
cfn_nag
Linting tool for CloudFormation templates

Linting tool for CloudFormation templates

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Semantic static analysis engine and query library for detecting security vulnerabilities in source code, enabling automated code scanning and CI/CD…

Language server for YARA rule development, providing code completion, linting, formatting, navigation, and debugging support inside IDEs.

Source code security scanner for expert code review; emits file:line findings in plain text, designed for fast manual triage and filtering with…

A list of awesome penetration testing tools and resources.

UT based automated fuzz driver generation

Batch-decompile binaries with Ghidra from the command line, generating per-function C files, callgraphs, BSim signatures, and optional SAST results…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Interactive Python call graph navigator for tracing code paths from user input to dangerous patterns, designed for security auditing and code…

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

Go static analysis tool that checks for security issues using an AST.

Automated security audit wrapper for .NET binaries: runs CAT.NET static analysis on all .NET binaries in a folder and tracks findings in a database.

👮 👊 RegEx Denial of Service (ReDos) Scanner