My personal collection of resources (mostly tools and training materials) for source code security audits.
☆106Aug 20, 2024Updated last year
Alternatives and similar repositories for security-code-review
Users that are interested in security-code-review are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Regex patterns for manual application source code review☆33Dec 14, 2020Updated 5 years ago
- ☆195Feb 26, 2023Updated 3 years ago
- A starter secure code review checklist☆184Nov 26, 2018Updated 7 years ago
- Training and certifications related to secure software development☆10Feb 9, 2026Updated 2 months ago
- Automatic tool using for crawling code to find low-hang fruit vulnerabilities - Based on OWASP Secure Code Review Guide☆21Aug 31, 2020Updated 5 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Find unicode codepoints to use in normalisation and transformation attacks.☆11Mar 15, 2021Updated 5 years ago
- Extract GraphQL operations from javascript☆23Mar 18, 2026Updated 3 weeks ago
- This tools used for Automating finding of subdomain, and checking for alive subdomain, and gathering js files from all the subdomain and …☆23Jun 28, 2024Updated last year
- SecureEye is an AI tool for secure code review. It assesses code for vulnerabilities, and common attack vectors☆14May 21, 2024Updated last year
- Collection of templates for linux☆10Jun 2, 2024Updated last year
- generates unique subdomain names and runs httpx on them☆18Apr 8, 2024Updated 2 years ago
- ☆40Nov 24, 2025Updated 4 months ago
- ☆12Feb 20, 2025Updated last year
- ☆12Jun 5, 2024Updated last year
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Query various sources for CVE proof-of-concepts☆53Jun 1, 2023Updated 2 years ago
- A collection of js analysis tools & scripts.☆19Mar 8, 2026Updated last month
- grep rough audit - source code auditing tool☆1,686Dec 19, 2025Updated 3 months ago
- A Productivity-Boosting Burp Suite extension written in Kotlin that enables persistent sticky session handling in web application testing…☆12Oct 8, 2025Updated 6 months ago
- My notes from courses,books ..etc☆48Nov 26, 2025Updated 4 months ago
- A list of threat sinks used in the manual security source code review for application security☆76May 9, 2023Updated 2 years ago
- A simple index for HackTheBox machine along with tags☆16Mar 26, 2026Updated 2 weeks ago
- History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094.☆10Apr 1, 2024Updated 2 years ago
- Report and finding templates used by the Serpico reporting tool☆16Sep 26, 2018Updated 7 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting with the flexibility to host WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Cloudways by DigitalOcean.
- Find endpoints in archived versions of robots.txt☆14Nov 21, 2019Updated 6 years ago
- Real Cyber Security Interview Questions for Various Job Roles☆60May 21, 2022Updated 3 years ago
- Welcome to RFS notes to CRTP - Certified Red Team Professional by Altered Security.☆22Aug 20, 2024Updated last year
- Every GitHub repo mentioning OSCP — hunted, cloned, read by AI, judged by a human. 399 clean repos.☆78Mar 5, 2026Updated last month
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆164Jul 2, 2024Updated last year
- OWASP ASVS Security Evaluation Templates with Nuclei☆42Dec 2, 2025Updated 4 months ago
- HP Data Protector Arbitrary Remote Command Execution☆11Aug 12, 2018Updated 7 years ago
- Source Code Review resources for Bug Bounty Hunters & Developers. This Repo is updated consistently.☆80Dec 30, 2021Updated 4 years ago
- Whitebox source code review cheatsheet (Based on AWAE syllabus)☆170Feb 16, 2022Updated 4 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A BurpSuite extension that allows you to use Chromium with PwnFox☆45Dec 23, 2025Updated 3 months ago
- ☆52Feb 12, 2024Updated 2 years ago
- OWASP Code Review Guide Web Repository☆149Jun 22, 2022Updated 3 years ago
- This repo contains the code for my secure code review challenges. People used this as the primary resource to pass FAANG AppSec interview…☆334Mar 12, 2026Updated last month
- You can find hardcoded Api-Key,Secret,Token Etc..☆77Sep 3, 2022Updated 3 years ago
- Reports from various areas of information security☆272Apr 13, 2024Updated last year
- Learning source code review, spot vulnerability, find some ways how to fix it.☆30Nov 17, 2022Updated 3 years ago