fullwaywang / QlRulesLinks
Auto-generated CodeQL rules for matching CVE vulnerabilities and variants.
☆182Updated last year
Alternatives and similar repositories for QlRules
Users that are interested in QlRules are comparing it to the libraries listed below
Sorting:
- Detecting Flow of Sensitive Data in Mini-Programs with Static Taint Analysis☆80Updated last year
- 静态分析笔记 Static-Analysis-Notes 程序分析笔记 资源分享☆186Updated 2 years ago
- A set of Code-ql/Joern queries to find vulnerabilities☆65Updated 4 years ago
- ☆64Updated 3 years ago
- Taint analysis implementation based on Heros and Soot☆45Updated last year
- 智能家居安全相关参考。The related reference of smart home security including: paper, website, topic of Mi IoT.☆78Updated 3 years ago
- ☆22Updated 3 years ago
- This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like [Cursor](https://cursor…☆119Updated 7 months ago
- 静态分析及代码审计自动化相关资料收集☆297Updated 3 years ago
- A structure-aware grey box fuzzer based on modeling the input processing logic.☆172Updated last year
- 一些阅读源码和Fuzzing 的经验,涵盖黑盒与白盒测试..☆62Updated 4 years ago
- Some test samples for CPG execution logic.☆20Updated last year
- 更好的包装pwntools,提高编写pwn题exp效率的工具☆27Updated 4 years ago
- attachments and (some) writeups/source code for RWCTF 6th☆120Updated last year
- Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities☆72Updated last year
- ☆27Updated last year
- 2021西湖论剑IoT、虚实结合赛后开放资源☆65Updated 3 years ago
- writeups for XNUCA2020Qualifier☆70Updated 4 years ago
- Writeups By Straw Hat☆55Updated last year
- 存储iot设备分析工具和分析文件☆14Updated 4 years ago
- A benchmark to evaluate taint analysis☆28Updated 3 years ago
- Artifact for ICSE 2023☆50Updated 3 years ago
- Official source code and writeups of *CTF2021☆82Updated 4 years ago
- IoT固件漏洞挖掘工具☆249Updated 3 years ago
- ☆69Updated 2 years ago
- A declarative static analysis tool for jvm bytecode based Datalog like CodeQL☆343Updated last year
- IDA Hexrays To Joern☆43Updated last year
- My PWN 练习题,异构PWN技能栈,适合IoT安全研究者。☆47Updated 3 years ago
- Debug pwn in docker, no need for virtual machines☆37Updated last month
- Corax for Java: A general static analysis framework for java code checking.☆253Updated 11 months ago