{"id":13814796,"url":"https://github.com/twosmi1e/Static-Analysis-and-Automated-Code-Audit","last_synced_at":"2025-05-15T06:33:09.883Z","repository":{"id":38320990,"uuid":"378979921","full_name":"twosmi1e/Static-Analysis-and-Automated-Code-Audit","owner":"twosmi1e","description":"静态分析及代码审计自动化相关资料收集","archived":false,"fork":false,"pushed_at":"2022-07-29T13:56:57.000Z","size":39948,"stargazers_count":280,"open_issues_count":0,"forks_count":27,"subscribers_count":6,"default_branch":"main","last_synced_at":"2024-08-04T04:06:21.806Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/twosmi1e.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-06-21T15:34:54.000Z","updated_at":"2024-06-19T14:30:48.000Z","dependencies_parsed_at":"2022-07-13T09:10:42.718Z","dependency_job_id":null,"html_url":"https://github.com/twosmi1e/Static-Analysis-and-Automated-Code-Audit","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/twosmi1e%2FStatic-Analysis-and-Automated-Code-Audit","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/twosmi1e%2FStatic-Analysis-and-Automated-Code-Audit/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/twosmi1e%2FStatic-Analysis-and-Automated-Code-Audit/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/twosmi1e%2FStatic-Analysis-and-Automated-Code-Audit/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/twosmi1e","download_url":"https://codeload.github.com/twosmi1e/Static-Analysis-and-Automated-Code-Audit/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225335151,"owners_count":17458219,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T04:02:35.418Z","updated_at":"2025-05-15T06:33:09.877Z","avatar_url":"https://github.com/twosmi1e.png","language":null,"funding_links":[],"categories":["Others"],"sub_categories":[],"readme":"# Static Analysis \u0026 Automated Code Audit\n静态分析及代码审计自动化相关资料收集\n\n## 公开课\n- [南京大学软件分析](https://pascal-group.bitbucket.io/teaching.html)，[课程视频](https://zhuanlan.zhihu.com/p/110050716)，以及一些[直播课录屏](https://space.bilibili.com/238948858/)\n\n- [北京大学软件分析](https://xiongyingfei.github.io/SA/2020/main.htm)\n\n\n## 论文\n- [Detecting Node.js Prototype Pollution Vulnerabilities via Object Lookup Analysis](https://github.com/twosmi1e/Static-Analysis-and-Automated-Code-Audit/blob/main/paper/Detecting%20Node.js%20Prototype%20Pollution%20Vulnerabilities%20via%20ObjectLookup%20Analysis.pdf)\n- [ConDySTA: Context-Aware Dynamic Supplement to Static Taint Analysis](https://readpaper.com/paper/3154138117)\n- [A Principled Approach to Selective Context Sensitivity for Pointer Analysis](https://readpaper.com/paper/3030148664)\n- [Static Analysis-Based Approaches for Secure Software Development](https://readpaper.com/paper/2884058242)\n- [An Empirical Study on the Effectiveness of Static C Code Analyzers for Vulnerability Detection](https://dl.acm.org/doi/10.1145/3533767.3534380)\n\n## 文章\n### 研究者\n- [从0开始聊聊自动化静态代码审计工具](https://lorexxar.cn/2020/09/21/whiteboxaudit/)\n- [软件测试简介](https://github.com/RangerNJU/Static-Program-Analysis-Book)\n- [白盒综述](https://forum.90sec.com/t/topic/1087)\n- [基于JS语义分析的Dom-XSS自动化研究](https://mp.weixin.qq.com/s/PWVJSd6nrKt6ErnIHIPRzA)\n- [构造一个CodeDB来探索全新的白盒静态扫描方案](https://lorexxar.cn/2020/10/30/whitebox-2/)\n- [owasp整理的白盒工具大全](https://owasp.org/www-community/Source_Code_Analysis_Tools)\n- [漏洞挖掘的艺术-面向二进制的静态漏洞挖掘](https://www.freebuf.com/articles/network/248487.html)\n- [漏洞挖掘的艺术-面向源码的静态漏洞挖掘](https://www.freebuf.com/articles/network/248215.html)\n- [Blackhat-Do You Speak My Language? Make Static Analysis Engines Understand Each Other](https://www.blackhat.com/us-21/briefings/schedule/#do-you-speak-my-language-make-static-analysis-engines-understand-each-other-22797)\n\n### 企业\n- 58集团白盒代码审计系统建设实践\n  - [58集团白盒代码审计系统建设实践1：技术选型](https://xz.aliyun.com/t/9335)\n  - [58集团白盒代码审计系统建设实践2：深入理解SAST](https://xz.aliyun.com/t/9429)\n  - [Java 供应链(依赖)安全检测实践](https://mp.weixin.qq.com/s/1fnDelBE1HisEaopEyk8nQ)\n- 腾讯Xcheck\n  - [Xcheck之Node.js安全检查引擎](https://mp.weixin.qq.com/s/Kl9omJ91R3rGSe4h8gk0PQ)\n  - [Xcheck之Python安全检查引擎](https://mp.weixin.qq.com/s/_UEofmOavtkYqNpti_FcxA)\n  - [Xcheck之PHP代码安全检查](https://mp.weixin.qq.com/s/K29g9Gu-JQvOoOQ98sreBg)\n  - [Xcheck之Golang安全检查引擎](https://mp.weixin.qq.com/s/VzjcXp3O8zc97aIppy4LUA)\n  - [Xcheck之Java安全检查引擎](https://mp.weixin.qq.com/s/rb1BfcZeCTr2PIiypXqVjw)\n  - [SAST大规模应用实践](https://mp.weixin.qq.com/s/7_r7N3X_fn22uGJWcW-8GQ)\n  - [Xcheck Java引擎漏洞挖掘\u0026防护识别](https://mp.weixin.qq.com/s/FPMUVoSqc0Lsf5BQx07ADw)\n- [360移动端工具fireline](http://magic.360.cn/zh/index.html)\n- [阿里代码规范检查工具](https://github.com/alibaba/p3c)\n- [DevSecOps建设之白盒续篇](https://www.freebuf.com/articles/es/317975.html)\n\n### CodeQL研究\n- [代码分析引擎 CodeQL 初体验](https://paper.seebug.org/1078)\n- [CodeQL 的学习以及尝试漏洞挖掘](https://bestwing.me/codeql.html)\n- [Finding security vulnerabilities in JavaScript with CodeQL](https://www.youtube.com/watch?v=pYzfGaLTqC0)\n- [Finding security vulnerabilities in Java with CodeQL](https://www.youtube.com/watch?v=nvCd0Ee4FgE)\n- [使用 CodeQL 分析 AOSP](https://xz.aliyun.com/t/11080)\n- [CodeQL 提升篇](https://xz.aliyun.com/t/10852)\n- [利用CodeQL分析并挖掘Log4j漏洞](https://xz.aliyun.com/t/10707)\n- [codeql分析grafana任意文件读取](https://xz.aliyun.com/t/10648)\n- [如何用CodeQL数据流复现 apache kylin命令执行漏洞](https://xz.aliyun.com/t/8240)\n- [使用 CodeQL 挖掘 CVE-2020-9297](https://xz.aliyun.com/t/7979)\n- [codeql学习——污点分析](https://xz.aliyun.com/t/7789)\n- [Codeql 入门教程](https://xz.aliyun.com/t/7657)\n- [如何利用CodeQL挖掘CVE-2020-10199](https://www.anquanke.com/post/id/202987)\n- [使用codeql 挖掘 ofcms](https://www.anquanke.com/post/id/203674)\n- [从Java反序列化漏洞题看CodeQL数据流](https://www.anquanke.com/post/id/256967)\n- [Codeql分析Vulnerability-GoApp](https://www.freebuf.com/articles/web/253491.html)\n- [semgrep 分析log4j漏洞](https://www.freebuf.com/articles/web/321757.html)\n\n\n## 书籍\n- [编译原理](https://github.com/twosmi1e/Static-Analysis-and-Automated-Code-Audit/blob/main/book/%E7%BC%96%E8%AF%91%E5%8E%9F%E7%90%86%E9%BE%99%E4%B9%A6%E4%B8%AD%E6%96%87%E7%AC%AC%E4%BA%8C%E7%89%88.pdf)\n- [Secure_programming_with_Static_Analysis](https://github.com/twosmi1e/Static-Analysis-and-Automated-Code-Audit/blob/main/book/Secure_programming_with_Static_Analysis.pdf)\n\n\n## 工具\n- [CodeQL](https://codeql.github.com/docs/)\n- [gosec](https://github.com/securego/gosec)\n- [Kunlun-M](https://github.com/LoRexxar/Kunlun-M)\n- [Cobra](https://github.com/FeeiCN/Cobra)\n- [sast-scan](https://github.com/ShiftLeftSecurity/sast-scan)\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftwosmi1e%2FStatic-Analysis-and-Automated-Code-Audit","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftwosmi1e%2FStatic-Analysis-and-Automated-Code-Audit","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftwosmi1e%2FStatic-Analysis-and-Automated-Code-Audit/lists"}