
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Community curated list of templates for the nuclei engine to find security vulnerabilities.

0-day malware detection for binaries, source & scripts (that doesn't suck)

Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA

Tool for advanced mining for content on Github

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Open-source threat intelligence platform for malware and observable analysis. Enriches IPs, domains, URLs, and hashes with external sources, performs…

Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging

A desktop workbench for writing, validating, compiling, and testing YARA rules.

agent runtime security - zero trust, zero setup, zero latency agent sandbox

Multi-format malware analysis platform combining a stealth Ring-3 Windows sandbox, static PE/PDF analyzers, ransomware key recovery, and an AI…

AI-powered security co-pilot that catches vulnerabilities as you code. Real-time security scanning, educational explanations, and auto fixes for…

PowerShell Obfuscation Detection Framework

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

YARA Rule Strings Statistics Calculator and Malware Research Helper

Using code search to help fix/mitigate log4j CVE-2021-44228