
sast-scan
Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.


Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

AI Smart Contract Security Analysis and PoC Generation Framework

Security research and reproduction of CVE-2025-5548: A stack-based buffer overflow in FreeFloat FTP Server 1.0. Includes binary analysis, crash…

AST-based Python code transformation & deobfuscation framework

Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis.…

Analyze any GitHub repo (URL or local path) → architecture map, verified run commands, risks, and actionable issues - in minutes.

Automatically create YARA rules from malicious documents.

Write your BPF programs in Go, not C. gobee transpiles a Go subset to BPF C and generates typed cilium/ebpf bindings.

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…