
log4shell-CVE-2021-44228
Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

Sourcetrail - free and open-source interactive source explorer

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

nodejsscan is a static security code scanner for Node.js applications.

grep rough audit - source code auditing tool

VisualCodeGrepper - Code security scanning tool.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

a static analysis tool for finding vulnerabilities in C/C++ source code

Static code analysis tool based on Elasticsearch

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

Python Command-Line Ghidra Decompiler

VBScript & VBA source-to-source deobfuscator with partial-evaluation

NCC Code Navigator