CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
☆9,635May 29, 2026Updated this week
Alternatives and similar repositories for codeql
Users that are interested in codeql are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Binaries for the CodeQL CLI☆979May 22, 2026Updated last week
- 《深入理解CodeQL》Finding vulnerabilities with CodeQL.☆1,771Nov 21, 2023Updated 2 years ago
- Starter workspace to use with the CodeQL extension for Visual Studio Code.☆585May 22, 2026Updated last week
- A CAT called tabby ( Code Analysis Tool )☆1,651Jan 17, 2026Updated 4 months ago
- Codeql学习笔记☆899Apr 25, 2022Updated 4 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- The CodeQL extractor and libraries for Go.☆471Jan 5, 2023Updated 3 years ago
- Resources related to GitHub Security Lab☆1,607Updated this week
- An extension for Visual Studio Code that adds rich language support for CodeQL☆524Updated this week
- CodeQL Java 全网最全的中文学习资料☆799Mar 18, 2022Updated 4 years ago
- Share Things Related to Java - Java安全漫谈笔记相关内容☆2,015Apr 9, 2025Updated last year
- Java web common vulnerabilities and security code which is base on springboot and spring security☆2,666Dec 2, 2024Updated last year
- KunLun-M — Open-source static code analysis for PHP, Nodejs/JavaScript, Python, Golang, Java, with AST-based semantic scanning and one-cl…☆2,387Updated this week
- Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.☆15,324Updated this week
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆8,897Dec 4, 2025Updated 5 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A byte code analyzer for finding deserialization gadget chains in Java applications☆1,083Jun 15, 2021Updated 4 years ago
- Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.…☆3,212Updated this week
- Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…☆2,694Mar 14, 2024Updated 2 years ago
- ☆3,684Jan 9, 2025Updated last year
- Pre-Built Vulnerable Environments Based on Docker-Compose☆20,759May 12, 2026Updated 3 weeks ago
- Actions for running CodeQL analysis☆1,553Updated this week
- MySQL Fake Server use to help MySQL Client File Reading and JDBC Client Java Deserialize☆1,370Nov 18, 2021Updated 4 years ago
- ☆836Jun 7, 2022Updated 3 years ago
- A helpful Java Deserialization exploit framework.☆1,241Feb 17, 2025Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list☆6,131Mar 10, 2021Updated 5 years ago
- 📦 Make security testing of K8s, Docker, and Containerd easier.☆4,666May 1, 2026Updated last month
- OSS-Fuzz - continuous fuzzing for open source software.☆12,304Updated this week
- 《Java安全-只有Java安全才能拯救宇宙》Only Java Security Can Save The Universe.☆2,881Aug 4, 2023Updated 2 years ago
- A powerful browser crawler for web vulnerability scanners☆3,033Mar 11, 2025Updated last year
- Burp suite 分块传输辅助插件☆2,033Feb 23, 2022Updated 4 years ago
- An easy-to-learn/use static analysis framework for Java☆1,779Mar 22, 2026Updated 2 months ago
- java内存对象搜索辅助工具☆821Sep 23, 2022Updated 3 years ago
- 自己学习java安全的一些总结,主要是安全审计相关☆1,705Jan 5, 2022Updated 4 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆28,877May 25, 2026Updated last week
- KCon is a famous Hacker Con powered by Knownsec Team.☆4,662Aug 28, 2024Updated last year
- APIKit:Discovery, Scan and Audit APIs Toolkit All In One.☆2,263Apr 2, 2024Updated 2 years ago
- The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power…☆6,543Updated this week
- Fastjson姿势技巧集合☆1,848Oct 20, 2023Updated 2 years ago
- JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)☆2,807Mar 22, 2023Updated 3 years ago
- BinAbsInspector: Vulnerability Scanner for Binaries☆1,669Jun 17, 2024Updated last year