YASA is an open-source static program analysis project. Its core innovation lies in a unified intermediate representation called UAST, designed to support multiple programming languages. Built on top of UAST, YASA provides a highly accurate static analysis framework.
☆310Jul 28, 2026Updated last week
Alternatives and similar repositories for YASA-Engine
Users that are interested in YASA-Engine are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- YASA-UAST is an intermediate representation structure for multi-language program analysis. The UAST-Parser parses code from different pro…☆87Jul 6, 2026Updated last month
- xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".☆487May 21, 2026Updated 2 months ago
- 《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Explo…☆594Feb 7, 2026Updated 6 months ago
- The source code of [S&P'25] Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications.☆72Nov 20, 2025Updated 8 months ago
- 用于快速启动tabby 分析漏洞或者gadget的环境☆92Jul 14, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- 阿里巴巴安全SDK,提供SSRF、JDBC、XXE防护能力☆118Oct 15, 2025Updated 9 months ago
- Fenrir 是一个基于 MCP 协议与 AST 技术的代码审计工具,旨在解决安全研究与自动化代码审计领域中,面对大规模、结构复杂甚至反编译代码时,传统代码搜索与分析手段效率低、准确性差的问题。☆179Oct 21, 2025Updated 9 months ago
- A neurosymbolic framework for vulnerability detection in code☆411Jul 2, 2026Updated last month
- A CAT called tabby ( Code Analysis Tool )☆1,656Jan 17, 2026Updated 6 months ago
- LLMDFA: Analyzing Dataflow in Code with Large Language Models (NeurIPS 2024)☆215Oct 24, 2025Updated 9 months ago
- A declarative static analysis tool for jvm bytecode based Datalog like CodeQL☆341Jan 6, 2024Updated 2 years ago
- Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.…☆3,402Updated this week
- Hacking GraalVM Espresso - Abusing Continuation API to Make ROP-like Attack☆36Aug 27, 2025Updated 11 months ago
- 《深入理解CodeQL》Finding vulnerabilities with CodeQL.☆1,788Nov 21, 2023Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- An easy-to-learn/use static analysis framework for Java and Android☆1,799Jun 28, 2026Updated last month
- 一个专注于 Java Web 特性、配置和 Trick 的安全谜题集合☆125Dec 24, 2025Updated 7 months ago
- 在xxe中使用smb外带多行内容☆112Nov 9, 2025Updated 9 months ago
- An autonomous LLM-agent for large-scale, repository-level code auditing☆428Mar 12, 2026Updated 4 months ago
- 闭源系统半自动漏洞挖掘工具,针对 jar/war/zip 进行静态代码分析,输出从source到sink的可达路径。LLM将验证路径可达性,并根据上下文给出该路径可信分数☆510Jan 12, 2026Updated 6 months ago
- ☆210Oct 27, 2025Updated 9 months ago
- 一个基于jvm-sandbox高度定制化rasp☆58Sep 28, 2023Updated 2 years ago
- My presentation slides☆18Oct 31, 2025Updated 9 months ago
- 之前方便自己研究RASP原理和绕过时顺手写的,用于快速启动和重置RASP环境☆71Oct 13, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Query-Based Code Analysis Engine☆357Sep 21, 2025Updated 10 months ago
- 一个IDEA插件:一键收集项目中所有jar包依赖的工具插件。遍历项目目录收集所有jar文件,复制到all-in-one文件夹,并自动添加为项目库。☆55Oct 30, 2025Updated 9 months ago
- 利用代理驱动绕过JDBC Attack检测☆145Jun 15, 2025Updated last year
- Claude Code plugin for Java JAR security audit — 基于 jar-analyzer 的 Claude Code 安全审计插件,构建数据库,AI 深入分析☆138Mar 20, 2026Updated 4 months ago
- ☆225Dec 16, 2025Updated 7 months ago
- WALA 学习笔记☆14Aug 8, 2023Updated 3 years ago
- Extract entire function source code based on giving line number using Javaparser☆21Jul 15, 2025Updated last year
- ☆31Sep 1, 2025Updated 11 months ago
- GitHub项目监控 && CodeQL自动扫描 (GitHub project monitoring && CodeQL automatic analysis)☆467Jan 19, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- JDBC Connection URL Attack☆450Sep 10, 2021Updated 4 years ago
- Java Vulnerability Exploitation Platform☆2,140Updated this week
- Java web路由内存分析工具☆437May 22, 2025Updated last year
- ☆45Jan 30, 2023Updated 3 years ago
- VulnGym: A Real-World, Project-Level Vulnerability Benchmark for White-Box Vulnerability-Hunting Agents☆217Jun 26, 2026Updated last month
- SAST + LLM Interprocedural Context Extractor☆207Oct 28, 2025Updated 9 months ago
- [SOSP'25] Automatic checker synthesis for system-level static analysis☆183Oct 26, 2025Updated 9 months ago