
sast-scan
Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Open source compliance tool for development platforms.

UnauthScout is an OSINT (Open Source Intelligence) tool developed in Bash for passive exploration of assets on version control platforms (GitLab and…

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

Detection script for cve-2021-23358

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Link sources to sinks in C# applications.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Static code analysis tool based on Elasticsearch

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Web services framework for building and developing SOAP, RESTful, and CORBA services with support for WS-Security, WS-Trust, and JAX-WS/JAX-RS APIs.

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…