Skip to content
@AppThreat

AppThreat

Empower your devs.

AppThreat

We are a team of passionate application security experts dedicated to developing open-source tools, providing security training, and offering consulting services. Our mission is to make application security accessible to everyone.

🚀 Our Projects

We are proud contributors to several well-known open-source projects:

  • AppThreat atom: An intermediate representation for next-generation application and dependency analysis. 
  • OWASP blint: A binary linter to check executable binaries’ security properties and capabilities.
  • CycloneDX Generator (cdxgen): A CLI tool, library, REPL, and server to create valid and compliant CycloneDX Bill-of-Materials (xBOM) for various programming languages, container images, and operating systems.
  • OWASP dep-scan: A next-generation security and risk audit tool for project dependencies, supporting both local repositories and container images. 

Explore more of our projects on our GitHub repositories. 

🛠️ Our Services

We offer a range of services to help organizations enhance their application security posture: 

  • Custom Application security tools development
  • Architectural review and security assessments 
  • Security training and secure coding workshops 
  • Code analysis workshops for AppThreat
  • Product security risk assessments 

📬 Get in Touch

We’d love to hear from you! Whether you’re interested in our tools, training, or consulting services, feel free to reach out:

Thank you for your interest in AppThreat. Together, let’s make application security accessible for everyone!

Pinned Loading

  1. atom atom Public

    atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.

    Rust 84 6

  2. atom-tools atom-tools Public

    Collection of tools for use with AppThreat/atom.

    Python 5 1

  3. vulnerability-db vulnerability-db Public

    Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers.

    Python 135 24

  4. chen chen Public

    Code Hierarchy Exploration Net (chen)

    Scala 24 3

Repositories

Showing 10 of 51 repositories
  • vuln-list Public

    Linux upstream vulnerabilities data suitable for dep-scan

    AppThreat/vuln-list’s past year of commit activity
    21 Apache-2.0 0 0 0 Updated Feb 5, 2026
  • atom Public

    atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.

    AppThreat/atom’s past year of commit activity
    Rust 84 MIT 6 39 (3 issues need help) 0 Updated Feb 4, 2026
  • vulnerability-db Public

    Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers.

    AppThreat/vulnerability-db’s past year of commit activity
    Python 135 MIT 24 34 (2 issues need help) 0 Updated Feb 3, 2026
  • caxa Public

    Package Node.js applications into executable binaries.

    AppThreat/caxa’s past year of commit activity
    JavaScript 9 MIT 0 1 0 Updated Feb 3, 2026
  • atom-samples Public

    Collection of atom, data-flow, and usage slices for appthreat/atom https://github.com/appthreat/atom.

    AppThreat/atom-samples’s past year of commit activity
    Python 3 Apache-2.0 2 1 0 Updated Feb 3, 2026
  • atom-parsetools Public

    Parsing tools that complement the @appthreat/atom project.

    AppThreat/atom-parsetools’s past year of commit activity
    JavaScript 0 MIT 0 0 0 Updated Feb 2, 2026
  • ruby_ast_gen Public

    A Ruby AST generator tool

    AppThreat/ruby_ast_gen’s past year of commit activity
    Ruby 1 Apache-2.0 0 0 0 Updated Jan 31, 2026
  • chen Public

    Code Hierarchy Exploration Net (chen)

    AppThreat/chen’s past year of commit activity
    Scala 24 Apache-2.0 3 22 (1 issue needs help) 0 Updated Jan 28, 2026
  • cdx-proto Public

    Runtime library to serialize/deserialize CycloneDX BOM with protocol buffers

    AppThreat/cdx-proto’s past year of commit activity
    TypeScript 0 Apache-2.0 0 0 0 Updated Jan 28, 2026
  • vuln-list-update Public

    Collects vulnerability data from a range of sources.

    AppThreat/vuln-list-update’s past year of commit activity
    Go 0 Apache-2.0 0 0 0 Updated Jan 27, 2026