
DepFuzzer
Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)

RCE exploit toolkit for CVE-2025-55182 and CVE-2025-66478 in React Server Components. Includes multiple exploit variants, detection scripts, a…

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

Semantic inspector for SQL — catches fan-out double-counting, additivity violations, wrong join keys, and policy breaches before the query runs.…

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…

Externalize Java application access to protected resources as log messages.

Tool for advanced mining for content on Github

NCC Code Navigator

Command-line tool for fast searching of GitHub repositories, users, and commits to gather open-source intelligence and code-related information.

Standalone MCP server plugin for IDA Pro.

Go library for parsing and executing Sigma detection rules against log entries, supporting field modifiers, CIDR matching, and custom field resolvers…

Hunt for AI coding artifacts containing secrets.

Use regular expressions to get sensitive information from a given repository (GitHub, pip or npm).

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

OWASP Thick Client Application Security Verification Standard