Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules π
β101Dec 24, 2025Updated 2 months ago
Alternatives and similar repositories for semgrep-rules-manager
Users that are interested in semgrep-rules-manager are comparing it to the libraries listed below
Sorting:
- Curated Collection of Popular Community Rules for Semgrepβ18Dec 27, 2023Updated 2 years ago
- Run CodeQL queries at scale using Multi-Repository Variant Analysis (MRVA)β61Apr 16, 2025Updated 10 months ago
- Semgrep queries developed by Trail of Bits.β484Nov 12, 2025Updated 3 months ago
- Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.β1,085Updated this week
- Tricard - Malware Sandbox Fingerprintingβ23Dec 11, 2023Updated 2 years ago
- Utility to analyse, ingest and push out credentials from common data sources during an internal penetration test.β19Jun 12, 2022Updated 3 years ago
- SARIF Explorer: A VSCode extension that helps you visualize and triage static analysis resultsβ46Feb 25, 2026Updated last week
- An implementation of infrastructure-as-code scanning using dynamic tooling.β56Jan 18, 2022Updated 4 years ago
- Gram is Klarna's own threat model diagramming toolβ331Jan 26, 2026Updated last month
- HashiCorp-relevant rules for the Semgrep code analysis toolβ41Oct 3, 2023Updated 2 years ago
- Secrets scanner that understands codeβ192Nov 2, 2023Updated 2 years ago
- A blazing-fast, thread-safe, straightforward and zero memory allocations tool to swiftly generate alternative IP(v4) address representatiβ¦β92Aug 25, 2023Updated 2 years ago
- Unsafe Unpacking Vulnerability: Lab Code, Semgrep Rules and Secure Implementation Guideβ43Dec 16, 2024Updated last year
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive filesβ228Feb 25, 2026Updated last week
- A collection of my Semgrep rules to facilitate vulnerability research.β798Feb 17, 2026Updated 2 weeks ago
- A Python-based tool to create zip, tar and cpio archives to exploit common archive library issues and developer mistakesβ43Nov 28, 2025Updated 3 months ago
- Generic SAST Libraryβ135Jun 17, 2025Updated 8 months ago
- Simplify and speed up common tasks in your ORT-based FOSS review workflowsβ13Dec 19, 2025Updated 2 months ago
- Collection of self-made Red Team tools that have come in handyβ12Aug 25, 2024Updated last year
- β12Jun 22, 2022Updated 3 years ago
- For finding secrets, tokens and other common mistakes made by developers.β12Oct 21, 2025Updated 4 months ago
- A collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.β321Nov 12, 2025Updated 3 months ago
- Home of code related to security of network systems.β25Jan 22, 2025Updated last year
- Automated (kinda) deployment of MalRDP infrastructure with Terraform & Ansibleβ12Sep 15, 2023Updated 2 years ago
- A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and Cβ¦β17Feb 20, 2026Updated last week
- Watches the Downloads folder for any new files and inserts it into Nemesis for analysis.β15Feb 29, 2024Updated 2 years ago
- Collection of Semgrep rules for security analysisβ10Mar 30, 2024Updated last year
- Tool for reconnaissance of AWS cloud environmentsβ16Oct 9, 2023Updated 2 years ago
- Crashbench is a LLM benchmark to measure bug-finding and reporting capabilities of LLMsβ14Jan 20, 2026Updated last month
- Use ORT in your GitLab pipelinesβ15Nov 11, 2025Updated 3 months ago
- β12Sep 13, 2023Updated 2 years ago
- β36Apr 24, 2024Updated last year
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently β¦β315Jan 25, 2026Updated last month
- Semgrep rules corresponding to the OWASP ASVS standardβ27Nov 2, 2020Updated 5 years ago
- A fork of openssh-portable for penetration testing purposes.β11May 18, 2018Updated 7 years ago
- Finding security vulnerabilities with CodeQL in C/C++β13Mar 25, 2021Updated 4 years ago
- The ImageMagick Security Policy Evaluator allows developers and security experts to check if an XML Security Policy is hardened against aβ¦β18Feb 6, 2023Updated 3 years ago
- This repo contains the lazyFuzzer and the Report on the output from the sameβ17Oct 26, 2019Updated 6 years ago
- β11Oct 16, 2021Updated 4 years ago