Detection and monitoring
Vulnerability scanners and threat detection
Vulnerability scanners 87
- the LLM vulnerability scannergithub.com
- LLM vulnerability scannergithub.com
- AI Security Scanner - Test your AI sygithub.com
- R.A.Y.D.E.R revolutionizes security testgithub.com
- Protection against Model Serializatiogithub.com
- Fiddler Auditor is a tool togithub.com
- AI-Driven Security Assessment - Connect AIgithub.com
- A.I.G (AI-Infra-Guard) is a compregithub.com
- Free LLM-based Vulnerability Scans for Open Source Projectsknostic.ai
- Achieving CVE Remediation in an Era of Escalating Vulnerabilities - Floxflox.dev
- Active defense: introducing a stateful vulnerability scanner for APIsblog.cloudflare.com
- ADPulse - Active Directory security scannergithub.com
- AllForOne - Nuclei template collector for bug bounty huntersgithub.com
- Andrew Ng: OpenWorker open-source agent adds built-in vulnerability and supply-chain scanningx.com
- Announcing OSV-Scanner V2: Vulnerability scanner and remediation tool for open sourcesecurity.googleblog.com
- AppLockerInspector - audits AppLocker policy for weak settingsgithub.com
- Autoswagger - detect unauthenticated API endpoints and auth weaknesses via OpenAPI specsgithub.com
- awesome-attack-surface-monitoring - curated list of ASM toolsgithub.com
- batfish - network configuration analysis and validation toolgithub.com
- BChecks - scripted scan checks in Burp Suite Professionalportswigger.net
- Bitor scanner - Ansible playbook template that runs Nuclei scansgithub.com
- Burp Suite Enterprise Edition 2023.12 - BChecks supportportswigger.net
- burp-dom-scanner - Burp Suite extension to crawl SPAs and scan for DOM XSSgithub.com
- cent - community Nuclei templates aggregatorgithub.com
- CRXaminer - Chrome extension security analyzercrxaminer.tech
- CryptoLyzer - multi-protocol cryptographic configuration analyzer for TLS, SSH, IKE, DNS and HTTPcryptolyzer.readthedocs.io
- dalfox - open-source XSS scannergithub.com
- Defense at AI speed: Microsoft's new multi-model agentic security system tops leading industry benchmarkmicrosoft.com
- deph-action - GitHub Action tracing which container CVEs are in your execution pathgithub.com
- dev-machine-guard - scan dev machines for AI agents, MCP servers, IDE extensions and suspicious packagesgithub.com
- DLLHound - DLL sideloading scanner for Windowsgithub.com
- dnsight - SDK and CLI for DNS, email and web security hygienegithub.com
- DotGit - browser extension to detect exposed .git folderschrome.google.com
- DotGit - Firefox extension to detect exposed .git foldersaddons.mozilla.org
- EasyEASM - zero-dollar attack surface management toolgithub.com
- EGOAlpha - EGO vulnerability scanner and reconnaissance platformgithub.com
- Filter Out Security Vulnerability False Positives with VEXdocker.com
- Find-WSUS - locate WSUS configurations in GPOs after CVE-2025-59287github.com
- ghostsecurity/reaper - agent tool source in Ghost Security's live validation proxy for web app vulnerability testinggithub.com
- ghqr - GitHub Quick Review, assess orgs against GitHub security best practicesgithub.com
- GRC ShieldsUP - Internet vulnerability profiling port scannergrc.com
- HVCI-loldrivers-check - check vulnerable drivers against HVCI blocklistgithub.com
- Introducing fAST Dynamic - streamlining dynamic application security testingsynopsys.com
- Introducing Nuclei v3 with improved vulnerability scanning featuresblog.projectdiscovery.io
- Introducing Orbit - BHIS tool to run Nuclei scans at scaleblackhillsinfosec.com
- JFrog Xray Contextual Analysis - vulnerability applicability scanningdocs.jfrog-applications.jfrog.io
- Jobert Abma on Nuclei Cloud integration into HackerOne for vulnerability detectionx.com
- kernel-hardening-checker - checks Linux kernel security hardening optionsgithub.com
- Kubernetes Cluster Security - Nuclei Templates v9.9.0blog.projectdiscovery.io
- Kubescape VEX document generationkubescape.io
- kubesplaining - Kubernetes RBAC, pod-escape and privilege-escalation security assessment CLIgithub.com
- managed-kubernetes-auditing-toolkit - security auditing for Amazon EKSgithub.com
- Mantis - asset discovery, recon automation and distributed scanning framework by PhonePephonepe.github.io
- mantis - asset discovery, reconnaissance and vulnerability scanning frameworkgithub.com
- Misconfig Mapper - detect security misconfigurations in third-party servicesgithub.com
- Nero - open source HTTP API fuzzergithub.com
- NGINX_RIFT_SCAN - scanner for nginx rewrite vulnerability CVE-2026-42945github.com
- NightVision - Whole-App DAST for web apps and APIsnightvision.net
- Nuclei AI - browser extension for AI-generated Nuclei vulnerability templatesgithub.com
- Nuclei as a Go library - projectdiscovery/nuclei/v3/lib packagepkg.go.dev
- Nuclei template for ServiceNow widget misconfiguration - PR #8396github.com
- Nuclei Templates Editor - create, generate, and scan templates using AI from ProjectDiscoverytemplates.nuclei.sh
- Online SQL Injection Vulnerability Scannersecurityforeveryone.com
- patchbot - vulnerability scanning with a coding agent that opens fix PRsgithub.com
- pgdsat - PostgreSQL Database Security Assessment Toolgithub.com
- picklescan - security scanner for malicious Python pickle filesgithub.com
- ProjectDiscovery on using CVEmap to find exploitable CVEs lacking Nuclei templatesx.com
- quibble - container security scanner for compose based configurationsgithub.com
- raven - CI/CD security analyzer for GitHub Actions workflowsgithub.com
- react2shell-scanner - detection tool for RSC/Next.js RCE CVE-2025-55182github.com
- runZero Loves Open Source - Integrating Nucleirunzero.com
- Security Crawl Maze - testbed for web security crawlerssecurity-crawl-maze.app
- Server-Side Prototype Pollution Scanner - Burp Suite extensionportswigger.net
- servicenow - ServiceNow widget-simple-list misconfiguration scannergithub.com
- ship-safe - CLI security scanner for AI-written software: CI/CD, agent permissions, MCP tool injection, secretsgithub.com
- Sirius Scan - open-source vulnerability scannersirius.publickey.io
- StackHawk Announces HawkScan Test Enginestackhawk.com
- StepSecurity Dev Machine Guard - scans dev machines for rogue MCP servers, extensions and packagesraw.githubusercontent.com
- The ZAP LLM Support Add-onzaproxy.org
- Unveiling poutine - an open source build pipelines security scannerboostsecurity.io
- Use ZAP with KRO in Kuberneteszaproxy.org
- VibeAudit - BOLA/IDOR authorization scanner for AI-generated web appsgithub.com
- Vigolium - agentic AI vulnerability scannergithub.com
- Visa enhances VVAH Vulnerability Agentic Harness with remediation and validation agentslinkedin.com
- vsix-audit - security scanner for VS Code extensionsgithub.com
- XSSTRON - Electron browser to find XSS vulnerabilities automaticallygithub.com
- ZAP LLM Integration add-on - zap-extensions pull request 5861github.com
Security platforms 83
- MACAW Security - The Trust Layer for Enterprise AImacawsecurity.ai
- 0Labs - AI Cyber Defense0labs.ai
- OpenAnt from Knostic is an open source LLgithub.com
- Project CodeGuardgithub.com
- Dropzone AI - Agentic SOC Platformdropzone.ai
- AI Risk Databasegithub.com
- A curated list of tgithub.com
- A curated list ofgithub.com
- Fishbowl - Containerized security auditing for AI coding agentsgithub.com
- Codefend - AI-powered security automation platformcodefend.ai
- Databricks Announces Lakewatch: New Open Agentic SIEMdatabricks.com
- eekta - AI Cyber Defense Consoleeekta.run
- Bltz AI - Agentic Defensive AI Securitypublic.bltz.ai
- Agent Charley by Charlemagne Labs - on-device privacy-first security agentcharlemagnelabs.ai
- Agentic SOC Platform: The Open-Source AI Security Revolution Taking Over Your SOCundercodetesting.com
- Aikido Device Protection - malicious package blocking and AI tool monitoring for dev workstationsaikido.dev
- AiSOC - open-source AI-powered Security Operations Center with agent-assisted triagegithub.com
- Akto - AI and API security platform for agents, MCPs and LLMsgithub.com
- Allama - open-source AI security automation and SOAR platformgithub.com
- Artiphishell Public Disclosure Ledger - AI-found vulnerabilities with sealed 30-day disclosuresartiphishell.com
- Avalor - Unified Vulnerability Management, now Zscaler UVMavalor.io
- Backslash Security - agentic AI endpoint security and AppSec platformappsec.backslash.security
- binaryedge - attack surface mapping POC in the style of Shodan and Censysgithub.com
- Boost Security with API Security Posture Management - Microsoft Defender for Cloudtechcommunity.microsoft.com
- Byos Secure Endpoint Edge - first-hop protection for untrusted Wi-Fibyos.io
- cartography - map infrastructure assets and relationships into a Neo4j graphgithub.com
- Context Is King: From Vulnerability Management to Exposure Managementtenable.com
- CrowdStrike Falcon AIDR - AI Detection and Response, redirected from Pangea AI Escape Roompangea.cloud
- CyberAgents Exchange - open-source AI agents, skills and MCP servers for cybersecurityexchange.tenable.com
- Deepfactor - Application Security Platformdeepfactor.io
- DetectFlow / Prime Detect - AI-powered detection intelligence from SOC Primegithub.com
- Empirical Security - AI foundation model for vulnerability exploitation predictionempiricalsecurity.com
- Empirical Security - data-driven models for vulnerability prioritization and exposure managementempiricalsecurity.com
- Enclave - autonomous AI security agents that find, fix and retest vulnerabilitiesx.com
- Endor Labs launches Zero-Day Patches: verified fixes for open source zero-days within 24 hoursx.com
- Exploit Observer - vulnerability and exploit intelligence databaseexploit.observer
- Forager - Truffle Security public event monitoringforager.trufflesecurity.com
- FullHunt - Attack Surface Management APIapi-docs.fullhunt.io
- Ghost Security - Autonomous security agents platformghostsecurity.com
- harden-runner - EDR for GitHub Actions runnersgithub.com
- Incidental - open-source incident management platform with Slack integrationgithub.com
- InfraTrust - Hardware Infrastructure Riskinfra-trust.org
- Introducing EVA - The Employee Verification App to stop AI and voice phishingblog.foxio.io
- Introducing Google AI Threat Defensecloud.google.com
- Introducing Microsoft Security Copilot: Empowering defenders at the speed of AIblogs.microsoft.com
- Introducing nano - lightweight SIEM in Rust with AI investigationblog.nano.rs
- Introducing Surf AI - automating security processes to reduce attack surfacesurf.ai
- Introducing Wiz ASM: Context-Driven Attack Surface Managementwiz.io
- Introducing Wiz Code - Code-to-cloud application securitywiz.io
- IVRE - self-hosted network recon and EASM frameworkgithub.com
- Koidex by Koi - risk detection for extensions, packages, apps, and modelsextensiontotal.com
- Leen - unified API for security dataleen.dev
- MagicSword - Threat-Driven Application Controlmagicsword.io
- Microsoft Security Copilot Early Access Program is now availablemicrosoft.com
- Monad - security data pipelines for enterprise teamsmonad.com
- Monad, formerly Tarsal - security data pipelines for enterprise teamstarsal.co
- Oligo Focus - runtime vulnerability reachability analysis productoligo.security
- OpenAI Daybreak - AI for cybersecurityopenai.com
- OpenHack - your always-on AI security engineeropenhack.com
- ProjectDiscovery launches Triage to auto-reproduce and validate bug bounty vulnerability reportsx.com
- ProjectDiscovery Neo - AI-driven offensive security and pentesting platform from the creators of Nucleiprojectdiscovery.io
- ProjectDiscovery Triage - automated vulnerability report validation and triageprojectdiscovery.io
- Prowler - open-source cloud security platformgithub.com
- Pruva verified reproduction: CVE-2026-33557 Apache Kafka SASL/OAUTHBEARER accepts unvalidated JWTspruva.dev
- RapidFort - container software supply chain security platformrapidfort.com
- RunReveal - security log management and SIEM with AI-powered detectionrunreveal.com
- Sandfly SSH Hunter - agentless SSH key and credential monitoring for Linuxsandflysecurity.com
- Seal Security - the AppSec remediation agentseal.security
- secureCodeBox - automated multi-scanner security testing platformsecurecodebox.io
- Securing the AI Enterprise - Introducing Prisma AIRS 3.0paloaltonetworks.com
- shade - shadow SaaS and credential detection via browser extensiongithub.com
- Shasta - open-source AI and cloud security platform with AI-BOM and compliance frameworksgithub.com
- ShipSec Studio - open-source security workflow orchestration platformgithub.com
- Shockwave - attack surface and continuous threat exposure management platformshockwave.cloud
- Smithy, formerly Dracon - security workflow enginegithub.com
- solst/ICE on why appsec teams should adopt ASPM platformsx.com
- The New Way to Discover Your Exposure - ProjectDiscoveryprojectdiscovery.io
- ThreatMapper - open source cloud native application protection platformgithub.com
- tuckner on SecureAnnex adding VS Code extension security analysisx.com
- Vigil - open source agentic AI SOC with MCP integrationsvigilsoc.org
- Visa Releases Its AI-Powered Cyber Defense System to Open Sourcecorporate.visa.com
- Wallarm AASM - API Attack Surface Managementwallarm.com
- WitnessAI - AI Security and Governance Platformwitness.ai
Threat detection and analysis 135
- Introducing VirusTotal Code Insight: Empowering threat analysis witblog.virustotal.com
- Introducing Socket AI – ChatGPT-Powered Threat Analysis - Socketsocket.dev
- Malicious ML models discovered on Hugging Face platformreversinglabs.com
- An AI-powered secugithub.com
- Pillar Security Unveils RedGraph: The World's First Attack Surfacpillar.security
- Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Iwiz.io
- LLM Backdoors at the Inference Level: The Threat of Poisoned Templatespillar.security
- Rowhammer-Based Trojan Injection: One Bit Flip Is Sufficioneflipbackdoor.github.io
- Awesome DFIR Skillsgithub.com
- A guide to threat hunting and monitoring in Snowflakesecuritylabs.datadoghq.com
- A Tale of Two SOCs: Insights From Two Red Team Assessments - CISAcisa.gov
- Agentic Threat Hunting Framework - ATHF, framework for agentic threat hunting systemsgithub.com
- Announcing Cloudflare Fraud Detectionblog.cloudflare.com
- Announcing cvemap from ProjectDiscoveryblog.projectdiscovery.io
- AntiHunter DIGINODE - WiFi, BLE and drone detection hardwarelectronz.com
- Artificial authentication: Monitoring Azure OpenAI abuseredcanary.com
- autoextdetector - a self-improving detection agent for supply-chain attacksmsuiche.com
- Azure Logs - Breaking Through the Cloud Coverpermiso.io
- Baddie Mapper - experimental IOC and threat actor relationship mapping toolmr-r3b00t.github.io
- bluehood - monitor your local neighbourhood's Bluetooth activitygithub.com
- BR-Phishing-Feed - CertStream phishing domain feed for Brazil filtered with Ollamagithub.com
- Building a Threat Intelligence GenAI Reporter with ORKL and Claudeblog.securitybreak.io
- Building Runtime Enforcement for Kubernetes with eBPFjuliet.sh
- cazadora - M365 OAuth app threat hunting scriptgithub.com
- certgrep - search Certificate Transparency logs for domain squatting and phishingcertgrep.sh
- checkpointctl - analysis of container checkpointsgithub.com
- cicd-sensor - eBPF runtime security for GitHub Actions and GitLab CI/CDgithub.com
- Cloudflare Radar URL Scannerradar.cloudflare.com
- cloudgrep - grep for cloud storage logs across S3, Azure and GCSgithub.com
- Coalition Exploit Scoring System - ML-powered exploit likelihood scoring for CVEsess.coalitioninc.com
- ContentOps - detection content lifecycle for Microsoft Sentinel and Defender XDRgithub.com
- copy-fail CVE-2026-31431 IOC - Linux kernel privesc detection toolkitgithub.com
- CRADLE - collaborative Cyber Threat Intelligence platformgithub.com
- crt.name - passive subdomain index built from Certificate Transparency logscrt.name
- ct-moniteur - Certificate Transparency log monitorgithub.com
- cti-expert - Cyber Threat Intelligence and OSINT analysis skill for Claude Codegithub.com
- CVE Crowd - crowd intelligence on actively discussed CVEscvecrowd.com
- CVEForecast - CVE publication predictions with machine learningcveforecast.org
- Defender Performance Tool - real-time Microsoft Defender scan monitorgithub.com
- Detection Engineering Weekly #27detectionengineering.net
- Detection Skills - open standard extending Agent Skills for agentic SOC and cyber defense engineeringdetectionskills.io
- Displaying IP addresses in the audit log for your GitHub Enterprisedocs.github.com
- dnsmonster - passive DNS capture and monitoring toolkitgithub.com
- eBPF Unleashed: The Future of Runtime Application Securityraven.io
- eCapture - capture SSL/TLS plaintext without a CA certificate using eBPFgithub.com
- EDRUnChoker - fileless WMI defense against EDRChoker QoS throttlinggithub.com
- esxi-testing-toolkit - CLI to test ESXi detections, Atomic Red Team stylegithub.com
- ExtensionHound - DNS forensics for browser extensionsgithub.com
- ExtSentry - Browser Extension Threat Intelligenceextsentry.github.io
- Ferdous Saljooki on macOS Tahoe's XProtect ClickFix paste protectionx.com
- FunkSec - Alleged Top Ransomware Group Powered by AI - Check Point Researchresearch.checkpoint.com
- gibson - network monitoring tool mapping process-to-network connections and detecting beaconinggithub.com
- grove - HashiCorp SaaS security log collection frameworkgithub.com
- Handala Detection Pack v2: Pre-Positioning, PIM Gap, and Bulk Wipe Controlsthreathunter.ai
- How Google Does It: Modernizing threat detectioncloud.google.com
- hunt.md - open Markdown format for threat-hunting playbooksgithub.com
- ice-axe - Snowflake native app for threat hunting and activity auditinggithub.com
- IDE Shepherd - VS Code/Cursor extension for realtime detection of malicious extensionsgithub.com
- Immanuel on eBPF bcc-tools one-liners for process, file and network monitoringx.com
- intelsummarize - LLM threat intel report summarizer by MHaggisgithub.com
- Introducing EvidenceForge: Synthetic security logs that don't look as fakeblog.talosintelligence.com
- Introducing YetiHunter: An open-source tool to detect and hunt for suspicious activity in Snowflakepermiso.io
- ipinfo cli - IP geolocation and ASN lookup toolgithub.com
- kerlab - Kerberos in Rust for building detection rulesgithub.com
- Kestrel - Active Directory backdoor and persistence audit toolgithub.com
- KEV Cross-Catalog Viewercyberdivemaster.github.io
- kntrl - eBPF runtime security agent for CI/CD pipelinesgithub.com
- KubeHound: Identifying attack paths in Kubernetes clusterssecuritylabs.datadoghq.com
- Log Sources Your SOC Needs for Detection, Forensics, and Huntingsocautomators.substack.com
- LOLFSaaS - Living off Free SaaSlolfsaas.github.io
- lolol.farm - curated index of Living Off the Land security research projectslolol.farm
- MagicSword integrates LOLExfil and ExtSentry to block exfiltration tools and malicious browser extensionsx.com
- Making Damn Vulnerable Web Application almost unhackable with Cilium and Tetragonholdmybeersecurity.com
- malcontent - malware and supply-chain risk detection for binariesgithub.com
- Malicious Extension Bot - feed tracking bad browser and IDE extensionsinfosec.exchange
- malicious_extension_sentry - auto-updated database of malicious Chrome and Edge extensionsgithub.com
- Merklemap - DNS records databasemerklemap.com
- Michael Haag on webshell testing for defenders - Apache and IIS builder tools to validate detectionsx.com
- msInvader - M365 and Azure adversary simulation tool for blue teamsgithub.com
- netwatch - terminal network monitor that names processes and catches malware calling homegithub.com
- NEX - autonomous LLM purple-team agent that finds and closes Splunk detection gapsgithub.com
- Next.js RSC RCE Detection: CVE-2025-55182 and CVE-2025-66478 - Assetnoteslcyber.io
- NoCat - harmless Netcat lookalike for detection testinggithub.com
- Nzyme - WiFi, Bluetooth and Ethernet intrusion detectionnzyme.org
- OdinEye public beta - one-liner scan to answer 'Is this computer compromised?'x.com
- oryx - TUI for sniffing network traffic using eBPF on Linuxgithub.com
- osquery - SQL-powered operating system instrumentation for endpoint monitoringosquery.io
- Otterize network-mapper - map Kubernetes pod, Internet and AWS IAM trafficgithub.com
- owLSM - Sigma rules engine inside the Linux kernel using eBPFgithub.com
- Patch Wednesday: Root Cause Analysis with LLMs - PatchDiff-AI multi-agent systemakamai.com
- Phoenix - Sigma Rule Intelligence Platformsigma.nasbench.dev
- PingCastle-Notify - monitor PingCastle AD scans and alert on rule diffs via Slack or Teamsgithub.com
- Pitfalls of relying on eBPF for security monitoring, and some solutionsblog.trailofbits.com
- pktz - eBPF network traffic monitor per processgithub.com
- PromptLock ransomware prompt - gist of the AI-powered malware's LLM promptgist.github.com
- RansomLook - open ransomware group intelligenceransomlook.io
- Recent CrowdStrike Outage Emphasizes the Need for eBPF-Based Sensorsoligo.security
- Relishing new Fickling features for securing ML systemsblog.trailofbits.com
- Renzon: OpenAI Computer History is a new DFIR artifact class, parsed by IRFlow-Timelinex.com
- Rob T. Lee announces Find Evil, an autonomous AI hackathon for incident response using Protocol SIFT and MCPx.com
- Ruben Groenewoud on Linux malware disguising as kernel worker threadsx.com
- RustNet - per-process network monitoring with deep packet inspection, sandboxedgithub.com
- Security-Detections-MCP - MCP server for querying Sigma, Splunk, Elastic, KQL and CrowdStrike detection rulesgithub.com
- security-investigator - automated security investigations with Copilot, Agent Skills and Microsoft MCP serversgithub.com
- SecurityClaw - autonomous LLM-powered SOC agentgithub.com
- SharkMCP - MCP server exposing Wireshark sharkd for LLM PCAP analysisgithub.com
- SIEMTriage - AI SOC triage agent for Microsoft Sentinel and Defender XDRgithub.com
- sniffnet - network traffic monitoring toolgithub.com
- SquatSquasher - typosquatting domain detectorgithub.com
- sshlog - eBPF SSH session monitoring daemongithub.com
- Stratoshark - Wireshark-style system call and cloud activity analysis toolstratoshark.org
- Sublime Security launches free Public EML Analyzer for email message analysisx.com
- surface-watch - external attack surface monitoring over timegithub.com
- Syd - air-gapped offline AI cybersecurity assistant for Nmap, Volatility, BloodHound and moregitlab.com
- Synapse - Vertex Project central intelligence system for threat analyst teamsgithub.com
- Synapse Quickstart - threat intelligence analysis platformgithub.com
- Tailpipe - open source SIEM for instant log insights powered by DuckDBgithub.com
- The AMOS infostealer is piggybacking ChatGPT's chat-sharing featurekaspersky.com
- Theia - pull IOCs from a threat intel reporttheia.ktlystlabs.com
- THINKPOL free Reddit OSINT tools - user lookup, trends and archive searchr00m101.com
- TwistScan - dnstwist plus urlscan.io for phishing and typosquatting detectiongithub.com
- VanGuard - cross-platform DFIR incident response toolkitgithub.com
- Venator - flexible threat detection platformgithub.com
- Venator - threat detection platform LLM modulegithub.com
- VirusTotal - malware, URL and domain analysis servicevirustotal.com
- Vulnerability Spoiler Alert - AI-powered early warning for open-source security patchesvulnerabilityspoileralert.com
- What framing security alerts as a binary true or false positive is costing youmagonia.io
- When AI infrastructure becomes the target: Securing gateways and control pointsmicrosoft.com
- WhoYouCalling - per-process network activity monitoring and packet capture for Windowsgithub.com
- Windows Security Events Referenceunresolvedhost.github.io
- WireMCP - Wireshark MCP server for LLM network traffic analysisgithub.com
- Wiz Cloud Threat Landscape - cloud security incidents, actors and techniques databasethreats.wiz.io
- YetiHunter - hunt for evidence of compromise in Snowflake environmentsgithub.com
- Young Domain Guard - browser extension warning on recently registered domainsgithub.com
- ZettelForge - agentic memory for cyber threat intelligence with MCP servergithub.com
Security code review 25
- Making frontier cybersecurity capabilities available to defendersanthropic.com
- #ai #llm #security #audit - Kevin J. - 21 commentslinkedin.com
- A prompt that finds deep logic bugs, and the pipeline we built around itworkos.com
- An AI harness found a container escape in HashiCorp Nomad, CVE-2026-14891volkankutal.com
- auditician - automated security auditing for Claude Codegithub.com
- Behind the Scenes Hardening Firefox with Claude Mythos Previewhacks.mozilla.org
- bug-hunter - adversarial AI bug hunter and auto-fix skill for coding agentsgithub.com
- Building a Practical Secure Code Review Processbetterappsec.com
- Claude Code security-guidance plugin: catch security issues as Claude writes codecode.claude.com
- Cursor Security Agentscursor.com
- Cursor Security Review - always-on AI agents for PR review and vulnerability scanningx.com
- Leveling Up Secure Code Reviews with Claude Codespecterops.io
- Mantis - security review skills toolkit for AI coding agentsgithub.com
- MindFort security-skills - security skills for AI coding agentsgithub.com
- PoiEx - VS Code extension for IaC security code reviewgithub.com
- quokka - CLI for LLM-assisted security code reviewgithub.com
- Ramp Labs - Finding high-severity security issues with publicly available modelsx.com
- raptor-loop-hunt - autonomous vulnerability hunt Claude Code skillgithub.com
- Read code like a pro with our weAudit VSCode extensionblog.trailofbits.com
- Security Context - mines repo history and CVEs to point AI agents at likely vulnerabilitiessecuritycontext.dev
- security-audit-skill - Cloudflare's coding-agent skill for multi-phase security auditsgithub.com
- Staying Ahead of Adversarial AI Through Agentic Source Code Reviewcloud.google.com
- The Ceiling for DIY Security Reviewslinkedin.com
- Unearned Confidence: AI Security Reviewers Don't Really Get Itcheckmarx.com
- V12 - AI security agent for mission critical codev12.sh