#1Static and dynamic code analysis, SAST, DAST, and code review tools.
Kitploit recommended

Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Ghidra is a software reverse engineering (SRE) framework

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

UNIX-like reverse engineering framework and command-line toolset

Find, verify, and analyze leaked credentials

.NET Decompiler with support for PDB generation, ReadyToRun, Metadata (&more) - cross-platform!

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Main repo for hosting release binaries

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Source-level debugger for Go with CLI, API, and headless modes; supports breakpoints, variable inspection, and execution tracing for efficient…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

A static analyzer for Java, C, C++, and Objective-C

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security