Abstract
Sighthound is an open-source Cybersecurity & Ethical Hacking project. Corgea's rule-based SAST scanner. Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis. It is built using Rust, Go, Java, JavaScript, PHP. Key capabilities include: Scans source code for security issues using AST-aware rules; Supports pattern mode and taint mode (source to sink tracking); Handles multi-file projects and parallel execution. The complete source code is publicly available on GitHub under the MIT License, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis.
Not currently supported: Razor (.cshtml), C/C++ (.c, .h).
and performs no dataflow or taint analysis on SQL, so rules match against the whole file rather than against parsed statements.
2. Objective
Corgea's rule-based SAST scanner
This project demonstrates how Rust, Go, Java can be applied to a real-world Cybersecurity & Ethical Hacking problem.
3. Key Features / Modules
- Scans source code for security issues using AST-aware rules.
- Supports pattern mode and taint mode (source to sink tracking).
- Handles multi-file projects and parallel execution.
- Outputs findings as text, JSON, CSV, or SARIF.
- Loads embedded rule packs by file extension, with optional file-based custom rules.
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Rust toolchain (rustup / cargo)
- Go 1.20 or later
- JDK 11 or later
- Maven / Gradle
- IntelliJ IDEA, Eclipse or Android Studio
- Node.js (LTS) and npm
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/Corgea/Sighthound.git
cd Sighthound- Rust 1.88+
git clone https://github.com/Corgea/Sighthound.git
cd Sighthound
cargo build --releaseDOCKER_BUILDKIT=1 docker build \
--target export \
--output type=local,dest=./sighthound_release \
.# Auto-detect languages and run embedded rules
cargo run --bin sighthound -- /path/to/project
# Explicit language + custom rules path
cargo run --bin sighthound -- /path/to/project python rules/python
# Taint-only scan and JSON output
cargo run --bin sighthound -- --taint-analysis --output-format json /path/to/project > findings.json
# SARIF output for GitHub Code Scanning
cargo run --bin sighthound -- --output-format sarif /path/to/project > results.sarifsighthound [OPTIONS] <ROOT_DIR> [LANGUAGE] [RULES_PATH]Full setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by Corgea and published on GitHub under the MIT License. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship