
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…


Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's net/http package. Demonstrates exploitation of improper…

World's first hazard checker for NVIDIA Blackwell (sm_120), with an assembler and scheduler matched against their own compiler byte for byte. The…

Obfuscates AutoIt scripts to protect source code from analysis, reverse engineering, and decompilation using advanced obfuscation and polymorphic…


A minimal, secure Python interpreter written in Rust for use by AI

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…

Source-level debugger for Go with CLI, API, and headless modes; supports breakpoints, variable inspection, and execution tracing for efficient…

Set of tools to assess and improve LLM security.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.