ASTTeam / SemgrepLinks
《深入理解Semgrep》Finding vulnerabilities with Semgrep.
☆55Updated 2 years ago
Alternatives and similar repositories for Semgrep
Users that are interested in Semgrep are comparing it to the libraries listed below
Sorting:
- Low-level RASP: Protecting Applications Implemented in High-level Programming Languages☆66Updated 2 years ago
- S&P2023 Paper☆39Updated 3 years ago
- Corax for Java: A general static analysis framework for java code checking.☆254Updated 10 months ago
- ☆161Updated last month
- JAVA IAST Example☆49Updated 3 years ago
- 静态分析及代码审计自动化相关资料收集☆296Updated 3 years ago
- https://ssa.to main page for ssa compiler utils☆51Updated last week
- Go-sec-code is a project for learning Go vulnerability code.☆43Updated 2 years ago
- 用来将Tai-e改造为开箱即用的静态代码安全分析框架的一些demo☆37Updated last year
- Auto-generated CodeQL rules for matching CVE vulnerabilities and variants.☆180Updated last year
- 安全本应纯粹,规避内卷,用一杯咖啡回归安全的乐趣!SEC.CAFE 安全咖啡是一个安全爱好者的服务平台与社区。☆46Updated 7 months ago
- ☆187Updated last week
- A benchmark to evaluate taint analysis☆29Updated 3 years ago
- A neo4j procedure for tabby☆133Updated 4 months ago
- Lessons for syntaxflow zero to hero☆52Updated last year
- 《深入理解DAST动态应用程序安全测试》Dynamic Application Security Testing.☆53Updated 2 years ago
- Cloud Native Security News☆65Updated 9 months ago
- Collection of CTF Web challenges I made☆52Updated 2 years ago
- Python bindings for CodeQL CLI☆54Updated 4 years ago
- 基于Java ASM技术和GadgetInspector的原理,尝试实现一个自动Java代码审计工具。目前做到了可控参数分析和数据流跟踪分析☆36Updated 3 years ago
- 《深入理解SAST静态应用安全测试》Static Application Security Testing.☆356Updated last week
- 自动反编译闭源应用,创建codeql数据库☆314Updated 3 years ago
- 个人使用CodeQL编写的一些规则☆176Updated 3 years ago
- 静态程序分析工具 主要生成方法的CFG和.java文件的AST☆132Updated 2 years ago
- ☆173Updated 2 years ago
- 收录go语言编写的项目、框架和组件出现的cve,或者一些相关的利用方式的文章☆42Updated 2 years ago
- ☆25Updated 3 years ago
- 一个辅助提交 CNVD/CNNVD/CVE 漏洞的工具☆19Updated 3 years ago
- 代码审计自动化系统,底层架构为蜻蜓编排系统,墨菲SCA,fortify,SemGrep,hema☆30Updated 6 months ago
- ☆28Updated 5 years ago