
ApplicationInspector
A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

nodejsscan is a static security code scanner for Node.js applications.

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

Proof-of-concept and static analysis toolkit for finding speculative race condition (SCUAF) gadgets in Linux kernel. Includes 1200+ gadget dataset.

Curated weggli queries for static analysis of C/C++ code to identify dangerous functions, stack issues, and malloc overflow vulnerabilities.

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

AWS Serverless Security

Easy setup of static analysis tools for Android and Java projects.

Sourcetrail - free and open-source interactive source explorer

find hardcoded strings from source code

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…

NCC Code Navigator

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool