RefactorSecurity / vscode-security-notes
Create notes during a security code review in VSCode ๐ Import your favorite SAST tool findings ๐ ๏ธ and collaborate with others ๐ค
โ133Updated 3 weeks ago
Alternatives and similar repositories for vscode-security-notes:
Users that are interested in vscode-security-notes are comparing it to the libraries listed below
- boostsecurityio/lotpโ123Updated last week
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsโ104Updated 2 months ago
- Manager of third-party sources of Semgrep rules ๐โ81Updated 9 months ago
- โ110Updated last year
- Blogpost series showcasing interesting cloud - web app security bugsโ47Updated last year
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRFโ58Updated last year
- โ177Updated last week
- โ189Updated 5 months ago
- โ114Updated last year
- truffleproc โ hunt secrets in process memory (TruffleHog & gdb mashup)โ116Updated last year
- ๐๏ธ STRIDE vs. ASVS equivalence tableโ76Updated 8 months ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.โ261Updated last month
- An extension to use Semgrep inside Burp Suite.โ88Updated last year
- Nuclei plugins to audit Chrome extensionsโ64Updated 9 months ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.โ40Updated last year
- Protect against subdomain takeoverโ92Updated 11 months ago
- HASH (HTTP Agnostic Software Honeypot)โ139Updated 11 months ago
- Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessmentsโ139Updated 3 months ago
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application aโฆโ157Updated 5 months ago
- A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalationโ103Updated last year
- A tool to keep AWS pentests and red teams efficient, organized, and stealthy.โ91Updated last year
- A research project to add some brrrrrr to Burpโ155Updated 2 months ago
- Enumeration/exploit/analysis/download/etc pentesting framework for GCP; modeled like Pacu for AWS; a product of numerous hours via @Webbiโฆโ243Updated last month
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raiderโ139Updated 3 years ago
- Hide from the InstanceCredentialExfiltration GuardDuty finding by using VPC Endpointsโ114Updated last year
- ๐งช Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.โ39Updated 4 months ago
- Recon tool for cloud provider attribution. Supports AWS, Azure, Google, Cloudflare, and Digital Ocean.โ166Updated 5 months ago
- Tools to assess DNS security.โ152Updated last year
- โ62Updated 4 months ago
- GCP GOAT is the vulnerable application for learn the GCP Securityโ64Updated last year