
slowql
Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

find hardcoded strings from source code

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…


client-side prototype pullution vulnerability scanner

NCC Code Navigator

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

A list of awesome penetration testing tools and resources.

The Secure Coding Practices Quick-reference Guide from OWASP

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.


Checklist and tools for increasing security of Apache Airflow

SAST CLI for scanning Java, JavaScript, and .NET applications plus AWS Lambda functions, detecting code vulnerabilities and over-permissive IAM…