
trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Project Wycheproof tests crypto libraries against known attacks.

An enterprise friendly way of detecting and preventing secrets in code.


Automatic SSTI detection tool with interactive interface

Collection of Offensive C# Tooling

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Protect against malicious open source packages 🤖

Pluggable linting tool to prevent committing credential.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

SQL / SQLI tokenizer parser analyzer

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…


Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

Trail of Bits Testing Handbook - appsec.guide

Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)