

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…

Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.

Python Command-Line Ghidra MCP

Use IDA PRO HexRays decompiler with OpenAI(ChatGPT) to find possible vulnerabilities in binaries

LLVM based static binary analysis framework

A tool that automatically creates fuzzing harnesses based on a library

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

An x86-64 code virtualizer for VM based obfuscation

Coverage-based fuzzer for python applications