Alternatives
Products that do what Offensive360 does
SAST + DAST + SCA + Malware analysis — one platform, offline
- 1

- 2

- 3

- 4

- 5BO
Hi HN, we’re the co-founders of Bearer, and today we launch an open-source alternative to code security solutions such as Snyk Code, SonarQube, or Checkmarx. Essentially, we help security & engineering teams to discover, filter and prioritize security risks and vulnerabilities in their codebase, with a unique approach through sensitive data (PII, PD, PHI). Our website is at https://www.bearer.com and our GitHub is here: https://github.com/bearer/bearer We are not originally Security experts but have been software developers and engineering leaders for over 15…
2023
- 6

- 7

- 8

- 9

- 10

Turn codebases into interactive maps, graphs, and governance
Jul 2026 · dev-swat.com
- 11IA
I'm building Incidental, an open-source (MIT license) incident management platform. I've been working on it for the past couple of months as a hobby, and now it's at a state where I'm comfortable sharing it. This is also my first open source project. Features: - Custom roles - Custom severities - Integrated with Slack - Web interface Todos: - Custom fields - Custom workflows Website: https://incidental.dev Github: https://github.com/incidentalhq/incidental I'd love to hear your feedback. Thanks!
2024 · github.com
- 12

- 13

- 14

- 15

- 16BG
We originally set out to solve complex debugging headaches and useless alerts caused by traditional security scanners in our own projects. Static Analysis (SAST) flagged too much noise because it couldn't verify runtime context, while Dynamic Analysis (DAST) missed internal logic bugs because it treated the app like a black box. We built a CLI tool to bridge this gap using grey box testing from a red team approach. We use internal knowledge of the codebase to guide parallel execution, allowing us to find complex or hidden logic errors and attack paths standard linters/scanners miss. The…
Dec 2025 · bloodhoundsecurity.ca
- 17

- 18IB
I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…
2025 · github.com
- 19

Highest Fidelity F1 Score Hybrid Engine, Language Agnostic
Jun 2026 · checkmarx.com
- 20AR
Hi HN, I built this open-source LLM red teaming tool based on my experience scaling LLMs at a big co to millions of users... and seeing all the bad things people did. How it works: - Uses an unaligned model to create toxic inputs - Runs these inputs through your app using different techniques: raw, prompt injection, and a chain-of-thought jailbreak that tries to re-frame the request to trick the LLM. - Probes a bunch of other failure cases (e.g. will your customer support bot recommend a competitor? Does it think it can process a refund when it can't? Will it leak your user's address?) -…
2024 · promptfoo.dev
- 21

- 22WV
Honeytoken technology is becoming more and more important in the world of supply chain security. SaaS-Sentinel is an alerting platform based on this technology to notify subscribers when a honeytoken planted in a SaaS provider was triggered. This is the story of the project.
2023 · blog.gitguardian.com
- 23

- 24

Ranked by how close each launch is in meaning, then by votes. Refine with a description →