Showing 36 of 73 projects
A static analysis security scanner for Ruby web applications, supporting Rails, Sinatra, and Padrino frameworks.
A PHP_CodeSniffer ruleset that detects security vulnerabilities and weaknesses in PHP code, including Drupal 7.
A collection of GitHub Actions for Snyk to check projects for vulnerabilities across multiple languages and tools.
A static application security testing (SAST) CLI tool that scans source code for OWASP Top 10 vulnerabilities across multiple programming languages.
A blackbox security profiling tool for Android that hooks and analyzes security-sensitive APIs at runtime.
Open-source static analysis tool for Python, TypeScript, and Go that detects dead code, security vulnerabilities, and AI-generated regressions.
A Visual Studio extension for real-time .NET secure code analysis that displays vulnerabilities as compiler warnings.
A secure, extensible command-line Android APK vulnerability analyzer written in Rust for automated security testing.
A fuzzer for Linux kernel drivers that combines interface recovery via LLVM analysis with a fuzzing engine to find security vulnerabilities.
A static security scanner for PHP code that identifies potential vulnerabilities without executing the code.
A static application security testing (SAST) tool for PHP that detects vulnerabilities like XSS through taint analysis.
A security scanning CLI tool that detects vulnerabilities, secrets, and outdated dependencies across multiple programming languages.
A static analysis tool for Android applications that detects security vulnerabilities through inter-procedure and intra-procedure analysis.
A tool to scan projects for regexes vulnerable to catastrophic backtracking (REDOS) through static extraction, detection, and validation.
A trustworthy ReDoS (Regular Expression Denial of Service) checker for identifying vulnerable regex patterns.
A static and symbolic analysis tool for finding memory safety bugs in browser code and other software.
Roslyn analyzers for detecting security vulnerabilities in .NET applications during development.
A browser emulation tool that detects exploits targeting browser and browser plugin vulnerabilities by analyzing various file types.
A dependency-aware GraphQL API fuzzing tool that automatically generates and executes security tests based on schema introspection.
A static analysis tool that spots security vulnerabilities in PostgreSQL extension scripts and SQL code.
A framework for using AFL to fuzz web applications and detect SQL/command injection vulnerabilities.
A collection of Splunk SPL queries for detecting vulnerability exploits, malware, and MITRE ATT&CK TTPs in security logs.
A static analyzer for Teal (Algorand Smart Contracts) that detects vulnerabilities and visualizes contract structure.
A lightweight static security analysis tool for modern Perl applications that identifies vulnerabilities using AST analysis and taint tracking.
A low-interaction honeypot that emulates Cisco ASA devices to detect exploitation attempts targeting CVE-2018-0101.
A tool to detect and mitigate Dependency Confusion supply chain security risks in npm projects.
A hybrid data-driven REST API fuzzer that combines sequence generation, request quality improvement, and parameter error detection.
A file format fuzzer for Android that pushes test files to emulators and monitors apps for buffer overflows.
A low-interaction honeypot that detects exploitation attempts targeting the CVE-2017-10271 WebLogic remote code execution vulnerability.
A CodeQL query suite for detecting common bug patterns in Cosmos SDK-based blockchain applications.
A fuzzing tool for ROS2 nodes that tests topics and services with pseudorandom data to uncover bugs and vulnerabilities.
A blockchain consensus protocol fuzzing framework that detects memory-related and logic bugs by modeling node states.
A fuzzing framework for automatically detecting and exploiting template escape bugs in template engines.
A low-interaction honeypot that simulates Oracle MICROS servers to detect exploitation attempts of the CVE-2018-2636 directory traversal vulnerability.
A fuzzer for discovering bugs and vulnerabilities in ROS nodes by testing topics with pseudorandom data.
Scans Alpine Linux Docker images for Common Vulnerabilities and Exposures (CVEs) using multi-stage builds.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.