
AuraBorealisApp
Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

a static analysis tool for finding vulnerabilities in C/C++ source code

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Static analysis CLI that scans AI-generated code for vulnerabilities like SQL injection, unsafe reflection, and hardcoded secrets, with SARIF export…

A static analyzer for Java, C, C++, and Objective-C

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Python Command-Line Ghidra Decompiler

Link sources to sinks in C# applications.

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Tool for reverse engineering of Angular applications

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Security hardening toolkit for COBOL legacy systems — invisible Unicode detection, format boundary analysis, source transformation integrity

A list of awesome penetration testing tools and resources.