
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

The iOS Security Testing Framework

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

The Secure Coding Practices Quick-reference Guide from OWASP

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…

Clickbait. The CVE is AI slop.

Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…