
dynast-bench
A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Collection of Solidity snippets and Foundry scripts for smart contract security audits

Community curated list of nuclei templates for finding "unknown" security vulnerabilities.

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

A collection of ZAP scripts and tips provided by the community - pull requests very welcome!

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

The Secure Coding Practices Quick-reference Guide from OWASP

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Curated collection of LLVM security resources covering binary lifting, code obfuscation, static analysis, symbolic execution, sanitizers, and…

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

Application Security Verification Standard

VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import…

Resources related to GitHub Security Lab

🔍NVD exploit & JVN(Japan Vulnerability Notes) easy description

OWASP Smart Contract Security (SCS) Project

OWASP Thick Client Application Security Verification Standard

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)