
xpfarm
Automated bug bounty & recon framework — wraps Subfinder, Naabu, Httpx, Nuclei, Nmap, CVEMap, Gowitness, Katana & more behind a unified web UI

Automated bug bounty & recon framework — wraps Subfinder, Naabu, Httpx, Nuclei, Nmap, CVEMap, Gowitness, Katana & more behind a unified web UI

Reverse engineering the BYD Dolphin head unit — CAN bus, AVAS, NFC keys, OTA, and more. DiLink 3 / Android 10.

Main repo for hosting release binaries

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Security profiling for blackbox iOS

Free XP on bug bounty, vulnerability scanning by wrapping well maintained tools, to perform automated tests. Alongside AI agents for binary analysis,…

iOS Syscall Explorer for IDA 9.X

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

A generic game/software hacking tool written from the ground up in Rust.

autonomous red teaming platform; multi-agent offensive-security meta-harness

PoC Frida script to view Android libbinder traffic

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection