
SafeLine
Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…
Tools for analyzing application behavior during runtime to find security vulnerabilities.

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

The repo contains a series of challenges for learning Frida for Android Exploitation.

Differential testing framework for HTTP implementations

Inject code into running Python processes

LLM powered fuzzing via OSS-Fuzz.

Automatic SSTI detection tool with interactive interface

Sample extensions, scripts, and API uses for WinDbg.

An Interactive Binary Patching Plugin for IDA Pro

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

Tool for reverse engineering macOS/OS X

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

An strace-like program for the Windows 'native' API

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

Scriptable debugger for Android Dalvik VM using JDWP/DDM interfaces to hook methods, inspect process state, and modify runtime behavior without…

x64 Dynamic Reverse Engineering Toolkit