
scan
0-day malware detection for binaries, source & scripts (that doesn't suck)

0-day malware detection for binaries, source & scripts (that doesn't suck)

Set of tools to assess and improve LLM security.

UNIX-like reverse engineering framework and command-line toolset

Binary Ninja plugin for reverse engineering PTX -- the virtual instruction set architecture of CUDA-based GPUs.

Proof-of-concept exploit for CVE-2025-53367, a vulnerability in the DjVuLibre library. Demonstrates exploitation of a memory corruption bug in DjVu…

A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.

Pluggable linting tool to prevent committing credential.


Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

A set of scripts for a radare-based malware code analysis workflow

A contextual security auditing system for research artifacts

FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis

We've set up an environment to test CVE-2025-57833. This environment was built using AI, so it's subject to ongoing modification.

OWASP Thick Client Application Security Verification Standard

Proof-of-concept for CVE-2023-4863, a heap buffer overflow in WebP image decoding. Demonstrates the code_lengths trigger mechanism discovered by…

Exploit for CVE-2020-35460 targeting MPXJ project management library, enabling arbitrary code execution via crafted project files in Java, .Net, and…


PoC of CVE-2024-33883, RCE vulnerability of ejs.