attesch's Stars
gitleaks/gitleaks
Find secrets with Gitleaks 🔑
facebook/infer
A static analyzer for Java, C, C++, and Objective-C
awslabs/git-secrets
Prevents you from committing secrets and credentials into git repositories
quay/clair
Vulnerability Static Analysis for Containers
tektoncd/pipeline
A cloud-native Pipeline resource.
graphql-kit/graphql-voyager
🛰️ Represent any GraphQL API as an interactive graph
EmpireProject/Empire
Empire is a PowerShell and Python post-exploitation agent.
PyCQA/bandit
Bandit is a tool designed to find common security issues in Python code.
linkedin/qark
Tool to look for several security related Android application vulnerabilities
facebookarchive/pfff
Tools for code analysis, visualizations, or style-preserving source transformation.
DominicBreuker/stego-toolkit
Collection of steganography tools - helps with CTF challenges
mozilla/http-observatory
Mozilla HTTP Observatory
crc-org/crc
CRC is a tool to help you run containers. It manages a local OpenShift 4.x cluster, Microshift or a Podman VM optimized for testing and development purposes
openstack-archive/bandit
Python AST-based static analyzer from OpenStack Security Group
secureCodeBox/secureCodeBox
secureCodeBox (SCB) - continuous secure delivery out of the box
Accenture/adop-docker-compose
Talk to us on Gitter: https://gitter.im/Accenture/ADOP
OWASP/glue
Application Security Automation
mike-goodwin/owasp-threat-dragon
An open source, online threat modelling tool from OWASP
threatspec/threatspec
threatspec - continuous threat modeling, through code
SublimeText/PowerShell
Support for the MS PowerShell programming language.
openstack-archive/syntribos
Python API security testing tool from OpenStack Security Group
abaplint/abaplint
Standalone static analysis for ABAP
aparsons/bag-of-holding
An application to assist in the organization and prioritization of software security activities.
devsecops/forecast
Forecast is a big data environment for understanding security anomalies as they are presented in a project and is meant to aid in the collection of data for the end-to-end CICD pipeline.
rohitpitkeappsec/SecAutomationFramework
Automation for security
webbreaker/webbreaker
Dynamic Application Security Test Orchestration (DASTO)
target/boots_of_haste
This script parses through an Nmap XML file and sends requests through Burp for every open port.
Xainey/xainey.github.io
Michael Willis's Blog
bushxnyc/SQRL-Server
Node implementation of SQRL
target/coldsalt
(THIS REPO HAS BEEN ARCHIVED) API test automation