Contrast-Security-OSS / contrast-rO0
A tiny Java agent that blocks attacks against unsafe deserialization
☆83Updated 7 years ago
Alternatives and similar repositories for contrast-rO0:
Users that are interested in contrast-rO0 are comparing it to the libraries listed below
- Java Agent which mitigates deserialisation attacks by making certain classes unserializable☆189Updated 8 years ago
- Identify vulnerable libraries in Maven dependencies☆46Updated 2 years ago
- A rule for the Maven enforcer plugin to check for vulnerable artifacts within a project.☆40Updated 4 years ago
- Hdiv CE | Application Self-Protection☆214Updated 2 months ago
- Externalize Java application access to protected resources as log messages.☆40Updated 9 months ago
- A static analysis API for finding deserialization attack gadgets☆38Updated 2 years ago
- Java Deserialization☆26Updated 8 years ago
- Maven plugin for integrating with HCL AppScan Source☆9Updated last year
- Custom security ruleset for the popular Java static analysis tool PMD.☆61Updated 9 years ago
- OWASP Security Logging library for Java☆116Updated last year
- Primitive tool for exploring/querying Java classes via the Tinkerpop Gremlin graph traversal language☆104Updated 8 years ago
- Evaluation Framework for Dependency Analysis (EFDA)☆43Updated 2 years ago
- Owasp Orizon is a source code static analyzer tool designed to spot security issues in Java applications.☆144Updated 7 years ago
- ThreadFix is a software vulnerability management platform. This GitHub site is far out of date. Please go to www.threadfix.it for up-to-d…☆339Updated 2 years ago
- Serial Whitelist Application Trainer☆29Updated 5 years ago
- Look-Ahead Java Deserialization Library☆411Updated 5 years ago
- Coverity Security Library (CSL) is a lightweight set of escaping routines for fixing cross-site scripting (XSS), SQL injection, and other…☆202Updated 8 years ago
- CVE database store☆130Updated 4 years ago
- A simple Java command-line utility to mirror the entire contents of VulnDB.☆44Updated 2 months ago
- An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressions☆122Updated 7 years ago
- Java taint propagation for java. Define tainted sources, sanitizer methods and sinks via aspects.☆28Updated 6 years ago
- Code Pulse is a real-time code coverage tool for penetration testing activities☆119Updated 2 years ago
- ☆132Updated 9 years ago
- ☆14Updated 5 years ago
- Java web and command line applications demonstrating various security topics☆237Updated this week
- Repository to showcase various configuration recipes with various technologies☆35Updated 2 years ago
- JMSDigger is JMS API basedEnterprise Messaging Application assessment tool☆31Updated 10 years ago
- An API for consuming all the memory of Java apps using deserialization☆28Updated 9 years ago
- ☆492Updated 8 years ago
- General Open Architecture Security Questionnaire☆31Updated last year