
semgrep-rules
Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.

Detections for CVE-2021-44228 inside of nested binaries

Checklist and tools for increasing security of Apache Airflow

Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.

Inspect all of your Heroku apps for vulnerable versions of the JSON gem

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

A command-line tool for securely backing up, restoring, and verifying secrets using interoperable standards like age encryption and coreutils,…

An Inspec profile to check for Log4j CVE-2021-44228 and CVE-2021-45046

Find, verify, and analyze leaked credentials


go CVE-2023-24538 patch issue resolver - Dunfell

go CVE-2023-24538 patch issue resolver - Kirkstone

Authorized security-research lab: reproduction of CVE-2024-42370 / GHSA-4hq2-rpgc-r8r7 (env injection in docs-preview.yml) — snapshot of…

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

MCP server for Slither static analysis of Solidity smart contracts