Program Analysis

SURFER

A static analysis tool to find SSRF candidates in PHP CPGs.

Arachnarium

Arachnarium is a plug-and-play benchmark framework for crawlers that can run experiments at scale against both local, standalone web applications and live websites.

JAW (Javascript Analysis frameWork)

JAW is a scalable framework to analyze client-side JavaScript programs. JAW can be used to conduct interactive and exploratory analysis of JavaScript code.

Deemon

Deemon detects CSRF in PHP/SQL web applications by combining dynamic analysis with property graphs.

Guenther

Guenther tests web applications against Server Side Request (SSR) abuse including Web Origin Laundering, Server Side Request Forgery (SSRF) and other abuses.