
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

nextpnr portable FPGA place and route tool

A project dedicated to teaching beginners and non-tech-savvy people about digital privacy and cybersecurity.

Chase H.Q. for ZX Spectrum — reverse-engineered and reconstructed in portable C

Hardened Android web browser forked from Mull/Firefox with privacy-focused patches, anti-fingerprinting, telemetry removal, and secure defaults for…

Behavioral eval lab (Quorum) for the superpowers project that drives real coding-agent CLIs (Claude, Codex, Gemini, Kimi, and more) through a QA…

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

No-root network monitor, firewall and PCAP dumper for Android

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

SpecterOps Presentations

Rust tool to detect cell site simulators on an orbic mobile hotspot

OWASP Smart Contract Security (SCS) Project

Comprehensive set of over 1500 AppArmor profiles to confine Linux system processes, desktops, and services, with support for multiple distributions…

OWASP Certified Secure-Software Developer

Educational security research repository for testing and learning vulnerability concepts, sandboxing, secure coding, and defensive practices in…

Proof-of-concept exploit scripts for CVE-2024-8068 and CVE-2024-8069, focused on authorized penetration testing, educational labs, and defensive…