trailofbits / testing-handbookLinks
Trail of Bits Testing Handbook
โ79Updated last month
Alternatives and similar repositories for testing-handbook
Users that are interested in testing-handbook are comparing it to the libraries listed below
Sorting:
- Manager of third-party sources of Semgrep rules ๐โ87Updated last year
- ๐A cutting edge context aware GraphQL API fuzzing tool!โ148Updated 2 weeks ago
- CodeQL queries developed by Trail of Bitsโ118Updated this week
- A coverage-guided REST API fuzzer developed on top of LibAFLโ127Updated this week
- SAST + LLM Interprocedural Context Extractorโ103Updated 3 weeks ago
- Create notes during a security code review in VSCode ๐ Import your favorite SAST tool findings ๐ ๏ธ and collaborate with others ๐คโ137Updated 5 months ago
- atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.โ72Updated 2 weeks ago
- CQ, a code security scannerโ100Updated last year
- โ48Updated last year
- ๐งช Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.โ40Updated 9 months ago
- Automated vulnerability discovery and annotationโ67Updated last year
- A very simple open source implementation of Google's Project Naptimeโ169Updated 5 months ago
- SARIF Explorer: A VSCode extension that helps you visualize and triage static analysis resultsโ33Updated last month
- Resources for Browser Security Researchโ44Updated 2 years ago
- boostsecurityio/lotpโ133Updated 5 months ago
- โ79Updated last year
- Create code bookmarks and code highlights with a click.โ213Updated 2 weeks ago
- Automatically fuzz Rust projects from scratchโ57Updated 2 months ago
- The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility tโฆโ111Updated last month
- A structure-aware HTTP fuzzing libraryโ214Updated 9 months ago
- โ116Updated 2 years ago
- An experimental project exploring the use of Large Language Models (LLMs) to solve HackTheBox machines autonomously.โ61Updated last week
- A curated list of awesome browser security learning material.โ144Updated 2 years ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.โ23Updated 3 years ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsโ105Updated 7 months ago
- A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB.โ40Updated 2 years ago
- Data about all known supply-chain attacks through historyโ60Updated 3 months ago
- Search engine for CTF writeups with instant results.โ149Updated 6 months ago
- Golem automates C/C++ vulnerability discovery with SemGrep+LLVM+LLMโ91Updated 2 months ago
- Coverage-Guided Greybox Distributed Fuzzerโ131Updated 4 months ago