
slowql
Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Python Command-Line Ghidra Decompiler

NCC Code Navigator

A list of awesome penetration testing tools and resources.

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Checklist and tools for increasing security of Apache Airflow

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Link sources to sinks in C# applications.


Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Open-source, cross-platform, multi-purpose security auditing tool

OSWE, OSEP, OSED, OSEE

PHP Static Analysis Tool - discover bugs in your code without running it!