trailofbits / testing-handbookLinks
Trail of Bits Testing Handbook - appsec.guide
☆92Updated 2 weeks ago
Alternatives and similar repositories for testing-handbook
Users that are interested in testing-handbook are comparing it to the libraries listed below
Sorting:
- SAST + LLM Interprocedural Context Extractor☆176Updated 3 months ago
- CodeQL queries developed by Trail of Bits☆144Updated 3 weeks ago
- Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules 🗂☆98Updated last month
- Create code bookmarks and code highlights with a click.☆228Updated this week
- ☆52Updated last year
- SARIF Explorer: A VSCode extension that helps you visualize and triage static analysis results☆44Updated last month
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆141Updated 3 months ago
- 🔍A cutting edge context aware GraphQL API fuzzing tool!☆156Updated this week
- Automatically fuzz Rust projects from scratch☆59Updated 7 months ago
- Automatic Exploit Generation with LLMs☆499Updated last week
- Resources for Browser Security Research☆53Updated 3 years ago
- A coverage-guided REST API fuzzer developed on top of LibAFL☆162Updated this week
- Semgrep queries developed by Trail of Bits.☆471Updated 2 months ago
- CQ, a code security scanner☆99Updated last year
- Scripts and examples for "From Day Zero to Zero Day" by Eugene Lim.☆211Updated 2 months ago
- ☆131Updated 5 months ago
- Data about all known supply-chain attacks through history☆63Updated 8 months ago
- The resources for glibc Malloc heap exploitation course by Maxwell Dulin and Security Innovation.☆171Updated last year
- A curated list of awesome browser security learning material.☆148Updated 3 years ago
- ☆156Updated 5 months ago
- Golem automates C/C++ vulnerability discovery with SemGrep+LLVM+LLM☆98Updated 7 months ago
- 🐛 UCLA ACM Cyber's Fuzzing Lab☆89Updated 2 months ago
- A web CTF for training developers in bug hunting and secure coding!☆100Updated last year
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆23Updated 4 years ago
- How GitHub Actions workflows can be hacked☆176Updated last year
- A very simple open source implementation of Google's Project Naptime☆184Updated 10 months ago
- atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.☆84Updated last week
- ☆79Updated last year
- A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, C…☆197Updated this week
- ☆116Updated 2 years ago