247arjun / ai-secure-code-review
Welcome to `ai-secure-code-review`, a repository that integrates static analysis tools with Generative AI, specifically Semgrep and Azure OpenAI's GPT models, to automate and enhance code reviews for improved efficiency, scalability, and effectiveness in identifying potential software vulnerabilities.
☆30Updated 5 months ago
Alternatives and similar repositories for ai-secure-code-review:
Users that are interested in ai-secure-code-review are comparing it to the libraries listed below
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆133Updated 3 weeks ago
- GCP GOAT is the vulnerable application for learn the GCP Security☆64Updated last year
- This repository hosts several snippets and file related to the BsidesLV 2024 talk about Shadow and Zombie APIs by me☆18Updated 8 months ago
- LLM Testing Findings Templates☆70Updated last year
- A research project to add some brrrrrr to Burp☆155Updated 2 months ago
- An experimental project using LLM technology to generate security documentation for Open Source Software (OSS) projects☆28Updated last month
- Manager of third-party sources of Semgrep rules 🗂☆81Updated 9 months ago
- Blogpost series showcasing interesting cloud - web app security bugs☆47Updated last year
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆104Updated 2 months ago
- InfoSec OpenAI Examples☆19Updated last year
- Run Capture the Flags and Security Trainings with OWASP WrongSecrets☆45Updated this week
- A collection of Turbo Intruder scripts.☆58Updated 2 months ago
- ☆110Updated last year
- ☆35Updated 3 weeks ago
- A powerful tool that leverages AI to automatically generate comprehensive security documentation for your projects☆72Updated last week
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆62Updated 9 months ago
- A comprehensive knowledge base for security professionals to keep track of and build defenses against API attack techniques.☆43Updated 7 months ago
- ☆57Updated last year
- Tools and blogs I use to perform GCP red teams☆110Updated 9 months ago
- The Arcanum Prompt Injection Taxonomy☆60Updated last week
- 🖇️ STRIDE vs. ASVS equivalence table☆76Updated 8 months ago
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application a…☆157Updated 5 months ago
- A vulnerable environment for exploring common GCP misconfigurations and vulnerabilities☆27Updated last month
- ☆62Updated 4 months ago
- 📚A curated list of product security resources.☆19Updated 2 years ago
- A small tool to help developers understand a huge set of security requirements from appsec teams☆45Updated 2 years ago
- Do bulk whois lookups and get alerted on domains of interest.☆34Updated 8 months ago
- Tarpit - A Web application seeded with vulnerabilities, rootkits, backdoors & data leaks☆79Updated 2 years ago
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆49Updated 2 years ago
- ☆78Updated last year