usnistgov / ai-bugfinder-testbedLinks
A static analyzer powered by AI
☆21Updated 10 months ago
Alternatives and similar repositories for ai-bugfinder-testbed
Users that are interested in ai-bugfinder-testbed are comparing it to the libraries listed below
Sorting:
- atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.☆65Updated this week
- Code Hierarchy Exploration Net (chen)☆21Updated this week
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and o…☆75Updated last month
- ☆26Updated last year
- Monthly CVE Stats☆42Updated last month
- VFCFinder: Searching for the Missing Vulnerability Fixing Commits☆29Updated last year
- A collection of prompt injection mitigation techniques.☆23Updated last year
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆39Updated 5 months ago
- Analysis of the Enterprise SAST/DAST product landscape☆37Updated last year
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆144Updated last year
- Statically Detecting Vulnerable Data Flows in Browser Extensions at Scale☆74Updated 3 years ago
- Automated vulnerability discovery and annotation☆67Updated 10 months ago
- A collection of permissively licensed Semgrep rules.☆11Updated 11 months ago
- VulZoo: A Comprehensive Vulnerability Intelligence Dataset (ASE 2024 Demo)☆48Updated 2 months ago
- ☆28Updated 2 weeks ago
- The Cloud Property Graph is based on a Code Property Graph and tries to connect static code analysis and Cloud runtime assessment.☆25Updated 4 months ago
- Extensible framework for analyzing publicly available information about vulnerabilities☆115Updated 3 weeks ago
- Manager of third-party sources of Semgrep rules 🗂☆86Updated 10 months ago
- A very simple open source implementation of Google's Project Naptime☆150Updated 2 months ago
- SecretBench is a dataset consisting of different secret types collected from public open-source repositories.☆32Updated 11 months ago
- Home page of project "KB"☆126Updated 2 months ago
- 🪐 A Database of Existing Security Vulnerabilities Patches to Enable Evaluation of Techniques (single-commit; multi-language)☆40Updated last month
- A command line tool for extracting machine learning ready data from software binaries powered by Radare2☆70Updated last month
- OWASP Benchmark Project Utilities - Provides scorecard generation and crawling tools for Benchmark style test suites.☆18Updated this week
- AutoVAS is an automated vulnerability analysis system with a deep learning approach.☆35Updated 3 years ago
- ChainReactor is a research project that leverages AI planning to discover exploitation chains for privilege escalation on Unix systems. T…☆47Updated 7 months ago
- ☆44Updated 10 months ago
- A library to produce cybersecurity exploitation routes (exploit flows). Inspired by TensorFlow.☆35Updated last year
- Tool to guess CPE name based on common software name☆96Updated 6 months ago
- A project to visualize the software supply chain☆52Updated last year