
jsluicepp
jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

A collection of smart contract vulnerabilities along with prevention methods

A collection of my Semgrep rules to facilitate vulnerability research.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Tool for reverse engineering of Angular applications

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

👮 👊 RegEx Denial of Service (ReDos) Scanner

A list of awesome penetration testing tools and resources.

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

Checklist and tools for increasing security of Apache Airflow

Curated weggli queries for static analysis of C/C++ code to identify dangerous functions, stack issues, and malloc overflow vulnerabilities.