
trivy-action
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

An easy-to-learn/use static analysis framework for Java and Android

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Run PowerShell with rundll32. Bypass software restrictions.

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

A vulnerable version of Rails that follows the OWASP Top 10

Protect against malicious open source packages 🤖

Vulnerability Patterns Detector for C# and VB.NET

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

A language and library for specifying syscall filtering policies.

A static code analysis for WordPress (and PHP)

ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).

A source code static analysis platform for AppSec enthusiasts.

Static analysis of malicious Python code

Interactive program analysis suite using Code Property Graphs to hunt for bugs in C and C++ code, unifying application-specific and low-level…

Scala-based static analysis framework for Android and Java bytecode with flow analysis, decompilation, and native code analysis via symbolic…