[!WARNING] Make sure you have the appropriate permissions to actively scan and test applications. Without doing so, you might face legal implications
The project aims to help organizations and security professionals to identify and discover open SAP services through the use of different network scanning techniques. This allows individuals to further test these services for any potential threat that might affect SAP applications in their organizations.
Three areas within the NO MONKEY Security Matrix can benefit from the project:
When applied to a single organization, the results from the project can aid organizations to further concentrate their efforts in the IDENTIFY and INTEGRATION quadrant of the NO MONKEY Security Matrix.
Another potential area of benefit will be under the DETECT and INTEGRATION quadrant, this will allow organizations to automate their monitoring capabilities when it comes to publishing SAP application to the internet. If publishing these applications is not a requirement and have been done due to misconfiguration then the organization would be able to properly detect it.
More information can be found on the OWASP CBAS project Page
More information, benefits and details to each service can be found in the Wiki
Anyone interested in supporting, contributing or giving feedback join us in our discord channel
We have also included a section about contribution in out Wiki, which can be found here