
CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

.NET Decompiler with support for PDB generation, ReadyToRun, Metadata (&more) - cross-platform!

Main repo for hosting release binaries

A static analyzer for Java, C, C++, and Objective-C

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Fast and accurate AI powered file content types detection

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

PHP Static Analysis Tool - discover bugs in your code without running it!

Find, verify, and analyze leaked credentials

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.