
aura
Python source code auditing and static analysis on a large scale

Python source code auditing and static analysis on a large scale

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Java library providing technical commons for XWiki projects, with a focus on vulnerability analysis and static code inspection for security testing.

The code of VulTriage: Triple-Path Context Augmentation for LLM-Based Vulnerability Detection


Java utility library with a focus on a specific CVE vulnerability, providing code analysis and static analysis capabilities for security assessment.

Interactive program analysis suite using Code Property Graphs to hunt for bugs in C and C++ code, unifying application-specific and low-level…

Java XML serialization library with a focus on the CVE-2013-7285 deserialization vulnerability, providing source code, binaries, and documentation…

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

Source code repository for Expat 2.1.0, a stream-oriented XML parser library, with focus on analyzing and addressing CVE-2022-43680.

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

Embeds and detects keyed, style-based watermarks in LLM-generated Python, Java, and C++ code via CST rewriting, preserving functional correctness and…

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Ghidra plugin that enhances reverse engineering by fixing missed disassembly, detecting functions, labeling crypto constants, and renaming functions…

An x86-64 code virtualizer for VM based obfuscation

Rust CLI suite that statically decompiles, deobfuscates, and unpacks native code, bytecode, scripts, firmware, and app packages across 15+ ecosystems…

AST-based Static Code Analyzer with Agentic LLM-Powered Relationship Mapping to discover Python RCE paths and deep deserialization chains on AI, LLM,…

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…