
graudit
grep rough audit - source code auditing tool

grep rough audit - source code auditing tool

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

Static code analysis tool based on Elasticsearch

A static analysis tool for securing Go code

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Java utility library with patched CVE-2022-4244 vulnerability, providing common helper classes for I/O, reflection, and CLI argument parsing in…

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.