4. Security & Compliance

24 skills

Found 3608 skills

Total Stars:1.6M
Avg Stars:450

fuzzing-obstacles

trailofbits

1.7K

Provides code patching techniques to overcome checksums, global state, and other obstacles in security fuzzing tests.

Fuzzing
Checksum
Global State
4. Security & Compliance

burpsuite-project-parser

trailofbits

1.7K

Command-line utility for parsing Burp Suite project files to search HTTP traffic, headers, and security audit data using regex patterns.

Burp Suite
regex
HTTP
4. Security & Compliance

ruzzy

trailofbits

1.7K

Coverage-guided fuzzer for Ruby code and C extensions, designed to automatically uncover security vulnerabilities through input mutation.

Ruby
Fuzzing
Security Testing
4. Security & Compliance

codeql

trailofbits

1.7K

A static code analysis tool for detecting security vulnerabilities and code quality issues using database-like queries.

CodeQL
Static Analysis
Security
4. Security & Compliance

libafl

trailofbits

1.7K

Modular library for building custom fuzzers to identify security vulnerabilities through automated input mutation.

Fuzzing
LibAFL
Security Testing
4. Security & Compliance

secure-workflow-guide

trailofbits

1.7K

Guides secure smart contract development with Slither scans, security checks, and documentation for fuzzing/verification.

Slither
Smart contracts
Fuzzing
4. Security & Compliance

semgrep

trailofbits

1.7K

Scans code for security vulnerabilities and enforces coding standards, integrating seamlessly into CI/CD pipelines for proactive security.

Semgrep
Static Analysis
Security
4. Security & Compliance

coverage-analysis

trailofbits

1.7K

Analyzes code coverage during fuzzing to evaluate harness effectiveness and identify execution blockers in security testing.

Fuzzing
Code Coverage
Security Testing
4. Security & Compliance

spec-to-code-compliance

trailofbits

1.7K

Verifies blockchain protocol code against specifications to identify implementation gaps and ensure compliance with documented requirements.

Blockchain
Compliance
Audit
4. Security & Compliance

firebase-apk-scanner

trailofbits

1.7K

Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, and authentication issues. For authorized security audits only.

Firebase
APK
Security Audit
4. Security & Compliance

sharp-edges

trailofbits

1.7K

Identifies security risks in API designs, configurations, and cryptographic libraries to enforce 'secure by default' principles and prevent common security pitfalls.

API Security
Secure Defaults
Cryptographic Libraries
4. Security & Compliance

guidelines-advisor

trailofbits

1.7K

Provides security-focused code analysis and actionable recommendations for smart contract development based on Trail of Bits best practices.

Smart Contract
Security Audit
Code Review
4. Security & Compliance

differential-review

trailofbits

1.7K

Performs security-focused differential code review for PRs and commits, detecting regressions and generating markdown reports with blast radius analysis.

Security Audit
Git Diff
Blast Radius
4. Security & Compliance

audit-prep-assistant

trailofbits

1.7K

Prepares codebases for security reviews by applying Trail of Bits' checklist, running static analysis, and generating security-focused documentation.

Static Analysis
Security Audit
Trail of Bits
4. Security & Compliance

atheris

trailofbits

1.7K

Provides coverage-guided fuzzing for Python code and C extensions to identify security vulnerabilities through automated input testing.

Fuzzing
Python
LibFuzzer
4. Security & Compliance

variant-analysis

trailofbits

1.7K

Identifies similar security vulnerabilities and bugs across codebases using pattern-based analysis, aiding in security audits and bug variant hunting.

CodeQL
Semgrep
Vulnerability Analysis
4. Security & Compliance

cairo-vulnerability-scanner

trailofbits

1.7K

Scans Cairo/StarkNet smart contracts for critical security vulnerabilities including arithmetic overflow and L1-L2 messaging issues, aiding in security audits.

Cairo
StarkNet
Smart Contract Security
4. Security & Compliance

entry-point-analyzer

trailofbits

1.7K

Analyzes smart contract codebases to identify and categorize state-changing entry points for security audits, excluding read-only functions.

State-Changing Functions
Access Control
Smart Contract Security
4. Security & Compliance

cosmos-vulnerability-scanner

trailofbits

1.7K

Scans Cosmos SDK blockchains for consensus-critical vulnerabilities including non-determinism, incorrect signers, and ABCI panics to aid in security audits.

Cosmos SDK
ABCI
Consensus
4. Security & Compliance

sarif-parsing

trailofbits

1.7K

Parses SARIF files to analyze security scan results, aggregate findings, deduplicate alerts, and integrate into security workflows.

SARIF
Security Scans
CI/CD
4. Security & Compliance

semgrep

trailofbits

1.7K

Performs static code analysis with Semgrep to detect security vulnerabilities, enforce code patterns via custom rules, and integrate into CI/CD pipelines.

Semgrep
Static Analysis
Vulnerability Scanning
4. Security & Compliance

ossfuzz

trailofbits

1.7K

Enables continuous fuzzing for open source projects to identify security vulnerabilities via automated input testing.

OSS-Fuzz
Fuzzing
Vulnerability Testing
4. Security & Compliance

constant-time-testing

trailofbits

1.7K

Detects timing side channels in cryptographic code to identify vulnerabilities during security audits.

Timing Attacks
Cryptographic Auditing
Side Channel
4. Security & Compliance

substrate-vulnerability-scanner

trailofbits

1.7K

Scans Substrate and Polkadot pallets for critical security vulnerabilities including arithmetic overflow and bad origin checks, aiding runtime audits.

Substrate
Polkadot
FRAME
4. Security & Compliance
PreviousPage 6 of 151 PageNext