oxsecurity / codetotalLinks
Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security, vulnerability, insecure infrastructure as code, and potential legal issues with open source licenses.
β79Updated last year
Alternatives and similar repositories for codetotal
Users that are interested in codetotal are comparing it to the libraries listed below
Sorting:
- β114Updated 2 years ago
- Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules πβ98Updated last month
- π Visualize and explore IaC βοΈ Create and share notes in VS Code π€ Sync notes and findings in real-time with friendsβ73Updated 2 years ago
- Scan your account for the use of untrusted AMIsβ31Updated 2 months ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsβ106Updated last year
- FastCVE: A Dockerized CVE search tool with API and CLI support for security vulnerability queries.β60Updated last month
- β39Updated last year
- Dependency Combobulatorβ95Updated 2 years ago
- WAF bypass PoCβ50Updated 2 years ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratioβ141Updated 11 months ago
- πA cutting edge context aware GraphQL API fuzzing tool!β156Updated this week
- Documentation of Semgrep: a fast, open-source, static analysis tool.β48Updated last week
- Nuclei plugins to audit Chrome extensionsβ65Updated last year
- truffleproc β hunt secrets in process memory (TruffleHog & gdb mashup)β122Updated 2 years ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.β23Updated 4 years ago
- Create notes during a security code review in VSCode π Import your favorite SAST tool findings π οΈ and collaborate with others π€β141Updated 3 months ago
- Kubernetes Pwnage for allβ57Updated 5 years ago
- Virtual environment for learning DevSecOpsβ39Updated 8 years ago
- β17Updated 3 years ago
- A Terraform reproducer for IngressNightmareβ25Updated 10 months ago
- This tool analyzes a given Gitlab repository and searches for dangling or force-pushed commits containing potential secret or interestingβ¦β47Updated last year
- Pentester-focused Docker registry tool to enumerate and pull imagesβ36Updated 3 months ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.β42Updated 2 years ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.β21Updated 10 months ago
- Create tar/zip archives that try to exploit zipslip vulnerability.β48Updated last year
- An Evil OIDC Serverβ54Updated 3 years ago
- β60Updated 2 years ago
- Scan DockerHub images that match a keyword to find secrets.β61Updated 4 years ago
- boostsecurityio/lotpβ138Updated last week
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and versβ¦β135Updated this week