
ghostrace
Proof-of-concept and static analysis toolkit for finding speculative race condition (SCUAF) gadgets in Linux kernel. Includes 1200+ gadget dataset.

Proof-of-concept and static analysis toolkit for finding speculative race condition (SCUAF) gadgets in Linux kernel. Includes 1200+ gadget dataset.

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

NCC Code Navigator

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

Curated weggli queries for static analysis of C/C++ code to identify dangerous functions, stack issues, and malloc overflow vulnerabilities.

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

nodejsscan is a static security code scanner for Node.js applications.

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

find hardcoded strings from source code

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Sourcetrail - free and open-source interactive source explorer

AWS Serverless Security

Easy setup of static analysis tools for Android and Java projects.