
Agentic-Bug-Hunter
AI-powered bug bounty hunting toolkit that works with or without subscription.

AI-powered bug bounty hunting toolkit that works with or without subscription.

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Linting tool for CloudFormation templates

The Secure Coding Framework

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

Sourcetrail - free and open-source interactive source explorer

A static analysis tool for securing Go code

The iOS Security Testing Framework

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.