daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

source-code-analysis.md (6068B)


      1 ---
      2 title: "Source Code Analysis"
      3 section: "Methodology"
      4 sectionSlug: "methodology"
      5 sourcePath: "docs/methodology/source-code-analysis.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/methodology/source-code-analysis.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Source Code Analysis
     12 
     13 > Source code analysis is the process of examining and reviewing the code of a software program to identify errors, vulnerabilities, and potential improvements. This can be performed manually by developers or through automated tools that scan the code for issues like security risks, coding standard violations, and performance inefficiencies.
     14 
     15 ## AI Analysis
     16 
     17 * [trailofbits/skills](https://github.com/trailofbits/skills) - Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows.
     18 
     19 ```ps1
     20 npm install -g @github/copilot
     21 copilot
     22 /login
     23 /model
     24 /plugin marketplace add trailofbits/skills
     25 /plugin marketplace browse trailofbits
     26 /plugin install ask-questions-if-underspecified@trailofbits
     27 /plugin install static-analysis@trailofbits
     28 /plugin install entry-point-analyzer@trailofbits
     29 /plugin install semgrep-rule-creator@trailofbits
     30 /plugin install semgrep-rule-variant-creator@trailofbits
     31 /plugin install sharp-edges@trailofbits
     32 /plugin install insecure-defaults@trailofbits
     33 ```
     34 
     35 ## Semgrep
     36 
     37 > Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
     38 
     39 **Install**:
     40 
     41 * Binaries: [opengrep/opengrep](https://github.com/opengrep/opengrep) / [semgrep/semgrep](https://github.com/semgrep/semgrep)
     42 * Ubuntu/WSL/Linux/macOS: `python3 -m pip install semgrep`
     43 * macOS: `brew install semgrep`
     44 * Docker
     45 
     46     ```ps1
     47     docker run -it -v "${PWD}:/src" semgrep/semgrep semgrep login
     48     docker run -e SEMGREP_APP_TOKEN=<TOKEN> --rm -v "${PWD}:/src" semgrep/semgrep semgrep ci
     49     ```
     50 
     51 **Semgrep rules**:
     52 
     53 * [semgrep/semgrep-rules](https://github.com/semgrep/semgrep-rules) - Official Semgrep rules registry
     54 * [trailofbits/semgrep-rules](https://github.com/trailofbits/semgrep-rules) - Semgrep queries developed by Trail of Bits
     55 * [Decurity/semgrep-smart-contracts)](https://github.com/Decurity/semgrep-smart-contracts) - Semgrep rules for smart contracts based on DeFi exploits
     56 * [0xdea/semgrep-rules](https://github.com/0xdea/semgrep-rules) - A collection of Semgrep rules to facilitate vulnerability research.
     57 * [elttam/semgrep-rules](https://github.com/elttam/semgrep-rules) - Elttam's public semgrep rules repository.
     58 
     59 **Other Tools**:
     60 
     61 * [Orange-Cyberdefense/grepmarx](https://github.com/Orange-Cyberdefense/grepmarx) - A source code static analysis platform for AppSec enthusiasts, based on semgrep engine.
     62 
     63 ## SonarQube
     64 
     65 > Continuous Inspection
     66 
     67 **Install**
     68 
     69 * Docker
     70 
     71     ```ps1
     72     docker run -d --name sonarqube -p 9000:9000 sonarqube:community
     73     ```
     74 
     75 **Configuration**
     76 
     77 * Go to localhost:9000
     78 * Login with `admin:admin`
     79 * Create a local project
     80 * Generate a token for the project
     81 * Use `sonar-scanner-cli` with the generated token
     82 
     83     ```ps1
     84     docker run --rm -e SONAR_HOST_URL="http://10.10.10.10:9000" -v "/tmp/www:/usr/src" sonarsource/sonar-scanner-cli -Dsonar.projectKey=sonar-project-name -Dsonar.sources=. -Dsonar.host.url=http://10.10.10.10:9000 -Dsonar.token=sqp_redacted
     85     ```
     86 
     87 * Check the Security Hotspots tab: `http://10.10.10.10:9000/security_hotspots?id=sonar-project-name`
     88 
     89 :warning: remove dead symbolic links before scanning a folder.
     90 
     91 ## Psalm
     92 
     93 > A static analysis tool for finding errors in PHP applications
     94 
     95 **Install**
     96 
     97 ```ps1
     98 composer require --dev vimeo/psalm
     99 ```
    100 
    101 **Configuration**
    102 
    103 * Create a project and initiate a scan of the codebase
    104 
    105     ```ps1
    106     ./vendor/bin/psalm --init
    107     ./vendor/bin/psalm --taint-analysis
    108     ./vendor/bin/psalm --report=results.sarif
    109     ```
    110 
    111 * Use a Sarif viewer to see the results: [microsoft.github.io/sarif-web-component](https://microsoft.github.io/sarif-web-component/)
    112 
    113 ## CodeQL
    114 
    115 > CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
    116 
    117 **Install**:
    118 
    119 * [github/codeql](https://github.com/github/codeql)
    120 
    121 **Configuration**
    122 
    123 ```ps1
    124 codeql resolve packs
    125 codeql resolve languages
    126 codeql database create <database> --language=<language-identifier>
    127 codeql database create --language=python <output-folder>/python-database
    128 codeql database create --language=cpp <output-folder>/cpp-database
    129 codeql database analyze <database> --format=<format> --output=<output> <query-specifiers>...
    130 codeql database analyze /codeql-dbs/example-repo javascript-code-scanning.qls --sarif-category=javascript-typescript  --format=sarif-latest --output=/temp/example-repo-js.sarif
    131 codeql database analyze <database> microsoft/coding-standards@1.0.0 github/security-queries --format=sarifv2.1.0 --output=query-results.sarif --download
    132 ```
    133 
    134 ## Snyk
    135 
    136 > Snyk CLI scans and monitors your projects for security vulnerabilities.
    137 
    138 **Install**
    139 
    140 * [Snyk Security - Visual Studio](https://marketplace.visualstudio.com/items?itemName=snyk-security.snyk-vulnerability-scanner-vs)
    141 * [Snyk Code / Snyk Open Source](https://app.snyk.io)
    142 
    143     ```ps1
    144     curl https://static.snyk.io/cli/latest/snyk-linux -o snyk
    145     chmod +x ./snyk
    146     mv ./snyk /usr/local/bin/ 
    147 
    148     docker run -it \
    149         -e "SNYK_TOKEN=<TOKEN>" \
    150         -v "<PROJECT_DIRECTORY>:/project" \
    151         -v "/home/user/.gradle:/home/node/.gradle" \
    152     snyk/snyk:gradle:6.4 test --org=my-org-name
    153     ```
    154 
    155 **Configuration**
    156 
    157 ```ps1
    158 snyk auth
    159 snyk ignore --file-path=<directory_or_file>
    160 snyk code test
    161 
    162 # npm install snyk-to-html -g
    163 snyk code test --json | snyk-to-html -o results-opensource.html
    164 ```
    165 
    166 ## References
    167 
    168 * [Code auditing 101 - Rodolphe Ghio - August 2, 2025](https://blog.rodolpheg.xyz/posts/code-auditing--101/)
    169 * [Detect PHP security vulnerabilities with Psalm - Matt Brown - June 23, 2020](https://psalm.dev/articles/detect-security-vulnerabilities-with-psalm)
    170 * [Security Analysis in Psalm - Official Documentation](https://psalm.dev/docs/security_analysis/)