
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

chat log tool, easily use your own chat data. 聊天记录工具,轻松使用自己的聊天数据

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

A collection of awesome security hardening guides, tools and other resources

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Parallel backup and restore solution for PostgreSQL with encryption, delta restore, and multi-cloud object store support for enterprise disaster…

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

Collaborative Passwords Manager

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Open-source vulnerability database aggregating CVE data from multiple sources with a web UI and API. Maps vulnerabilities to specific software…

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…


A Python Framework For NoSQL Scanning and Exploitation

MSDAT: Microsoft SQL Database Attacking Tool