wspr-ncsu / mininode
Mininode is a CLI tool to reduce the attack surface of the Node.js applications by using static analysis.
☆21Updated 2 years ago
Alternatives and similar repositories for mininode
Users that are interested in mininode are comparing it to the libraries listed below
Sorting:
- PoC: Python package static and dynamic analysis to detect environment variable stealing☆10Updated 4 years ago
- A Simple command line tool that helps checking web applications to identify insecure deserialization vulnerabilities.☆24Updated 5 years ago
- An HTTP Response fuzzer to find Vulnerabilities in Security Scanners☆26Updated 10 months ago
- Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass☆18Updated 4 years ago
- Docker container for running OWASP WebGoat.NET application☆11Updated 6 years ago
- Make exploiting race conditions in web applications highly efficient and ease-of-use.☆23Updated last year
- Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool☆25Updated 3 years ago
- OWASP ZAP add-on to detect reflected parameter vulnerabilities efficiently☆12Updated 4 years ago
- Tools for auditing WAFS☆19Updated 3 years ago
- A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service and versions.☆16Updated 3 months ago
- Reference architecture and proof of concept implementation for supply chain security gateway☆23Updated 2 years ago
- Paper, data and code from Investigating Potential Security Vulnerability Manifestation through Various Analyses & Inferences Regarding In…☆19Updated 4 years ago
- The official repository of ICSME'23 paper "Exploring Security Commits in Python"☆18Updated last year
- Pythonize Intruder Payload☆13Updated 4 years ago
- Mitigate security concerns of Dependency Confusion supply chain security risks☆46Updated 2 years ago
- ☆71Updated 3 years ago
- AI Powered Sensitive Information Detection☆18Updated last year
- An information gathering tool to collect git emails in version control host services☆11Updated 6 years ago
- Dependency Combobulator☆93Updated last year
- Extract endpoints from specific Git repository for fuzzing☆23Updated 4 years ago
- Automated compromise detection of the world's most popular packages☆15Updated last year
- Push notifications to Slack channel or to custom server based on BurpSuite response conditions.☆17Updated 4 years ago
- Docker image for reconftw, a simple script intended to perform a full recon on an objective with multiple subdomains☆10Updated 4 years ago
- A Developer and Security Engineer friendly package for Securing NodeJS Applications.☆27Updated 2 years ago
- ☆24Updated last year
- Supporting material for the "Hunting Bugs In The Tropics" DEFCON 30 talk☆9Updated 2 years ago
- Automatic tool using for crawling code to find low-hang fruit vulnerabilities - Based on OWASP Secure Code Review Guide☆20Updated 4 years ago
- Guided Differential Fuzzing for HTTP Request Parsing Discrepancies☆17Updated last year
- *Unofficial* lgtm.com CLI — Use at your own risk. Also don't add more than 3K projects to "My projects" list.☆13Updated 3 years ago
- A collection of my Semgrep rules☆49Updated last year