oxsecurity / codetotalLinks
Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security, vulnerability, insecure infrastructure as code, and potential legal issues with open source licenses.
☆79Updated last year
Alternatives and similar repositories for codetotal
Users that are interested in codetotal are comparing it to the libraries listed below
Sorting:
- FastCVE: A Dockerized CVE search tool with API and CLI support for security vulnerability queries.☆61Updated 6 months ago
- ☆114Updated 2 years ago
- A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chain☆96Updated 10 months ago
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆120Updated 2 years ago
- 🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends☆73Updated last year
- Dependency Combobulator☆94Updated last year
- Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules 🗂☆92Updated this week
- Find CVE PoCs on GitHub☆156Updated 4 months ago
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers…☆133Updated last week
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆106Updated 11 months ago
- Secrets scanner that understands code☆191Updated 2 years ago
- ☆116Updated 2 years ago
- Scan your account for the use of untrusted AMIs☆30Updated 3 weeks ago
- boostsecurityio/lotp☆138Updated 2 months ago
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆47Updated last week
- Kubernetes Pwnage for all☆56Updated 5 years ago
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆139Updated last year
- A vulnerable environment for exploring common GCP misconfigurations and vulnerabilities☆31Updated last month
- A project to visualize the software supply chain☆55Updated 2 years ago
- An extension to use Semgrep inside Burp Suite.☆89Updated 7 months ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆23Updated 4 years ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆41Updated last year
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆139Updated 4 years ago
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆140Updated last month
- WAF bypass PoC☆50Updated 2 years ago
- Blogpost series showcasing interesting cloud - web app security bugs☆50Updated 2 years ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆138Updated 10 months ago
- Monorepo of Labs for the Security Knowledge Framework (SKF)☆41Updated 6 months ago
- GCP GOAT is the vulnerable application for learn the GCP Security☆70Updated 7 months ago
- 🔍A cutting edge context aware GraphQL API fuzzing tool!☆156Updated 2 weeks ago