
security-audit-skill
A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Automatic SSTI detection tool with interactive interface

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

A vulnerable version of Rails that follows the OWASP Top 10

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Xyntia, the black-box deobfuscator

Pishi is a code coverage tool like kcov for macOS.


Exploit for Jenkins serialization vulnerability - CVE-2016-0792

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Fuzzing Framework for Modules in Apache HTTPD Server


A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.