
noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

A plugin to introduce interactive symbols into your debugger from your decompiler

Performing security tests inside your CI

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

🦆 Malduck is your ducky companion in malware analysis journeys

a fast check, if your server could be vulnerable to CVE-2021-44228

Write your BPF programs in Go, not C. gobee transpiles a Go subset to BPF C and generates typed cilium/ebpf bindings.

Automatic security vulnerability remediation for your code.

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

Static binary analysis with Detect It Easy — 100% in your browser, no uploads.

A lightweight hex editor and decompiler to solve your binary file analysis problems.

Pre-execution intent verification for AI agents. Audits what your AI is about to do, not what it says. Zero dependencies, deterministic, hash-sealed.

A doggo that helps look for security issues in your repositories.