Pinned Repositories
2ms
Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git
ast-cli
A CLI project wrapping application security testing (AST) APIs
capital
A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Security vulnerabilities within your own API Security CTF.
chainalert-github-action
scans popular packages and alerts in cases there is suspicion of an account takeover
chainjacking
Find which of your direct GitHub dependencies is susceptible to RepoJacking attacks
ci-cd-integrations
If you are using a CI/CD platform that doesn’t yet have a dedicated Checkmarx plugin, please check this repository.
dustilock
DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.
JS-SCP
JavaScript Secure Coding Practices guide
kics
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
kics-github-action
GitHub actions of KICS scan - Keeping Infrastructure as Code Secure
Checkmarx's Repositories
Checkmarx/kics
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Checkmarx/capital
A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Security vulnerabilities within your own API Security CTF.
Checkmarx/2ms
Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git
Checkmarx/kics-github-action
GitHub actions of KICS scan - Keeping Infrastructure as Code Secure
Checkmarx/ast-cli
A CLI project wrapping application security testing (AST) APIs
Checkmarx/Goatlin
(aka Kotlin Goat) - an intentionally vulnerable Kotlin application
Checkmarx/cuteboi
This open-source project tracks CuteBoi's activity over time as there are evidence the actor is still active. All information provided here is intended for research purposes.
Checkmarx/ast-github-action
Checkmarx application security testing (AST) GitHub action
Checkmarx/ast-vscode-extension
The Checkmarx One Visual Studio Code plugin (extension) enables you to import results from a Checkmarx One scan directly into your VS Code console. You can view the vulnerabilities that were identified in your source code and navigate directly to the vulnerable code in the editor.
Checkmarx/red-lili
This open-source project tracks RED-LILI's activity over time as there are evidence the actor is still active. All information provided here is intended for research purposes.
Checkmarx/ci-cd-integrations
If you are using a CI/CD platform that doesn’t yet have a dedicated Checkmarx plugin, please check this repository.
Checkmarx/kics-cdk-validator-plugin
A KICS plugin for AWS CDK
Checkmarx/ast-azure-plugin
The CxAST Azure DevOps plugin enables you to trigger SAST, SCA, and KICS scans directly from an Azure DevOps pipeline.
Checkmarx/ast-eclipse-plugin
The CxAST Eclipse plugin enables you to import results from a CxAST scan directly into your IDE. You can view the vulnerabilities that were identified in your source code and navigate directly to the vulnerable code in the editor.
Checkmarx/ast-jetbrains-plugin
The CxAST JetBrains plugin enables you to import results from a CxAST scan directly into your IDE.
Checkmarx/ast-teamcity-plugin
The CxAST TeamCity plugin enables you to trigger SAST, SCA, and KICS scans directly from a TeamCity project.
Checkmarx/sast-to-ast-export
CLI tool to export data from CxSAST and import into Checkmarx Application Security Testing Platform
Checkmarx/vorpal-reviewdog-github-action
Run Vorpal with reviewdog 🐶
Checkmarx/ast-visual-studio-extension
The CxAST Visual Studio plugin enables you to import results from a CxAST scan directly into your IDE
Checkmarx/dast-github-action
Checkmarx/homebrew-ast-cli
Checkmarx/nexus-security-plugin
Checkmarx/gen-ai-prompts
Remediate SAST results using AI
Checkmarx/overlay
Overlay is a browser extension helping developers evaluate open source packages before picking them
Checkmarx/artifactory-security-plugin
Checkmarx/kics-github-action-demo
A demo repo to show KICS Github Action in Action
Checkmarx/terraform-aws-cxone
Checkmarx/ast-cli-maven-plugin
A Maven plugin for using the AST CLI in Maven lifecycle phases
Checkmarx/gen-ai-wrapper
Checkmarx/gitleaks
Protect and discover secrets using Gitleaks 🔑