
capslock
CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

A minimal LLM-powered zero-day vulnerability scanner by AISLE.

Proof-of-concept for CVE-2023-4863, a heap buffer overflow in WebP image decoding. Demonstrates the code_lengths trigger mechanism discovered by…

IDA Pro plugin for filtering functions by assembly patterns, byte sequences, string/name references, and size constraints, with rule-based search and…

Kurukshetra - A framework for teaching secure coding by means of interactive problem solving.

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Modular framework to detect and prevent dependency confusion attacks by analyzing package manifests across multiple sources and package management…

Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…

Plugin for Binary Ninja that integrates local Ollama models to rename functions and variables in decompiled HLIL code, preserving privacy by keeping…

WslinkVMAnalyzer is a tool to facilitate analysis of code protected by a virtual machine featured in Wslink malware

Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class…

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…