
ASC
Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

A desktop workbench for writing, validating, compiling, and testing YARA rules.

Community curated list of templates for the nuclei engine to find security vulnerabilities.

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

Find, verify, and analyze leaked credentials

Main repo for hosting release binaries

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

UNIX-like reverse engineering framework and command-line toolset

PHP Static Analysis Tool - discover bugs in your code without running it!

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Django application that performs SAST and Malware Analysis for Android APKs

A security focused static analysis tool for Android and Java applications.

Ghidra is a software reverse engineering (SRE) framework

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…