
reverse-engineering-browser
Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

0-day malware detection for binaries, source & scripts (that doesn't suck)

An LLM-driven fuzzing pipeline powered by the GitHub Security Lab Taskflow Agent

A native APK and DEX decompiler written in Rust

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

Agent-native CLI wrapping IDA Pro IDALib for stateless, JSON-output binary analysis: disassembly, Hex-Rays decompilation, CFG, xrefs, strings, and…

Fix-Like Artifacts With Embedded Defects

C++ reimplementation of Ghidra's analytical core without JVM dependencies, providing embeddable binary analysis, Pcode/Sleigh foundations, and…

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

LuaJIT FFI bindings for libinjection, providing SQL injection and XSS detection with context-specific APIs for web application security.

Proof-of-concept for CVE-2026-29628, a stack-based buffer overflow in tinyobjloader's experimental parser, with ASan/UBSan reproduction and fix…

Proof-of-concept for CVE-2025-52099, an integer overflow in SQLite 3.50.0's setupLookaside function leading to heap-buffer-overflow.

Axios CRLF Injection (CVE-2026-40175) 취약점 대응 가이드 및 fetch 기반 마이그레이션 분석

Rust macros and Cargo subcommand to automate fuzzing with afl.rs, including corpus generation and harness implementation, integrated with Rust's…

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

A wrapper around grep, to help you grep for things

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…