
vulnhuntr
Zero shot vulnerability discovery using LLMs

Zero shot vulnerability discovery using LLMs

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

A Chrome extension static analysis tool to help aide in security reviews.

Go CLI that deobfuscates javascript-obfuscator (obfuscator.io) output and unminifies JavaScript using AST transforms, static decoding, and a goja…

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

Write your BPF programs in Go, not C. gobee transpiles a Go subset to BPF C and generates typed cilium/ebpf bindings.

Static analysis tool for investigating potentially malicious Microsoft Excel files, extracting metadata, macros, and embedded objects to aid digital…

Detect and fix log4j log4shell vulnerability (CVE-2021-44228)

A tool written in Go that scans files & directories for the Follina exploit (CVE-2022-30190)

Static analysis CLI that scans AI-generated code for vulnerabilities like SQL injection, unsafe reflection, and hardcoded secrets, with SARIF export…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

CLI tool that scans codebases for high-entropy lines to detect potential secrets, with customizable file extension and top-N filtering.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Go package that checks if RSA keys are vulnerable to ROCA / CVE-2017-15361

Command-line and GUI tool for decompiling Android Dex and APK files into readable Java source code, with resource decoding, deobfuscation, and Smali…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…