Git Product home page Git Product logo

tmnc / threadfix Goto Github PK

View Code? Open in Web Editor NEW

This project forked from denimgroup/threadfix

0.0 1.0 0.0 149.49 MB

ThreadFix is a software vulnerability aggregation and management system that helps organizations aggregate vulnerability data, generate virtual patches, and interact with software defect tracking systems.

License: Other

Shell 0.11% Java 84.71% JavaScript 11.46% Python 0.39% C# 1.64% ASP 0.19% Ruby 0.42% CSS 0.71% PHP 0.33% HTML 0.02% Batchfile 0.03%

threadfix's Introduction

NOTE: If you wish to download the latest build of ThreadFix please visit the ThreadFix download page. Please DO NOT use the "Download ZIP" function from GitHub. If you DO use the "Download ZIP" function from GitHub you will just get a dump of the source code, but no ready-to-run Tomcat webserver and other facilities that make it really easy to get up and running with ThreadFix quickly. The normal ThreadFix download build comes pre-packaged and ready-to-run and is the preferred way to start using ThreadFix. You can set up your own development environment but it is advised that first time users start with the pre-packaged build.

ThreadFix is a software vulnerability aggregation and management system that reduces the time it takes to fix software vulnerabilities. ThreadFix imports the results from dynamic, static and manual testing to provide a centralized view of software security defects across development teams and applications. The system allows companies to correlate testing results and streamline software remediation efforts by simplifying feeds to software issue trackers. By auto generating application firewall rules, this tool allows organizations to continue remediation work uninterrupted. ThreadFix empowers managers with vulnerability trending reports that show progress over time, giving them justification for their efforts.

ThreadFix is licensed under the Mozilla Public License (MPL) version 2.0.

The main GitHub site for ThreadFix can be found here:

https://github.com/denimgroup/threadfix/

The Google Group for ThreadFix can be found here:

https://groups.google.com/forum/#!forum/threadfix

Instructions on setting up a development environment can be found here:

https://github.com/denimgroup/threadfix/wiki/Development-Environment-Setup

Further documentation can be found online here:

https://github.com/denimgroup/threadfix/wiki

Submit bugs to the GitHub issue tracker:

https://github.com/denimgroup/threadfix/issues

ThreadFix is a platform with a number of components. Each subdirectory should have its own pom.xml files to support Maven builds. The major components in the repository include:

  • threadfix-cli-endpoints - Command-line utility to calculate the attack surface of an application and print it to standard output. This relies on the Hybrid Analysis Mapping (HAM) capabilities in the threadfix-ham/ component.
  • theadfix-cli - Command-line client for ThreadFix. This allows for scripting and automation of the ThreadFix platform.
  • threadfix-extras - Experimental tools and ThreadFix proof-of-concept projects.
  • threadfix-ham - Hybrid Analysis Mapping (HAM) technology used in ThreadFix that performs lightweight static analysis of application source code to calculate attack surfaces and map application attack surface endpoints to source code locations.
  • threadfix-ide-plugin - IDE plugins for Eclipse and IntelliJ that pulls vulnerability data from ThreadFix and highlights these vulnerabilities in application source code.
  • threadfix-main - Main ThreadFix server application. This is a Java-based Spring/Hibernate web application with associated web services. Other components of the ThreadFix platform call into the ThreadFix server.
  • threadfix-scanner-plugin - Scanner plugins that can connect to a ThreadFix server and import an application's attack surface to improve the thoroughness of dynamic scanning. Also allows for exporting scan results directly into ThreadFix (rather than saving files and uploading them.)
  • threadfix-update - Update scripts to upgrade the ThreadFix server database between versions.

threadfix's People

Contributors

bgarcia6811 avatar bobrich avatar d-maldonado avatar dancornell avatar daryl-shannon avatar dg-jfessler avatar dg-mhatz avatar dharrison13 avatar gmlewis avatar jblow avatar johnbeoris avatar macacollins avatar maryamghani avatar rtimmonsdg avatar skakani avatar zabdisubhan avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.