All Projects → Semgrep Rules → Similar Projects or Alternatives

521 Open source projects that are alternatives of or similar to Semgrep Rules

Nodejsscan
nodejsscan is a static security code scanner for Node.js applications.
Stars: ✭ 1,874 (+1238.57%)
Ikos
Static analyzer for C/C++ based on the theory of Abstract Interpretation.
Stars: ✭ 1,368 (+877.14%)
Codeql Go
The CodeQL extractor and libraries for Go.
Stars: ✭ 224 (+60%)
Dg
[LLVM Static Slicer] Various program analyses, construction of dependence graphs and program slicing of LLVM bitcode.
Stars: ✭ 242 (+72.86%)
progge.rs
Program analysis playground for a simple, imperative language
Stars: ✭ 29 (-79.29%)
Salus
Security scanner coordinator
Stars: ✭ 441 (+215%)
Detect It Easy
Program for determining types of files for Windows, Linux and MacOS.
Stars: ✭ 2,982 (+2030%)
Bap
Binary Analysis Platform
Stars: ✭ 1,385 (+889.29%)
Vulny Code Static Analysis
Python script to detect vulnerabilities inside PHP source code using static analysis, based on regex
Stars: ✭ 207 (+47.86%)
tiro
TIRO - A hybrid iterative deobfuscation framework for Android applications
Stars: ✭ 20 (-85.71%)
Cwe checker
cwe_checker finds vulnerable patterns in binary executables
Stars: ✭ 372 (+165.71%)
Phasar
A LLVM-based static analysis framework.
Stars: ✭ 503 (+259.29%)
Pyre Check
Performant type-checking for python.
Stars: ✭ 5,716 (+3982.86%)
clam
Static Analyzer for LLVM bitcode based on Abstract Interpretation
Stars: ✭ 180 (+28.57%)
Wala
T.J. Watson Libraries for Analysis
Stars: ✭ 395 (+182.14%)
Linter
Static Analysis Compiler Plugin for Scala
Stars: ✭ 273 (+95%)
Seahorn
SeaHorn Verification Framework
Stars: ✭ 270 (+92.86%)
Crab
CoRnucopia of ABstractions: a library for building abstract interpretation-based analyses
Stars: ✭ 102 (-27.14%)
Applicationinspector
A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.
Stars: ✭ 3,873 (+2666.43%)
Crab Llvm
Static Analyzer for LLVM bitcode based on Abstract Interpretation
Stars: ✭ 143 (+2.14%)
Pyt
A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications
Stars: ✭ 2,061 (+1372.14%)
iec-checker
Static analysis of IEC 61131-3 programs
Stars: ✭ 36 (-74.29%)
Insider
Static Application Security Testing (SAST) engine focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code, focused on a agile and easy to implement software inside your DevOps pipeline. Support the following technologies: Java (Maven and Android), Kotlin (Android), Swift (iOS), .NET Full Framework, C#, and Javascript (Node.js).
Stars: ✭ 216 (+54.29%)
Krane
Kubernetes RBAC static Analysis & visualisation tool
Stars: ✭ 254 (+81.43%)
Jsprime
a javascript static security analysis tool
Stars: ✭ 556 (+297.14%)
Pest
🐞 Primitive Erlang Security Tool
Stars: ✭ 79 (-43.57%)
Vuln Web Apps
A curated list of vulnerable web applications.
Stars: ✭ 128 (-8.57%)
Mutual labels:  security-scanner
Minions
Distributed filesystem scanner
Stars: ✭ 115 (-17.86%)
Mutual labels:  security-scanner
Java Disassembler
The Java Disassembler
Stars: ✭ 114 (-18.57%)
Mutual labels:  static-analysis
Abaplint
Standalone linter for ABAP
Stars: ✭ 111 (-20.71%)
Mutual labels:  static-analysis
Just Another Android App
An Android base app with loads of cool libraries/configuration NOT MAINTAINED
Stars: ✭ 1,654 (+1081.43%)
Mutual labels:  static-analysis
Njsscan
njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.
Stars: ✭ 128 (-8.57%)
Mutual labels:  static-analysis
Haxe Checkstyle
Haxe Checkstyle
Stars: ✭ 110 (-21.43%)
Mutual labels:  static-analysis
Stingray
IDAPython plugin for finding function strings recursively
Stars: ✭ 110 (-21.43%)
Mutual labels:  static-analysis
Find Sec Bugs
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
Stars: ✭ 1,748 (+1148.57%)
Mutual labels:  static-analysis
Analyzer
🔍 Offline Analyzer for extracting features, artifacts and IoCs from Windows, Linux, Android, iPhone, Blackberry, macOS binaries, emails and more
Stars: ✭ 108 (-22.86%)
Mutual labels:  static-analysis
Dependency Cruiser
Validate and visualize dependencies. Your rules. JavaScript, TypeScript, CoffeeScript. ES6, CommonJS, AMD.
Stars: ✭ 2,326 (+1561.43%)
Mutual labels:  static-analysis
Btscan
批量漏洞扫描框架
Stars: ✭ 108 (-22.86%)
Mutual labels:  security-scanner
Mythril
Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Hedera, Quorum, Vechain, Roostock, Tron and other EVM-compatible blockchains.
Stars: ✭ 1,968 (+1305.71%)
Mutual labels:  program-analysis
Phpstan
PHP Static Analysis Tool - discover bugs in your code without running it!
Stars: ✭ 10,534 (+7424.29%)
Mutual labels:  static-analysis
Vscan Go
golang version for nmap service and application version detection (without nmap installation)
Stars: ✭ 107 (-23.57%)
Mutual labels:  security-scanner
Mba
Malware Behavior Analyzer
Stars: ✭ 125 (-10.71%)
Mutual labels:  program-analysis
Patrowldocs
PatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform
Stars: ✭ 105 (-25%)
Mutual labels:  security-scanner
Gopherci
GopherCI was a project to help you maintain high-quality Go projects, by checking each GitHub Pull Request, for backward incompatible changes, and a suite of other third party static analysis tools.
Stars: ✭ 105 (-25%)
Mutual labels:  static-analysis
Wpscan V3
THIS REPOSITORY HAS BEEN MOVED TO https://github.com/wpscanteam/wpscan USE THAT!!!
Stars: ✭ 132 (-5.71%)
Mutual labels:  security-scanner
Malwarelab vm Setup
Setup scripts for my Malware Analysis VMs
Stars: ✭ 126 (-10%)
Mutual labels:  static-analysis
Sast Scan
Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure DevOps, Google CloudBuild, VS Code and Visual Studio. No server required!
Stars: ✭ 104 (-25.71%)
Mutual labels:  static-analysis
Zpa
A parser and source code analyzer for PL/SQL and Oracle SQL.
Stars: ✭ 124 (-11.43%)
Mutual labels:  static-analysis
Awesome Machine Learning Deep Learning Mathematics
A curated list of mathematics documents ,Concepts, Study Materials , Algorithms and Codes available across the internet for machine learning and deep learning
Stars: ✭ 138 (-1.43%)
Mutual labels:  static-analysis
Php testability
Analyses and reports testability issues of a php codebase
Stars: ✭ 136 (-2.86%)
Mutual labels:  static-analysis
Mazewalker
Toolkit for enriching and speeding up static malware analysis
Stars: ✭ 132 (-5.71%)
Mutual labels:  static-analysis
Pbscan
Faster and more efficient stateless SYN scanner and banner grabber due to userland TCP/IP stack usage.
Stars: ✭ 122 (-12.86%)
Mutual labels:  security-scanner
Panopticon
A libre cross-platform disassembler.
Stars: ✭ 1,376 (+882.86%)
Mutual labels:  static-analysis
Awesome Golang Security
Awesome Golang Security resources 🕶🔐
Stars: ✭ 1,355 (+867.86%)
Mutual labels:  static-analysis
Reading
A list of computer-science readings I recommend
Stars: ✭ 1,919 (+1270.71%)
Mutual labels:  static-analysis
Squealer
Telling tales on you for leaking secrets!
Stars: ✭ 97 (-30.71%)
Mutual labels:  static-analysis
Pakala
Offensive vulnerability scanner for ethereum, and symbolic execution tool for the Ethereum Virtual Machine
Stars: ✭ 97 (-30.71%)
Mutual labels:  security-scanner
Gsil
GitHub Sensitive Information Leakage(GitHub敏感信息泄露监控)
Stars: ✭ 1,764 (+1160%)
Mutual labels:  security-scanner
Nosqli
NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.
Stars: ✭ 120 (-14.29%)
Mutual labels:  security-scanner
Phpstan Drupal
Extension for PHPStan to allow analysis of Drupal code.
Stars: ✭ 97 (-30.71%)
Mutual labels:  static-analysis
1-60 of 521 similar projects