jtmelton / semgrep-idea-plugin
☆17Updated last year
Related projects ⓘ
Alternatives and complementary repositories for semgrep-idea-plugin
- Some helpful Helm Charts for pentesters☆38Updated 5 years ago
- INTERCEPT / Policy as Code Auditing & Compliance☆82Updated last month
- Externalize Java application access to protected resources as log messages.☆41Updated 6 months ago
- Crawljax: Crawling JavaScript-based Ajax Web Applications☆21Updated 11 months ago
- My custom semgrep rules☆18Updated 4 years ago
- CVE-2020-10749 PoC (Kubernetes MitM attacks via IPv6 rogue router advertisements)☆25Updated 4 years ago
- Vulnerability Scanner for Detecting Publicly Disclosed Vulnerabilities in Application Dependencies☆23Updated 5 years ago
- A zero-dependency tool for finding secrets in directories☆10Updated 3 years ago
- Rules for Bearer SAST☆24Updated last week
- Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass☆18Updated 3 years ago
- Static Token And Credential Scanner☆95Updated last year
- Vulnerability consolidation and management tool, enhances scan results by merging different findings of the same weakness across multiple…☆24Updated last year
- General Open Architecture Security Questionnaire☆31Updated last year
- A gitbook for doing a null Bangalore session on linux container security to discuss and teach namespaces, cgroups etc.☆20Updated 7 years ago
- Run CodeQL queries at scale using Multi-Repository Variant Analysis (MRVA)☆49Updated 7 months ago
- The Web Audit Search Engine - Index and Search HTTP Requests and Responses in Web Application Audits with ElasticSearch☆23Updated 6 years ago
- Fork of https://github.com/PortSwigger/param-miner for header smuggling research☆12Updated 3 years ago
- Provides a suite of Burp extensions and a maven plugin to automate security tests using BurpSuite.☆25Updated 6 years ago
- Swiftly search FDNS datasets from Rapid7 Open Data☆21Updated 2 years ago
- Writeup of CVE-2017-1002101 with sample "exploit"/escape☆35Updated 6 years ago
- Monitoring GitHub for sensitive data shared publicly☆66Updated 2 years ago
- Dependency Combobulator☆89Updated 10 months ago
- Security scanning & static analysis tool☆93Updated last month
- Proof of Concept exploit for Kubernetes CVE-2020-8559☆20Updated 4 years ago
- Proof-of-concept CORS exploitation tool.☆34Updated 5 years ago
- A wrapper around jq, to help you parse jq output!☆30Updated 4 years ago
- A docker example for privilege escalation☆25Updated 7 years ago
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)☆22Updated 4 months ago
- insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.☆49Updated 2 years ago
- Generate CodeQL taint-tracking models for Go (along with tests) in a graphical UI☆20Updated last year