CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
☆9,557May 6, 2026Updated last week
Alternatives and similar repositories for codeql
Users that are interested in codeql are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Binaries for the CodeQL CLI☆975May 1, 2026Updated last week
- 《深入理解CodeQL》Finding vulnerabilities with CodeQL.☆1,770Nov 21, 2023Updated 2 years ago
- Starter workspace to use with the CodeQL extension for Visual Studio Code.☆582Updated this week
- A CAT called tabby ( Code Analysis Tool )☆1,649Jan 17, 2026Updated 3 months ago
- Codeql学习笔记☆901Apr 25, 2022Updated 4 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- The CodeQL extractor and libraries for Go.☆470Jan 5, 2023Updated 3 years ago
- Resources related to GitHub Security Lab☆1,604Dec 2, 2025Updated 5 months ago
- An extension for Visual Studio Code that adds rich language support for CodeQL☆520May 6, 2026Updated last week
- CodeQL Java 全网最全的中文学习资料☆800Mar 18, 2022Updated 4 years ago
- Share Things Related to Java - Java安全漫谈笔记相关内容☆2,013Apr 9, 2025Updated last year
- Java web common vulnerabilities and security code which is base on springboot and spring security☆2,664Dec 2, 2024Updated last year
- KunLun-M是一个完全开源的静态白盒扫描工具,支持PHP、JavaScript的语义扫描,支持使用AI Agent(OpenClaw / Codex / Claude Code / Hermes 等)一键接入工具☆2,385Updated this week
- Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.☆15,045May 7, 2026Updated last week
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆8,871Dec 4, 2025Updated 5 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A byte code analyzer for finding deserialization gadget chains in Java applications☆1,083Jun 15, 2021Updated 4 years ago
- Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.…☆3,148Updated this week
- Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…☆2,696Mar 14, 2024Updated 2 years ago
- ☆3,683Jan 9, 2025Updated last year
- Actions for running CodeQL analysis☆1,536Updated this week
- Pre-Built Vulnerable Environments Based on Docker-Compose☆20,691Updated this week
- MySQL Fake Server use to help MySQL Client File Reading and JDBC Client Java Deserialize☆1,368Nov 18, 2021Updated 4 years ago
- ☆835Jun 7, 2022Updated 3 years ago
- A helpful Java Deserialization exploit framework.☆1,242Feb 17, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list☆6,131Mar 10, 2021Updated 5 years ago
- 📦 Make security testing of K8s, Docker, and Containerd easier.☆4,651May 1, 2026Updated last week
- OSS-Fuzz - continuous fuzzing for open source software.☆12,223Updated this week
- 《Java安全-只有Java安全才能拯救宇宙》Only Java Security Can Save The Universe.☆2,882Aug 4, 2023Updated 2 years ago
- A powerful browser crawler for web vulnerability scanners☆3,033Mar 11, 2025Updated last year
- Burp suite 分块传输辅助插件☆2,032Feb 23, 2022Updated 4 years ago
- An easy-to-learn/use static analysis framework for Java☆1,782Mar 22, 2026Updated last month
- java内存对象搜索辅助工具☆822Sep 23, 2022Updated 3 years ago
- 自己学习java安全的一些总结,主要是安全审计相关☆1,702Jan 5, 2022Updated 4 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆28,299Updated this week
- KCon is a famous Hacker Con powered by Knownsec Team.☆4,668Aug 28, 2024Updated last year
- APIKit:Discovery, Scan and Audit APIs Toolkit All In One.☆2,258Apr 2, 2024Updated 2 years ago
- The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power…☆6,518Updated this week
- Fastjson姿势技巧集合☆1,842Oct 20, 2023Updated 2 years ago
- JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)☆2,803Mar 22, 2023Updated 3 years ago
- BinAbsInspector: Vulnerability Scanner for Binaries☆1,671Jun 17, 2024Updated last year