0l4bs Cross-site scripting labs
A tool that safely installs packages with npm/yarn by auditing them as part of your install process.
Secure your applications with robust security measures. Protect against vulnerabilities and threats effectively.
A tool that safely installs packages with npm/yarn by auditing them as part of your install process.
A tool for building and installing PhoneyC with optional Python version configuration and root privileges.
QIRA is a competitor to strace and gdb with MIT license, supporting Ubuntu and Docker for wider compatibility.
ConDroid performs concolic execution of Android apps to observe 'interesting' behavior in dynamic analysis.
An open-source modern Dependency Walker for Windows developers.
An automated security testing platform that performs AI-driven penetration testing and vulnerability assessment for web applications and APIs with compliance reporting capabilities.
CFRipper is a Library and CLI security analyzer for AWS CloudFormation templates.
An API security platform that provides automated discovery, documentation, and continuous security testing throughout the API lifecycle.
StepSecurity is a platform that enhances GitHub Actions security by providing network egress control, risk discovery, action replacement, and security best practices orchestration.
XSS Polyglot Challenge - XSS payload running in multiple contexts for testing XSS.
Application monitoring and security platform that provides runtime visibility, threat detection, and automated response capabilities for application-layer security
An application security testing platform that combines automated scanning, AI assistance, and manual expert testing to provide continuous security assessment throughout the software development lifecycle.
A static code analysis tool for parsing common data formats to detect hardcoded credentials and dangerous functions.
SAST and malware analysis tool for Android APKs with detailed scan information.
A cloud-native web application and API security solution that uses contextual AI to protect against known and zero-day threats without signature-based detection.
Snyk Code is a real-time SAST tool that provides secure code analysis and actionable remediation advice to prevent code delays and ensure secure development.
A tool to profile web applications based on response time discrepancies.
An ASPM platform that provides software supply chain security through risk assessment, prioritization, and protection mechanisms.
Static code analyzer for Infrastructure as Code with 500+ security policies and support for various IaC tools and cloud platforms.
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.