
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Pluggable linting tool to prevent committing credential.

Curated, community-maintained directory of data broker opt-out instructions to help individuals remove personal information from people-search sites…

A network diagnostic tool combining traceroute and ping for analyzing network paths, latency, and packet loss with an interactive terminal UI.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

German OWASP Day conference site & presentation archive

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…


External read-only game overlay for Linux. Derived offsets, composed skeletons, optional kernel module for ptrace-independent memory reads and…

GNU IFUNC is the real culprit behind CVE-2024-3094

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

Fast and accurate AI powered file content types detection

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Demonstrate CVE-2025-24257 with a public PoC for IOGPUFamily kernel heap OOB read/write and panic analysis

Educational security research repository for CVE-2025-9974, providing vulnerability awareness material and authorized lab guidance for controlled…