
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

The system of record for AI-written software. A persistent graph of entities, relationships, changes, and provenance, so humans and AI agents see…

UNIX-like reverse engineering framework and command-line toolset

Self-hosted multi-agent environment for Go with LLM-powered pentesting agents (exploiter, reverser, threathunter, webscanner) that automate…

Community curated list of templates for the nuclei engine to find security vulnerabilities.

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

Static analysis of malicious Python code

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Source code for the Binaries of OWASP WrongSecrets

Collection of Solidity snippets and Foundry scripts for smart contract security audits

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Find, verify, and analyze leaked credentials

Reverse engineering assistant that uses a locally running LLM to aid with pseudocode analysis.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision