xbow-engineering / validation-benchmarks
XBOW Validation Benchmarks
☆85Updated 7 months ago
Alternatives and similar repositories for validation-benchmarks:
Users that are interested in validation-benchmarks are comparing it to the libraries listed below
- ☆189Updated 6 months ago
- Manager of third-party sources of Semgrep rules 🗂☆81Updated 9 months ago
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆46Updated last year
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆22Updated 3 years ago
- future-proof vulnerability detection benchmark, based on CVEs in open-source repos☆52Updated last week
- YuraScanner☆41Updated 2 months ago
- ☆84Updated 10 months ago
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js☆64Updated last year
- A very simple open source implementation of Google's Project Naptime☆142Updated last month
- A research project to add some brrrrrr to Burp☆158Updated 2 months ago
- CodeQL zero to hero blog post series challenges☆119Updated 4 months ago
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆105Updated 4 months ago
- ☆64Updated 3 months ago
- using ML models for red teaming☆43Updated last year
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆104Updated 3 months ago
- Grammar-based HTTP/1 fuzzer with mutation ability☆250Updated 6 months ago
- A collection of Server-Side Prototype Pollution gadgets and exploits☆185Updated 3 months ago
- An extension to use Semgrep inside Burp Suite.☆88Updated last year
- How effective are LLMs in identifying and exploiting security vulnerabilities?☆41Updated 2 months ago
- Testability Pattern Catalogs for SAST☆30Updated 2 months ago
- Awesome MXSS ??☆49Updated 7 months ago
- PP-finder Help you find gadget for prototype pollution exploitation☆158Updated 8 months ago
- A coverage-guided REST API fuzzer developed on top of LibAFL☆122Updated 2 weeks ago
- Guided Differential Fuzzing for HTTP Request Parsing Discrepancies☆17Updated last year
- ☆175Updated 6 months ago
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 2 years ago
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆44Updated last month
- 🐛 UCLA ACM Cyber's Fuzzing Lab☆84Updated 4 months ago
- Learn AI security through a series of vulnerable LLM CTF challenges. No sign ups, no cloud fees, run everything locally on your system.☆283Updated 8 months ago
- Resources for Browser Security Research☆38Updated 2 years ago