CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
☆9,416Apr 2, 2026Updated this week
Alternatives and similar repositories for codeql
Users that are interested in codeql are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Binaries for the CodeQL CLI☆964Mar 27, 2026Updated last week
- 《深入理解CodeQL》Finding vulnerabilities with CodeQL.☆1,763Nov 21, 2023Updated 2 years ago
- Starter workspace to use with the CodeQL extension for Visual Studio Code.☆580Mar 27, 2026Updated last week
- A CAT called tabby ( Code Analysis Tool )☆1,642Jan 17, 2026Updated 2 months ago
- Codeql学习笔记☆901Apr 25, 2022Updated 3 years ago
- Wordpress hosting with auto-scaling on Cloudways • AdFully Managed hosting built for WordPress-powered businesses that need reliable, auto-scalable hosting. Cloudways SafeUpdates now available.
- The CodeQL extractor and libraries for Go.☆470Jan 5, 2023Updated 3 years ago
- Resources related to GitHub Security Lab☆1,594Dec 2, 2025Updated 4 months ago
- An extension for Visual Studio Code that adds rich language support for CodeQL☆519Updated this week
- CodeQL Java 全网最全的中文学习资料☆798Mar 18, 2022Updated 4 years ago
- Share Things Related to Java - Java安全漫谈笔记相关内容☆1,998Apr 9, 2025Updated 11 months ago
- Java web common vulnerabilities and security code which is base on springboot and spring security☆2,663Dec 2, 2024Updated last year
- Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.☆14,652Updated this week
- KunLun-M是一个完全开源的静态白盒扫描工具,支持PHP、JavaScript的语义扫描,基础安全、组件安全扫描,Chrome Ext\Solidity的基础扫描。☆2,382Jan 16, 2026Updated 2 months ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆8,831Dec 4, 2025Updated 3 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- A byte code analyzer for finding deserialization gadget chains in Java applications☆1,081Jun 15, 2021Updated 4 years ago
- Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…☆2,695Mar 14, 2024Updated 2 years ago
- ☆3,666Jan 9, 2025Updated last year
- Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.…☆3,048Updated this week
- Actions for running CodeQL analysis☆1,514Mar 27, 2026Updated last week
- Pre-Built Vulnerable Environments Based on Docker-Compose☆20,465Mar 25, 2026Updated last week
- MySQL Fake Server use to help MySQL Client File Reading and JDBC Client Java Deserialize☆1,364Nov 18, 2021Updated 4 years ago
- ☆835Jun 7, 2022Updated 3 years ago
- A helpful Java Deserialization exploit framework.☆1,242Feb 17, 2025Updated last year
- DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list☆6,127Mar 10, 2021Updated 5 years ago
- 📦 Make security testing of K8s, Docker, and Containerd easier.☆4,597Feb 23, 2026Updated last month
- 《Java安全-只有Java安全才能拯救宇宙》Only Java Security Can Save The Universe.☆2,877Aug 4, 2023Updated 2 years ago
- OSS-Fuzz - continuous fuzzing for open source software.☆11,996Updated this week
- A powerful browser crawler for web vulnerability scanners☆3,023Mar 11, 2025Updated last year
- Burp suite 分块传输辅助插件☆2,029Feb 23, 2022Updated 4 years ago
- java内存对象搜索辅助工具☆823Sep 23, 2022Updated 3 years ago
- An easy-to-learn/use static analysis framework for Java☆1,772Mar 22, 2026Updated last week
- 自己学习java安全的一些总结,主要是安全审计相关☆1,701Jan 5, 2022Updated 4 years ago
- DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆27,689Updated this week
- KCon is a famous Hacker Con powered by Knownsec Team.☆4,669Aug 28, 2024Updated last year
- APIKit:Discovery, Scan and Audit APIs Toolkit All In One.☆2,251Apr 2, 2024Updated 2 years ago
- The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power…☆6,418Updated this week
- Fastjson姿势技巧集合☆1,835Oct 20, 2023Updated 2 years ago
- JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)☆2,799Mar 22, 2023Updated 3 years ago
- BinAbsInspector: Vulnerability Scanner for Binaries☆1,669Jun 17, 2024Updated last year