apiiro / malicious-code-ruleset
Focused malicious code detection ruleset, with a high protection-to-noise ratio
β116Updated 2 months ago
Alternatives and similar repositories for malicious-code-ruleset:
Users that are interested in malicious-code-ruleset are comparing it to the libraries listed below
- A comprehensive checklist and guide for organizations looking to implement a robust cybersecurity programβ15Updated last week
- A powerful tool that leverages AI to automatically generate comprehensive security documentation for your projectsβ76Updated 3 weeks ago
- π§ͺ Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.β39Updated 4 months ago
- Semgrep-based Policy Controller for Kubernetesβ47Updated last month
- boostsecurityio/lotpβ123Updated 3 weeks ago
- Prevent merging of malicious code in pull requestsβ220Updated last month
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.β41Updated last year
- Demonstrates how a malicious dependency could negatively impact the build output.β25Updated last year
- This tool analyzes a given Gitlab repository and searches for dangling or force-pushed commits containing potential secret or interestingβ¦β47Updated 8 months ago
- β180Updated 3 weeks ago
- Enriching the NVD CVSS scores to include Temporal & Threat Metricsβ194Updated this week
- AI featured threat modeling and security review actionβ43Updated 5 months ago
- Security tool against dependency typosquatting attacksβ39Updated this week
- Create notes during a security code review in VSCode π Import your favorite SAST tool findings π οΈ and collaborate with others π€β133Updated last month
- Nuclei plugins to audit Chrome extensionsβ64Updated 9 months ago
- β64Updated last week
- Independently deploy customized honeyservices in AWS to trigger alerts on unauthorized access. It utilizes a dedicated CloudTrail for preβ¦β51Updated 5 months ago
- β63Updated 3 months ago
- An experimental project using LLM technology to generate security documentation for Open Source Software (OSS) projectsβ28Updated 2 months ago
- β35Updated 9 months ago
- A tool for preventing the installation of malicious PyPI and npm packagesβ141Updated this week
- HashiCorp-relevant rules for the Semgrep code analysis toolβ41Updated last year
- β110Updated last year
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflowsβ95Updated last month
- Build a CVE library with aggregated CISA, EPSS and CVSS dataβ27Updated last year
- This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.β54Updated 3 months ago
- Manager of third-party sources of Semgrep rules πβ81Updated 9 months ago
- Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessmentsβ140Updated 4 months ago
- β17Updated 6 months ago
- A tool to uncover undocumented APIs from the AWS Console.β102Updated last week