oxsecurity / codetotalLinks
Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security, vulnerability, insecure infrastructure as code, and potential legal issues with open source licenses.
☆79Updated last year
Alternatives and similar repositories for codetotal
Users that are interested in codetotal are comparing it to the libraries listed below
Sorting:
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆106Updated last year
- FastCVE: A Dockerized CVE search tool with API and CLI support for security vulnerability queries.☆60Updated last month
- WAF bypass PoC☆50Updated 2 years ago
- 🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends☆73Updated 2 years ago
- ☆114Updated 2 years ago
- ☆39Updated last year
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆141Updated 3 months ago
- An extension to use Semgrep inside Burp Suite.☆89Updated 8 months ago
- Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules 🗂☆97Updated last month
- Nuclei plugins to audit Chrome extensions☆65Updated last year
- This tool analyzes a given Gitlab repository and searches for dangling or force-pushed commits containing potential secret or interesting…☆47Updated last year
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆48Updated last week
- Scan your account for the use of untrusted AMIs☆31Updated 2 months ago
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆122Updated 2 years ago
- ☆17Updated 3 years ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆21Updated 10 months ago
- Kubernetes Pwnage for all☆57Updated 5 years ago
- Dependency Combobulator☆95Updated 2 years ago
- ☆116Updated 2 years ago
- Blogpost series showcasing interesting cloud - web app security bugs☆49Updated 2 years ago
- This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.☆61Updated last year
- A vulnerable environment for exploring common GCP misconfigurations and vulnerabilities☆32Updated 2 months ago
- Burp Suite extension for testing Passkey systems.☆75Updated 10 months ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆23Updated 4 years ago
- boostsecurityio/lotp☆137Updated last week
- 🔍A cutting edge context aware GraphQL API fuzzing tool!☆156Updated this week
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆42Updated 2 years ago
- Create tar/zip archives that try to exploit zipslip vulnerability.☆48Updated last year
- Pentester-focused Docker registry tool to enumerate and pull images☆36Updated 3 months ago
- Konstellation is a configuration-driven CLI tool to enumerate cloud resources and store the data into Neo4j.☆30Updated this week