Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
sast — Free offline SAST engine for CI/CD: AST and cross-file taint analysis, secret detection with live validation, SCA/CVE, IaC misconfiguration, and web-shell scanning with SARIF output. | Kitploit
Tools/GitHubGitHub/vulnz/sast
Defensive ToolsStatic AnalysisVulnerability ScannersStatic Code Analysis (SAST)Vulnerability AnalysisCode AnalysisMalware AnalysisCloud SecurityDevSecOpsSecret DetectionSupply Chain SecurityMisconfiguration
2103 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHubvulnz/sast

sast

Free offline SAST engine for CI/CD: AST and cross-file taint analysis, secret detection with live validation, SCA/CVE, IaC misconfiguration, and web-shell scanning with SARIF output.

View Repository
Share

Insomnia

sast — by Insomnia

Free, fast static application security testing for your terminal & CI/CD.
SAST + taint · secrets with live key validation · SCA/CVEs · IaC · CMS & web-shell/malware — one self-contained binary, the same engine in your IDE and your build.

PyPI Homebrew npm Docker image Platforms Rules Free

Get the editor plugins — same engine, same results

VS Code Marketplace   Open VSX (VSCodium / Cursor / Windsurf / Gitpod)   JetBrains Marketplace   GitHub Marketplace Action

Plugin home · CI/CD & SDLC · Direct downloads · Manifest


sast is a tiny launcher. Installing it is instant; the first time you run it, it downloads a self-contained SAST engine binary that matches your operating system, verifies its checksum, and caches it. Every run after that is native speed with no Python dependencies.

pip install sast
sast .                       # scan the current directory
sast ./src -f sarif -o out   # write a SARIF report into ./out
sast . --fail-on high        # exit non-zero on high+ findings (CI gating)
sast --help                  # full engine options

Watch the Insomnia SAST overview video
▶ Watch the overview video  ·  Read the SDLC walkthrough →

Coverage at a glance: 1,750+ FP-validated rules · native AST + cross-file taint on 16 languages (regex for 40+) · 230+ secret rule packs with live key validation · SCA across 8+ ecosystems + container/OS packages · ~24,000 CMS advisories · web-shell & malware signatures · IaC (Terraform/K8s/Docker/ CloudFormation) · SARIF / JSON / HTML.

Supports Linux, macOS and Windows (x86-64). On Apple Silicon the macOS binary runs under Rosetta.

Installing

Pick whichever fits your stack — every method lands the same engine.

MethodCommand
pip / pipx (any OS, Python 3.8+)pip install sast  ·  pipx install sast (recommended — isolated, always on PATH)
Homebrew (macOS / Linux)brew tap vulnz/sast && brew install sast
npm (global launcher)sudo npm install -g sastai
Debian / Ubuntu (signed apt repo)see below — then sudo apt-get install sast
Direct binary (Fedora / Arch / Alpine / air-gapped)curl -sSL https://insom.ai/latest/sast/linux -o /usr/local/bin/sast

Debian / Ubuntu — signed apt repo

curl -sSL https://insom.ai/apt/public-key.asc | sudo gpg --yes --dearmor \
  -o /usr/share/keyrings/insomnia-archive-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/insomnia-archive-keyring.gpg] https://insom.ai/apt stable main" \
  | sudo tee /etc/apt/sources.list.d/insomnia.list
sudo apt-get update && sudo apt-get install -y sast

Direct download from insom.ai (no package manager)

A single self-contained binary — handy for air-gapped boxes and minimal CI images:

curl -sSL https://insom.ai/latest/sast/linux  -o /usr/local/bin/sast   # Linux x86-64
# curl -sSL https://insom.ai/latest/sast/macos -o /usr/local/bin/sast   # macOS
chmod +x /usr/local/bin/sast
sast --version

Windows: download https://insom.ai/latest/sast/windows, or grab any build from the downloads page. Files + SHA-256 are listed in the manifest.

Notes on the pip install

pip install sast creates a sast command (Linux/macOS: <prefix>/bin/sast, Windows: <prefix>\Scripts\sast.exe). For the command to be found, that directory must be on your PATH. Inside a virtual environment:

python -m venv .venv
# Linux/macOS:
source .venv/bin/activate
# Windows:
.venv\Scripts\activate
pip install sast

If sast is "not recognized" / "command not found" after a pip install --user, the per-user scripts dir isn't on your PATH. Either add it, or just run it as a module — this always works regardless of PATH:

python -m sast .
  • Windows per-user scripts dir: %APPDATA%\Python\Python3XX\Scripts
  • Linux/macOS per-user scripts dir: ~/.local/bin

Run with Docker

A prebuilt, multi-arch (amd64 + arm64) image ships the engine baked in — nothing to install, ideal for CI/CD. Available on both registries:

  • Docker Hub: dominators/sast
  • GHCR: ghcr.io/vulnz/sast
docker pull dominators/sast:latest        # or: ghcr.io/vulnz/sast:latest

Scan local source code — report saved to your folder. Mount your project at /src; the reports land in ./reports on your machine (not inside the container, which --rm discards):

docker run --rm -v "$PWD:/src" dominators/sast:latest /src -f html,json,sarif -o /src/reports --fail-on high
# Windows PowerShell
docker run --rm -v "${PWD}:/src" dominators/sast:latest /src -f html,json,sarif -o /src/reports --fail-on high
Download Tool