#1OWASP 速查表系列旨在针对特定的应用安全主题,提供一份简明扼要的高价值信息集合。

Ghidra 是一个软件逆向工程(SRE)框架

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

类 UNIX 逆向工程框架与命令行工具集

查找、验证和分析泄露的凭证

.NET 反编译器,支持PDB生成、ReadyToRun、元数据(及更多)——跨平台!

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…


在容器、Kubernetes、代码仓库、云环境等中发现漏洞、错误配置、密钥、SBOM

Go 源码级调试器,支持 CLI、API 和无头模式;具备断点、变量检查与执行跟踪功能,以实现高效调试。

快速、开源的静态分析工具,用于检测git仓库、文件和stdin流中硬编码的机密(如密码、API密钥和令牌),具有可自定义的规则引擎。

一个用于 Java、C、C++ 和 Objective-C 的静态分析器

社区策划的用于 nuclei 引擎寻找安全漏洞的模板列表。

轻量级多语言静态分析。通过类似源代码的模式查找Bug变种。

Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

CodeQL:为全球安全研究人员提供支持,以及GitHub高级安全中代码扫描功能的库和查询。