#1Static and dynamic code analysis, SAST, DAST, and code review tools.
Kitploit 추천

Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA
OWASP 치트 시트 시리즈는 특정 애플리케이션 보안 주제에 대한 고가치 정보의 간결한 모음을 제공하기 위해 만들어졌습니다.

Ghidra는 소프트웨어 리버스 엔지니어링(SRE) 프레임워크입니다.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

UNIX 계열 리버스 엔지니어링 프레임워크 및 명령줄 도구 모음

유출된 자격 증명을 찾고, 검증하고, 분석합니다.

.NET 디컴파일러, PDB 생성 지원, ReadyToRun, 메타데이터(및 기타) - 크로스 플랫폼!

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…


컨테이너, Kubernetes, 코드 리포지토리, 클라우드 등에서 취약점, 잘못된 구성, 비밀, SBOM을 찾습니다.

CLI, API 및 헤드리스 모드를 지원하는 Go용 소스 수준 디버거로, 중단점, 변수 검사 및 실행 추적을 지원하여 효율적인 디버깅을 제공합니다.

빠르고 오픈소스인 정적 분석 도구로, Git 저장소, 파일, stdin 스트림에서 비밀번호, API 키, 토큰과 같은 하드코딩된 비밀 정보를 감지하며 사용자 정의 규칙 엔진을 지원합니다.

Java, C, C++, Objective-C를 위한 정적 분석기

커뮤니티가 엄선한 nuclei 엔진용 템플릿 목록으로, 보안 취약점 탐색에 사용됩니다.

많은 언어를 위한 경량 정적 분석. 소스 코드처럼 보이는 패턴으로 버그 변종을 찾습니다.

Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

CodeQL: 전 세계 보안 연구원들과 GitHub Advanced Security의 코드 스캐닝을 지원하는 라이브러리 및 쿼리 모음입니다.