☆246Jul 20, 2026Updated this week
Alternatives and similar repositories for semgrep-rules
Users that are interested in semgrep-rules are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Semgrep queries developed by Trail of Bits.☆513May 7, 2026Updated 2 months ago
- A collection of my Semgrep rules☆54Jul 4, 2023Updated 3 years ago
- Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.☆1,207Updated this week
- Custom semgrep rules registry☆14Aug 23, 2022Updated 3 years ago
- A collection of my Semgrep rules to facilitate vulnerability research.☆844Jul 16, 2026Updated last week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- My custom semgrep rules☆24Sep 13, 2020Updated 5 years ago
- ☆14Jan 29, 2026Updated 5 months ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆23Oct 4, 2021Updated 4 years ago
- Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules 🗂☆115Dec 24, 2025Updated 7 months ago
- A collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.☆335Jun 5, 2026Updated last month
- Link sources to sinks in C# applications.☆150Apr 10, 2023Updated 3 years ago
- Collection of Semgrep rules for security analysis☆10Mar 30, 2024Updated 2 years ago
- An extension to use Semgrep inside Burp Suite.☆90May 23, 2025Updated last year
- A collection of permissively licensed Semgrep rules.☆25Jul 5, 2024Updated 2 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- ☆18Dec 20, 2025Updated 7 months ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆178Oct 26, 2024Updated last year
- HashiCorp-relevant rules for the Semgrep code analysis tool☆42Oct 3, 2023Updated 2 years ago
- RMIScout uses wordlist and bruteforce strategies to enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilities☆449Sep 7, 2022Updated 3 years ago
- Collection of community-driven CodeQL query, library and extension packs☆212Jul 16, 2026Updated last week
- Unsafe Unpacking Vulnerability: Lab Code, Semgrep Rules and Secure Implementation Guide☆45Dec 16, 2024Updated last year
- Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.☆621Mar 4, 2021Updated 5 years ago
- GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations☆412Dec 24, 2022Updated 3 years ago
- JMX enumeration and attacking tool.☆508Jun 26, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆864Updated this week
- A library for detecting known secrets across many web frameworks☆815Jul 7, 2026Updated 2 weeks ago
- grep rough audit - source code auditing tool☆1,683Dec 19, 2025Updated 7 months ago
- Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.☆1,357Updated this week
- Semgrep rules to identify GWT attack surface☆12Apr 28, 2022Updated 4 years ago
- Companion labs to "An Exploration of JSON Interoperability Vulnerabilities"☆210Mar 9, 2023Updated 3 years ago
- The cheat sheet about Java Deserialization vulnerabilities☆3,180May 26, 2023Updated 3 years ago
- For unpacking base64:ed "Save items"-content from Burp (From search + proxy history)☆55Feb 26, 2025Updated last year
- Deliberately vulnerable AWS resources for security assessment demos☆32Aug 20, 2022Updated 3 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Automating situational awareness for cloud penetration tests.☆2,536May 26, 2026Updated last month
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆271Mar 30, 2026Updated 3 months ago
- Burp extension to log requests and responses to PostgreSQL☆16Jun 30, 2025Updated last year
- Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.☆278Sep 20, 2024Updated last year
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆280Sep 11, 2025Updated 10 months ago
- Autogrep automates Semgrep rule generation and filtering by using LLMs to analyze vulnerability patches, enabling automatic creation of h…☆87Feb 27, 2025Updated last year
- Provides an overview of the inner file structure of a PDF☆24Sep 26, 2022Updated 3 years ago