advanced-security / custom-codeql-bundle
An example repository that demonstrates how the build custom CodeQL bundles that include query customizations through the `Customizations.qll` library
☆25Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for custom-codeql-bundle
- Custom / Experimental CodeQL queries☆37Updated 2 years ago
- My CodeQL queries collection☆94Updated last year
- [Deprecated] GitHub's Field Team's CodeQL Custom Queries, Suites, and Configurations. See GitHubSecurityLab/CodeQL-Community-Packs instea…☆80Updated 6 months ago
- My solution for GitHub Security Lab CTF 4: CodeQL and Chill - The Java Edition☆19Updated 4 years ago
- Personal CodeQL queries☆58Updated last week
- ☆70Updated 2 years ago
- Collection of community-driven CodeQL query, library and extension packs☆74Updated last week
- GH CLI CodeQL Scan Extension☆18Updated last month
- CodeQL model generation for Go.☆17Updated 3 years ago
- Action to retrofit a CodeQL bundle with additional queries, libraries, and customizations☆21Updated 6 months ago
- CodeQL database manager☆46Updated 9 months ago
- GreHack 2021 CodeQL for Java workshop☆75Updated 3 years ago
- Several XStream gadgets ported from ysoserial☆32Updated 3 years ago
- ☆15Updated 3 years ago
- Run CodeQL queries at scale using Multi-Repository Variant Analysis (MRVA)☆49Updated 7 months ago
- A proof-of-concept tool for detection and exploitation Object Injection Vulnerabilities in .NET applications☆62Updated 3 years ago
- ☆12Updated 3 years ago
- Unofficial Dockerfile and scripts for building CodeQL databases for the OpenJDK☆47Updated 10 months ago
- A static analysis API for finding deserialization attack gadgets☆38Updated 2 years ago
- ☆78Updated 3 years ago
- Library for manually creating Java serialization data.☆28Updated last year
- CTF stuff☆40Updated last year
- ☆33Updated 2 years ago
- ☆22Updated 2 years ago
- 一些Java RASP demo☆11Updated 5 years ago
- POC for leaking java version through file and ftp protocols☆24Updated 4 years ago
- Additional materials for RootedCON 2015 Apache Struts talk☆28Updated 9 years ago
- generate facts from bytecode (source is https://github.com/plast-lab/doop-mirror/tree/master/generators)☆23Updated 10 months ago
- Dependencies with Log4j2 Checklist☆35Updated 2 years ago
- Some PoC (Proof-of-Concept) about vulnerability of java deserialization of untrusted data☆26Updated 3 years ago