Tools list

Prober

An AI-powered tool that analyse CVEs by examining source code, identifying the top-ranked Git commits that patch vulnerabilities. Supporting over 14 programming languages, it identifies impacted source files and functions, leveraging data from OSV.dev. The results are delivered in a structured, machine-readable format for seamless integration into your workflows.

SSVC-based CVE Evaluator

A tool that leverages the Stakeholder-Specific Vulnerability Categorization (SSVC) framework to assess CVEs, prioritizing them based on exploitation status, technical impact, and stakeholder-specific decision-making criteria for effective risk management.

Software Security Mapping

The Software Security Mapping tool offers an interactive and comprehensive platform to map high-level software security requirements to industry standards such as NIST SSDF, SLSA, OWASP, and more. It allows users to explore relationships between security goals, requirements, and operational practices through a visually rich and intuitive interface.