X-SAST 替代Seay的多语言、轻量、快速、代码审计工具 (Python版本)
☆122Feb 10, 2026Updated 5 months ago
Alternatives and similar repositories for XSAST-Python
Users that are interested in XSAST-Python are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- 基于Java开发的代码字符串搜索工具,用于辅助快速代码审计,筛选危险方法名称搜索代码中可能存在的漏洞☆39Mar 7, 2026Updated 4 months ago
- JavaGadgetGenerator 工具,支持 ysoserial,Hessian,字节码,Expr/SSTI,Shiro,JDBC 等 Gadget 生成,封装,混淆,出网延迟探测,内存马注入等...☆573Apr 3, 2026Updated 3 months ago
- 闭源系统半自动漏洞挖掘工具,针对 jar/war/zip 进 行静态代码分析,输出从source到sink的可达路径。LLM将验证路径可达性,并根据上下文给出该路径可信分数☆511Jan 12, 2026Updated 6 months ago
- GodInfo 是一个功能全面的后渗透信息和凭据收集工具,旨在帮助安全测试人员在获得授权访问权限后,快速收集目标系统的信息和凭据。☆257Apr 29, 2025Updated last year
- 让fscan再次伟大☆362Jun 18, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- 一个用于测试文件上传功能安全性的 Burp Suite 插件。通过 Intruder 模块自动生成各类绕过 payload,覆盖常见的文件上传限制场景。共1000+条payload☆621Dec 24, 2025Updated 7 months ago
- 综合后渗透方面的杂烩☆600Mar 1, 2026Updated 4 months ago
- 从流量包匹配敏感信息的工具-可用作bp、浏览器的下游代理。0感知、无卡顿,支持https。☆297May 1, 2026Updated 2 months ago
- 针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT …☆290Aug 12, 2025Updated 11 months ago
- "chanzi" is a simple and user-friendly JAVA SAST tool that utilizes taint analysis technology, includes built-in common vulnerability ru…☆490Feb 1, 2026Updated 5 months ago
- 一款基于Zjackky/CodeScan的轻量级匹配Sink点并AI审计的代码审计扫描器☆253Feb 13, 2025Updated last year
- Burpsuite - Js Route Scan 正则匹配获取响应中的路由进行被动探测与递归目录探测的burp插件☆375Jun 7, 2024Updated 2 years ago
- xxl-job漏洞综合利用工具☆161Jun 3, 2025Updated last year
- 基于Python javalang库开发的一款轻量级Java源代码审计工具,by Tr0e☆75Oct 23, 2025Updated 9 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- 互联网资产综合扫描/攻击面测绘☆609Updated this week
- 此Suricata IDS Rules 用于检测网络攻击行为,支持常见C2工具/中间件漏洞利用/Frp隧道/HTTP隧道/TCP隧道/常见webshell/redis未授权/Shiro反序列化/Fastjson反序列化/挖矿/SQL注入等特征☆27Sep 5, 2025Updated 10 months ago
- 这是一款图形化的代码审计工具,支持对规则进行增删改查。可协助代码审计人员在日常代审中对于规则的积累。其中配置页面可配置:审计文件后缀、审计路径关键字、禁止审计路径关键字。支持 java php net项目审计。☆125Jan 16, 2025Updated last year
- The first Computer Emergency Response (ARK) Tools for young people ;) 年轻人的第一款应急响应(ARK)工具 ;)☆682Oct 21, 2025Updated 9 months ago
- 用友NC漏洞批量检测工具,支持POC显示、单一检测、批量检测、结果导出、AI交互等☆46Sep 8, 2025Updated 10 months ago
- 最好用最智能最可控的目录Fuzz工具 | The most powerful, user-friendly, intelligent, and precise HTTP Fuzzer.☆1,054Jul 19, 2026Updated last week
- ☆65Oct 24, 2025Updated 9 months ago
- burpsuit插件,解析swagger/openapi接口文档并进行请求,模拟参数方便渗透测试人员快速发现可用接口 (最新使用源码编译,release有时候没空搞)☆46Oct 23, 2025Updated 9 months ago
- TL-NodeJsShell 是一个为安全专业人员和渗透测试人员设计的综合性 WebShell 管理平台。它提供了一个现代化的 Web 界面,用于管理基于 Node.js 的 Shell,具有内存马注入、命令执行、文件管理和代理支持等高级功能。☆88Dec 12, 2025Updated 7 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- 一个半自动化springboot打点工具,内置目前springboot所有漏洞☆788Sep 30, 2025Updated 10 months ago
- Rshell是一款开源的golang编写的支持多平台的C2框架,旨在帮助安服人员渗透测试、红蓝对抗。☆533Jul 7, 2026Updated 3 weeks ago
- 最强大的密码爆破/喷洒工具 | The most powerful bruteforcer / sprayer Artifact☆373Jul 19, 2026Updated last week
- 一款轻量级匹配Sink点的代码审计扫描器,为了帮助红队过程中快速代码审计的小工具☆402Oct 6, 2024Updated last year
- 一款强大的 burp 安全测试插件,集成多种安全测试功能,支持自动化扫描和手动测试。☆677Mar 20, 2026Updated 4 months ago
- Privacy Check Go☆25Feb 11, 2026Updated 5 months ago
- 🔍 CodeAuditAssistant - JetBrains Code Audit Plugin (Beta) ⚡ Deep Call-Chain Tracking | 🚀 Method/Class Search | 🔥 Prebuilt Vuln Sink…☆784Mar 14, 2026Updated 4 months ago
- 辅助甲方安全人员巡检网站资产,发现并分析API安全问题☆533Jan 20, 2025Updated last year
- jeecg综合漏洞利用工具☆455Aug 30, 2024Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- 基于W01fh4cker大佬的LearnJavaMemshellFromZero从零掌握java内存马的复现重组版本。☆94Jun 15, 2026Updated last month
- java-web 自动化鉴权绕过☆380Apr 3, 2025Updated last year
- Pillager是一个适用于后渗透期间的信息收集工具☆1,289Sep 7, 2024Updated last year
- Linux权限维持☆1,114Jun 10, 2026Updated last month
- Burp插件,快速探测可能存在SQL注入的请求并标记,提高测试效率☆821Feb 26, 2026Updated 5 months ago
- SwordfishSuite - Web安全测试利器 一款轻量、高速、插件化的现代Web安全测试工具,专为安全研究员和渗透测试者打造。 ✨ 核心特性: 智能代理:无缝拦截与修改HTTP/S请求,流畅度超越BurpSuite。 高度集成:集成云端虚拟手机,快速定位AP…☆75Apr 10, 2026Updated 3 months ago
- 快速测试是否存在FastAdmin框架相关漏洞☆26Oct 14, 2024Updated last year