oxsecurity / codetotalLinks
Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security, vulnerability, insecure infrastructure as code, and potential legal issues with open source licenses.
☆79Updated last year
Alternatives and similar repositories for codetotal
Users that are interested in codetotal are comparing it to the libraries listed below
Sorting:
- ☆114Updated 2 years ago
- FastCVE: A Dockerized CVE search tool with API and CLI support for security vulnerability queries.☆59Updated 5 months ago
- Kubernetes Pwnage for all☆56Updated 5 years ago
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆121Updated 2 years ago
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆45Updated this week
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆24Updated 4 years ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆127Updated 8 months ago
- Dependency Combobulator☆93Updated last year
- Manager of third-party sources of Semgrep rules 🗂☆90Updated last year
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆106Updated 9 months ago
- 🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends☆73Updated last year
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆140Updated 2 weeks ago
- ☆116Updated 2 years ago
- ☆60Updated 2 years ago
- Pentester-focused Docker registry tool to enumerate and pull images☆37Updated last month
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆41Updated 11 months ago
- Tools to assess DNS security.☆153Updated last year
- boostsecurityio/lotp☆137Updated 3 weeks ago
- WAF bypass PoC☆49Updated 2 years ago
- Reference architecture and proof of concept implementation for supply chain security gateway☆23Updated 2 years ago
- A curated list of argument injection vectors☆41Updated 9 months ago
- Secrets scanner that understands code☆191Updated 2 years ago
- Monorepo of Labs for the Security Knowledge Framework (SKF)☆39Updated 5 months ago
- Blogpost series showcasing interesting cloud - web app security bugs☆50Updated 2 years ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆139Updated 4 years ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆42Updated last year
- Scan DockerHub images that match a keyword to find secrets.☆60Updated 4 years ago
- A beginner-friendly CTF about Kubernetes security.☆80Updated 3 years ago
- Scan your account for the use of untrusted AMIs☆30Updated 2 months ago
- Semgrep-based Policy Controller for Kubernetes☆47Updated 7 months ago