
cfn_nag
Linting tool for CloudFormation templates

Linting tool for CloudFormation templates

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security


A list of awesome penetration testing tools and resources.

UT based automated fuzz driver generation

Python Command-Line Ghidra Decompiler

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

Go static analysis tool that checks for security issues using an AST.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

👮 👊 RegEx Denial of Service (ReDos) Scanner