Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
semgrep-rules — A collection of my Semgrep rules to facilitate vulnerability research. | Kitploit
Tools/GitHubGitHub/0xdea/semgrep-rules
Static Code Analysis (SAST)Vulnerability AnalysisCode AnalysisBinary AnalysisLearning & EducationCurated Resources
GitHub0xdea/semgrep-rules

semgrep-rules

A collection of my Semgrep rules to facilitate vulnerability research.

View Repository
86689244 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

semgrep-rules

validate

"The attack surface is the vulnerability. Finding a bug there is just a detail."

-- Mark Dowd

"Some details are more important than others."

-- Fedor G. Pikus

A collection of my Semgrep rules to facilitate vulnerability research.

Program in C

Blog posts

  • https://hnsecurity.it/blog/semgrep-ruleset-for-c-c-vulnerability-research
  • https://hnsecurity.it/blog/automating-binary-vulnerability-discovery-with-ghidra-and-semgrep
  • https://hnsecurity.it/blog/big-update-to-my-semgrep-c-cpp-ruleset
  • https://hnsecurity.it/blog/streamlining-vulnerability-research-with-the-idalib-rust-bindings-for-ida-9-2/
  • https://hnsecurity.it/blog/my-semgrep-c-cpp-ruleset-is-ready-for-prime-time-again/

See also

  • https://appsec.guide/docs/static-analysis/semgrep/
  • https://semgrep.dev/docs/writing-rules/overview
  • https://semgrep.dev/r

Setup and usage instructions

  1. Install Semgrep.
  2. To use these rules via the Semgrep registry, run the following from the root folder of your target source code repository:
# high priority scan (quick wins)
semgrep --severity ERROR --config "p/0xdea"

# high and medium priority scan (recommended)
semgrep --severity ERROR --severity WARNING --config "p/0xdea"

# full scan (might include marginal findings and more false positives)
semgrep --config "p/0xdea"

Alternatively, you can clone this GitHub repository locally and run:

# full scan
semgrep --config semgrep-rules/rules /path/to/source

# specific rule scan
semgrep --config semgrep-rules/rules/c/command-injection.yaml /path/to/source

[!TIP] Specify the --no-git-ignore switch to scan files regardless of git tracking status or .gitignore rules.

For a better streamlined experience, I recommend saving the Semgrep scan output in SARIF format and using SARIF Explorer in VS code:

semgrep --sarif --sarif-output=/path/to/source/SEMGREP.sarif --config semgrep-rules/rules /path/to/source
code /path/to/source # then open the SEMGREP.sarif file in VS code with SARIF Explorer 

See also the included SARIF output example.

Compatibility

Tested with Semgrep CLI 1.169.0.

Rules

C/C++

Battle-tested C (and sometimes C++) ruleset.

buffer overflows

  • insecure-api-gets. Use of the insecure API function gets.
  • insecure-api-strcpy-strcat. Use of potentially insecure API functions strcpy, stpcpy, strcat.
  • insecure-api-sprintf-vsprintf. Use of potentially insecure API functions sprintf and vsprintf.
  • insecure-api-scanf. Use of potentially insecure API functions in the scanf family.
  • incorrect-use-of-strncat. Wrong size argument passed to strncat.
  • use-of-source-size-in-copy. Wrong size argument passed to strncpy, memcpy, snprintf, and variants.
  • incorrect-use-of-sizeof. Accidental use of the sizeof operator on a pointer instead of its target.
  • unterminated-string-strncpy. Lack of explicit NUL-termination after strncpy and stpncpy.
  • off-by-one. Potential off-by-one error.
  • unsafe-ret-snprintf-vsnprintf. Potentially unsafe use of the return value of snprintf and vsnprintf.
  • unsafe-ret-strlcpy-strlcat. Potentially unsafe use of the return value of strlcpy and strlcat.
  • pointer-subtraction. Potential use of pointer subtraction to determine size.
  • write-into-stack-buffer. Direct write into buffer allocated on the stack.

integer overflows

  • integer-wraparound. Potential integer wraparound errors.
  • unsafe-strlen. Casting the return value of strlen to short might be dangerous.
  • integer-truncation. Potential integer truncation errors.
  • signed-unsigned-conversion. Potential signed/unsigned conversion errors.
  • incorrect-unsigned-comparison. Checking if an unsigned variable is negative.

format strings

  • format-string-bugs. Potential format string bugs.

memory management

Download Tool