StaCoAn is a cross-platform tool designed for static code analysis on mobile applications, focusing on identifying hardcoded credentials, API keys, URLs, decryption keys, and major coding mistakes. It offers a user-friendly interface with graphical guidance, supporting APK files with future support for IPA files. The tool allows customization through settings and wordlists, generating visual and portable reports.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
EvoMaster is an open-source tool that automatically generates system-level test cases for web APIs using AI-driven techniques.
A lightweight web security auditing toolkit that simplifies security tasks and enhances productivity.
Static code analysis tool for infrastructure as code (IaC) and software composition analysis (SCA) with over 1000 built-in policies for AWS, Azure, and Google Cloud.
A free book providing design and implementation guidelines for writing secure programs in various languages.
InQL is a Burp Suite extension for advanced GraphQL testing and vulnerability detection
BunkerWeb is a next-generation and open-source Web Application Firewall (WAF) with seamless integration and user-friendly customization options.
API security platform that combines discovery, testing, and monitoring capabilities to identify and protect against API vulnerabilities throughout the development lifecycle.
Pint is a PIN tool that exposes the PIN API to lua scripts, allowing dynamic instrumentation of binaries.
Automated framework for monitoring and tampering system API calls of native macOS, iOS, and Android apps.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.