testable-eu / sast-tp-frameworkLinks
TP-Framework: Testability Pattern Framework for SAST
☆15Updated last year
Alternatives and similar repositories for sast-tp-framework
Users that are interested in sast-tp-framework are comparing it to the libraries listed below
Sorting:
- Testability Pattern Catalogs for SAST☆30Updated 3 months ago
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆49Updated last year
- An extension to use Semgrep inside Burp Suite.☆89Updated 2 weeks ago
- Manager of third-party sources of Semgrep rules 🗂☆86Updated 10 months ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆23Updated 3 years ago
- YuraScanner☆42Updated 3 months ago
- Run CodeQL queries at scale using Multi-Repository Variant Analysis (MRVA)☆59Updated last month
- Bundle of security analysis scripts for keras tensorflow models☆14Updated last year
- jws2pubkey tool☆38Updated 11 months ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆105Updated 4 months ago
- AutoSpear☆61Updated last year
- Guided Differential Fuzzing for HTTP Request Parsing Discrepancies☆17Updated last year
- Testability Tarpits: the Impact of Code Patterns on the Security Testing of Web Applications (NDSS 2022)☆25Updated last year
- Grammar-based HTTP/2 fuzzer with mutation ability☆45Updated 2 years ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆39Updated 5 months ago
- ☆194Updated 7 months ago
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js☆65Updated last year
- A proof-of-concept tool for detection and exploitation Object Injection Vulnerabilities in .NET applications☆63Updated 4 years ago
- A collection of my Semgrep rules☆49Updated last year
- Intentionally vulnerable Go web app.☆43Updated 2 weeks ago
- ☆77Updated 3 weeks ago
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆144Updated last year
- Static Token And Credential Scanner☆96Updated 2 years ago
- Proof of Concepts for unsafe deserialization in Ruby☆16Updated 7 months ago
- Unsafe Unpacking Vulnerability: Lab Code, Semgrep Rules and Secure Implementation Guide☆41Updated 5 months ago
- A curated list of argument injection vectors☆41Updated 4 months ago
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆50Updated last month
- An HTTP Response fuzzer to find Vulnerabilities in Security Scanners☆26Updated 11 months ago
- My custom semgrep rules☆21Updated 4 years ago
- A tool that checks if a TorchServe instance is vulnerable to CVE-2023-43654☆39Updated last year