
frelatage
Coverage-based fuzzer for python applications

Coverage-based fuzzer for python applications

A coverage-guided fuzzer for pure Ruby code and Ruby C extensions

Edge-coverage-guided fuzzer for PHP libraries that detects bugs via crashes, timeouts, and warnings. Supports corpus management, crash minimization,…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Source-level debugger for Go with CLI, API, and headless modes; supports breakpoints, variable inspection, and execution tracing for efficient…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

Application Security Verification Standard

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

A lightweight dynamic instrumentation library

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

A wrapper around grep, to help you grep for things

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Demystifying Exploitable Bugs in Smart Contracts

Curated collection of LLVM security resources covering binary lifting, code obfuscation, static analysis, symbolic execution, sanitizers, and…

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Automatic SSTI detection tool with interactive interface