
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

A static + runtime security scanner for MCP (Model Context Protocol) servers

A library for detecting known secrets across many web frameworks

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

A vulnerability scanner for container images and filesystems

A wrapper around grep, to help you grep for things


An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

Find, verify, and analyze leaked credentials

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages