ASTTeam / Semgrep
《深入理解Semgrep》Finding vulnerabilities with Semgrep.
☆43Updated last year
Alternatives and similar repositories for Semgrep:
Users that are interested in Semgrep are comparing it to the libraries listed below
- Low-level RASP: Protecting Applications Implemented in High-level Programming Languages☆57Updated last year
- CodeQL中文资料和常见使用解释。Chinese version of Codeql documents☆9Updated 4 years ago
- 《深入理解DAST动态应用程序安全测试》Dynamic Application Security Testing.☆49Updated 2 years ago
- S&P2023 Paper☆39Updated 2 years ago
- Collect some security conference topics☆38Updated 6 months ago
- JAVA IAST Example☆47Updated 3 years ago
- Go-sec-code is a project for learning Go vulnerability code.☆37Updated last year
- 收录go语言编写的项目、框架和组件出现的cve,或者一些相关的利用方式的文章☆36Updated 2 years ago
- ☆28Updated 4 years ago
- 用来将Tai-e改造为开箱即用的静态代码安全分析框架的一些demo☆36Updated 9 months ago
- A benchmark to evaluate taint analysis☆30Updated 2 years ago
- 代码审计自动化系统,底层架构为蜻蜓编排系统,墨菲SCA,fortify,SemGrep,hema☆26Updated 3 months ago
- ☆35Updated 3 years ago
- Cloud Native Security News☆59Updated 3 weeks ago
- Tai-e的Web插件☆22Updated 7 months ago
- neo4j plugin of ByteCodeDL for the IntelliJ Platform. ByteCodeDL-Neo4j-IDEA-Plugin☆16Updated last year
- ☆31Updated 7 months ago
- 简单实现的 Java RASP☆35Updated 4 years ago
- Collection of CTF Web challenges I made☆51Updated last year
- 基于Java ASM技术和GadgetInspector的原理,尝试实现一个自动Java代码审计工具。目前做到了可控参数分析和数据流跟踪分析☆36Updated 3 years ago
- ☆41Updated 3 years ago
- slides and papers from (or partly from) Bonan☆22Updated 10 months ago
- A neo4j procedure for tabby☆116Updated 7 months ago
- 基于污点分析的JSP Webshell检测工具,模拟JVM的栈帧操作进行数据流分析,可以检测出各种变形的JSP Webshell☆20Updated 3 years ago
- generate facts from bytecode (source is https://github.com/plast-lab/doop-mirror/tree/master/generators)☆23Updated last month
- 安全大佬 Top 100☆66Updated 2 years ago
- CTF中Pwn的快速利用模板(包含awd pwn)☆27Updated 3 years ago