semgrep / semgrep-docs
Documentation of Semgrep: a fast, open-source, static analysis tool.
β39Updated this week
Alternatives and similar repositories for semgrep-docs:
Users that are interested in semgrep-docs are comparing it to the libraries listed below
- Manager of third-party sources of Semgrep rules πβ78Updated 6 months ago
- Paper, data and code from Investigating Potential Security Vulnerability Manifestation through Various Analyses & Inferences Regarding Inβ¦β18Updated 4 years ago
- Maturity Model Collaborative projectβ14Updated last year
- A collection of my Semgrep rulesβ48Updated last year
- Proof-of-concept code for research into GitHub Actions Cache poisoning.β22Updated 2 months ago
- Reference architecture and proof of concept implementation for supply chain security gatewayβ23Updated last year
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parametersβ14Updated 3 years ago
- Burp Suite Enterprise Edition Power Toolsβ17Updated 6 months ago
- Anti-Takeover is a sub domain monitoring tool for (blue/purple) team / internal security team which uses cloud flare. Currently Anti-Takeβ¦β12Updated 4 years ago
- Salesforce Policy Deviation Checkerβ30Updated 4 years ago
- β23Updated 3 years ago
- multiple password 'asher using Pythonβs hashlibβ14Updated 3 years ago
- Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Toolβ25Updated 3 years ago
- Dependency Combobulatorβ89Updated last year
- AWS Security Checksβ36Updated 7 years ago
- π§ͺ Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.β38Updated 2 months ago
- A tool to run nmap against each line in a script.β17Updated 4 years ago
- Fork of https://github.com/PortSwigger/param-miner for header smuggling researchβ12Updated 3 years ago
- InfoSec OpenAI Examplesβ19Updated last year
- A Python-based tool to create zip, tar and cpio archives to exploit common archive library issues and developer mistakesβ42Updated last year
- A collection of Semgrep rules which followed security guidelines for .NET and Java.β17Updated 3 years ago
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)β22Updated 7 months ago
- DEbian Cve REproducer Toolβ22Updated last year
- β58Updated last year
- GCP Audit checks projects in Google Cloud for compliance with CIS Benchmarksβ21Updated 2 months ago
- insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.β50Updated 3 years ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.β40Updated last year
- Material from presentations done by GoSecure researchersβ35Updated last year
- Binary builds for dep-scan - The Dependency Scannerβ10Updated 10 months ago
- β22Updated 2 years ago