
ASST
OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Static code analysis plugin for Android project. (Checkstyle, PMD)

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

find hardcoded strings from source code

👮 👊 RegEx Denial of Service (ReDos) Scanner

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Python Command-Line Ghidra Decompiler

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

VBScript & VBA source-to-source deobfuscator with partial-evaluation

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

client-side prototype pullution vulnerability scanner

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

A list of awesome penetration testing tools and resources.

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…