
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

A static + runtime security scanner for MCP (Model Context Protocol) servers

A wrapper around grep, to help you grep for things


An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

A library for detecting known secrets across many web frameworks

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Find, verify, and analyze leaked credentials

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.