
gitleaks
Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

A tool to capture all the git secrets by leveraging multiple open source git searching tools

APKinspector is a powerful GUI tool for analysts to analyze the Android applications.

Automatic SSTI detection tool with interactive interface

A security focused static analysis tool for Android and Java applications.

A tool for generating fake code signing certificates or signing real ones

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

Pluggable linting tool to prevent committing credential.

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

VisualCodeGrepper - Code security scanning tool.

Multifunctional java deobfuscation tool suite