
tiny_tracer
Intel Pin-based tracer for API calls, syscalls, and instructions with anti-debug evasion, used for malware analysis and reverse engineering of packed…

Intel Pin-based tracer for API calls, syscalls, and instructions with anti-debug evasion, used for malware analysis and reverse engineering of packed…

a PE Loader and Windows API tracer. Useful in malware analysis.

Verdict-as-a-Service SDKs: Analyze files for malicious content

CLI client for bulk DIARIO API consumption: upload PDF/Office documents, query file hashes, and automate malware analysis workflows via command-line…

A script that automatically submits files to Hybrid Analysis (API)

ClamAV antivirus scanning for Node.js — scan file uploads with a single function call. Zero dependencies. Typed Symbol verdicts. Local or…


An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

Automagically reverse-engineer REST APIs via capturing traffic

A secure low code deception runtime framework, leveraging AI for System Virtualization.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

A reverse proxy like nginx, built on pingora, simple and efficient.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.