AppThreat / atom
Atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.
β52Updated this week
Related projects β
Alternatives and complementary repositories for atom
- XBOW Validation Benchmarksβ53Updated 2 months ago
- Manager of third-party sources of Semgrep rules πβ76Updated 4 months ago
- Code Hierarchy Exploration Net (chen)β14Updated this week
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.0, purl, and versβ¦β98Updated this week
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and oβ¦β71Updated 3 weeks ago
- π§ͺ Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.β33Updated last month
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,β¦β126Updated 9 months ago
- β46Updated this week
- Create notes during a security code review in VSCode π Import your favorite SAST tool findings π οΈ and collaborate with others π€β131Updated last year
- Trail of Bits Testing Handbookβ58Updated 3 weeks ago
- PURL to CPE Relationship mapping project.β78Updated this week
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebasβ¦β141Updated 8 months ago
- Community reconstruction of the legacy JSON NVD Data Feeds. This project uses and redistributes data from the NVD API but is neither endoβ¦β113Updated this week
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsβ98Updated 9 months ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.β22Updated 3 months ago
- β115Updated last year
- πA cutting edge context aware GraphQL API fuzzing tool!β126Updated this week
- β175Updated 2 weeks ago
- Generative and mutative fuzzer for Kubernetes admission controller chains by automatically parsing the cluster api specification.β70Updated last year
- A collection of Semgrep rules which followed security guidelines for .NET and Java.β16Updated 3 years ago
- The security workflow engine!β73Updated this week
- CodeQL queries developed by Trail of Bitsβ75Updated this week
- β41Updated 4 months ago
- An open-source dataset of malicious software packages found in the wild, 100% vetted by humans.β140Updated this week
- A community collection of security reviews of open source software components.β92Updated 8 months ago
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilitβ¦β254Updated this week
- boostsecurityio/lotpβ101Updated 7 months ago
- Coverage-Guided Greybox Distributed Fuzzerβ128Updated 3 months ago
- Common Corpus is used to build coverage-minimized corpus data sets for fuzzing.β24Updated last year
- Open Source Vulnerability schema.β185Updated this week