ASTTeam / IAST
《深入理解IAST交互式应用安全测试》Interactive Application Security Testing.
☆13Updated 2 years ago
Alternatives and similar repositories for IAST
Users that are interested in IAST are comparing it to the libraries listed below
Sorting:
- 《深入理解DAST动态应用程序安全测试》Dynamic Application Security Testing.☆51Updated 2 years ago
- 手把手教你写IAST系列☆24Updated last year
- Spring Cloud Netflix Hystrix Dashboard template resolution vulnerability CVE-2021-22053☆37Updated 2 years ago
- 安全升级jar包时,辅助检测Java Archive (JAR) 包之间兼容性☆14Updated 10 months ago
- ☆41Updated 4 years ago
- jre8u20 gadget☆33Updated 3 years ago
- JAVA IAST Example☆48Updated 3 years ago
- springboot getRequestURI acl bypass☆37Updated 4 years ago
- ☆14Updated 3 years ago
- fastjson auto type derivation search☆21Updated 3 years ago
- TongASDP漏洞测试环境☆35Updated 2 years ago
- ☆33Updated 2 years ago
- 代码审计自动化系统,底层架构为蜻蜓编排系统,墨菲SCA,fortify,SemGrep,hema☆28Updated 2 months ago
- neo4j plugin of ByteCodeDL for the IntelliJ Platform. ByteCodeDL-Neo4j-IDEA-Plugin☆16Updated last year
- 渗透技术栈☆20Updated 5 years ago
- 一个高价值漏洞采集与推送服务 | A valueable vulnerability collection and push service☆31Updated 7 months ago
- Unofficial Dockerfile and scripts for building CodeQL databases for the OpenJDK☆49Updated last year
- MysqlHoneypot☆23Updated 3 years ago
- xrecon is a powerful web fingerprinting tool with CDN detection capabilities☆33Updated 9 months ago
- 收集规则☆30Updated 2 years ago
- My security presentations☆28Updated last year
- 打CTF实在厌倦了找利用链,就知道一个fastjson的版本,一堆依赖找啊找,头都疼。为了解决这个烦恼,用了卓卓师傅的fastjson黑名单工具和库,自己改造了一下。☆32Updated 5 years ago
- 子域名接管的几种变体靶场☆23Updated 10 months ago
- Automatically scan jar packages by using ast to find fastjson gadgets. In particular, this project is limited to mining Gadgets that may …☆50Updated 3 years ago
- CodeQL extractor for java, which don't need to compile java source☆10Updated 2 years ago
- notes☆27Updated 2 years ago
- Low-level RASP: Protecting Applications Implemented in High-level Programming Languages☆59Updated last year
- cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件☆90Updated 2 years ago
- API Security DAST & Oprations☆16Updated last year
- Celestion 是一个无回显漏洞测试辅助平台,平台使用flask编写,提供DNSLOG,HTTPLOG等功能。 (界面懒得弄,后续有需要再说)。☆30Updated last year