that your SAP environment might posses.

Security Posture Validation & Baseline Controls

Validating and enforcing secure configurations and controls in SAP, we offer frameworks for continuous monitoring of system integrity against best practices.

Leaders

News and Updates Channels

Anyone interested in supporting, contributing or giving feedback join us in our discord channel.

License

Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

About

OWASP Foundation Web Respository

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • HTML 90.0%
  • Ruby 10.0%