baidu-security / openrasp-iastView external linksLinks
IAST 灰盒扫描工具
☆448Jul 19, 2022Updated 3 years ago
Alternatives and similar repositories for openrasp-iast
Users that are interested in openrasp-iast are comparing it to the libraries listed below
Sorting:
- Java Agent is a Java application probe of DongTai IAST, which collects method invocation data during runtime of Java application by dynam…☆696Dec 25, 2023Updated 2 years ago
- 🔥Open source RASP solution☆2,952Oct 2, 2025Updated 4 months ago
- ☆835Jun 7, 2022Updated 3 years ago
- KunLun-M是一个完全开源的静态白盒扫描工具,支持PHP、JavaScript的语义扫描,基础安全、组件安全扫描,Chrome Ext\Solidity的基础扫描。☆2,379Jan 16, 2026Updated 3 weeks ago
- Passive Security Scanner (被动式安全扫描器)☆1,946Feb 8, 2023Updated 3 years ago
- 360/0Kee-Team/crawlergo动态爬虫结合长亭XRAY扫描器的被动扫描功能☆1,183Nov 10, 2021Updated 4 years ago
- IDEA静态代码安全审计及漏洞一键修复插件☆1,047Mar 10, 2022Updated 3 years ago
- 用于辅助安全工程师漏洞挖掘、测试、复现,集合了mock、httplog、dns tools、xss,可用于测试各类无回显、无法直观判断或特定场景下的漏洞。☆868Jul 21, 2019Updated 6 years ago
- OpenRASP 漏洞测试环境☆314Oct 31, 2023Updated 2 years ago
- 在渗透测试中快速检测常见中间件、组件的高危漏洞。☆729Mar 21, 2022Updated 3 years ago
- A Java runtime information-gathering tool which uses the Java Attach API for information acquisition☆204Apr 26, 2021Updated 4 years ago
- Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…☆2,689Mar 14, 2024Updated last year
- 网页相似度判断:根据网页结构判断页面相似性 ,可用于相似度计算、越权检测等(Determine page similarity based on HTML page structure)☆284Jul 27, 2019Updated 6 years ago
- 一个利用ASM对字节码进行污点传播分析的静态代码审计应用(添加了大量代码注释,适合大家进行源码学习)。也加入了挖掘Fastjson反序列化gadget chains和SQLInject(JdbcTemplate、MyBatis、JPA、Hibernate、原生jdbc等)静…☆458Mar 24, 2022Updated 3 years ago
- Java RCE 回显测试代码☆1,015Oct 15, 2020Updated 5 years ago
- 越权检测工具☆746Jun 17, 2022Updated 3 years ago
- 红队基础设施自动化部署工具☆852Jan 4, 2023Updated 3 years ago
- JAVA安全SDK及编码规范☆1,070Oct 13, 2020Updated 5 years ago
- Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)☆1,387Dec 16, 2022Updated 3 years ago
- PHP Runtime Vulnerability Detection☆483May 25, 2019Updated 6 years ago
- Source Code Security Audit (源代码安全审计)☆3,188Sep 16, 2022Updated 3 years ago
- 绿盟科技漏洞扫描器(RSAS)漏洞库☆366May 30, 2019Updated 6 years ago
- BCS(北京网络安全大会)2019 红队行动会议重点内容☆821Sep 4, 2019Updated 6 years ago
- Dongtai IAST is an open-source Interactive Application Security Testing (IAST) tool that enables real-time detection of common vulnerabil…☆1,315May 22, 2025Updated 8 months ago
- 🚀 A simple asset discovery engine for cybersecurity. (网络资产发现引擎)☆1,345Dec 8, 2022Updated 3 years ago
- Static code auditing system☆468Jan 8, 2021Updated 5 years ago
- bayonet是一款src资产管理系统,从子域名、端口服务、漏洞、爬虫等一体化的资产管理系统☆1,508Nov 22, 2022Updated 3 years ago
- 洞察-宜信集应用系统资产管理、漏洞全生命周期管理、安全知识库管理三位一体的平台。☆1,182Jan 12, 2021Updated 5 years ago
- a simple tool to detect potential security threat in php code☆317Sep 9, 2024Updated last year
- Java web common vulnerabilities and security code which is base on springboot and spring security☆2,645Dec 2, 2024Updated last year
- A powerful browser crawler for web vulnerability scanners☆3,018Mar 11, 2025Updated 11 months ago
- A CAT called tabby ( Code Analysis Tool )☆1,634Jan 17, 2026Updated 3 weeks ago
- SRC子域名资产监控☆1,300Jan 14, 2021Updated 5 years ago
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆2,010May 21, 2024Updated last year
- Burp被动扫描流量转发插件☆1,459Jun 17, 2024Updated last year
- Burp suite 分块传输辅助插件☆2,021Feb 23, 2022Updated 3 years ago
- Redis 4.x/5.x RCE☆975Nov 30, 2021Updated 4 years ago
- java内存对象搜索辅助工具☆822Sep 23, 2022Updated 3 years ago
- ☆153Jun 24, 2019Updated 6 years ago