Essential tools and best practices for securing software applications throughout their lifecycle.
Explore 221 curated tools and resources
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.
A cloud-native web application and API security solution that uses contextual AI to protect against known and zero-day threats without signature-based detection.
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Websecurify provides efficient ways to protect organizations with sophisticated technology and expert consultancy.
Protect your Fastify server against CSRF attacks with a series of utilities and recommendations for secure application development.
Reformat and re-indent bookmarklets, ugly JavaScript, and unpack scripts with options available via UI.
A script that implements Cognito attacks such as Account Oracle or Priviledge Escalation
Static code analyzer for Infrastructure as Code with 500+ security policies and support for various IaC tools and cloud platforms.
A web-based tool for instrumenting and analyzing Android applications using Flask, Jinja, and Redis.
Dynamic Java code instrumentation kit for Android applications.
Yaramod is a library for parsing YARA rules into AST and building new YARA rulesets with C++ programming interface.
A web security tool that scans for vulnerabilities and known attacks.
Kiterunner is a tool for lightning-fast traditional content discovery and bruteforcing API endpoints in modern applications.
A honeypot trap for Symfony2 forms to reduce spam submissions.
DOMPurify is a fast XSS sanitizer for HTML, MathML, and SVG.
Real-time, eBPF-based Security Observability and Runtime Enforcement component