
CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Snyk CLI scans and monitors your projects for security vulnerabilities.

Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.

Community curated list of templates for the nuclei engine to find security vulnerabilities.

A security focused static analysis tool for Android and Java applications.

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

A minimal, secure Python interpreter written in Rust for use by AI

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Read-only scanner for what lets a repository run code in a coding agent (Claude Code, Codex, Cursor, Copilot): git settings, hooks, and committed MCP…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Ghidra is a software reverse engineering (SRE) framework

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…