
lightkeeper
Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Xyntia, the black-box deobfuscator

Pishi is a code coverage tool like kcov for macOS.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Fuzzing Framework for Modules in Apache HTTPD Server

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)

CVE-2025-60374: Stored Cross-Site Scripting (XSS) in Perfex CRM Chatbot

Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)

ngxray — nginx config security scanner

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Application Security Verification Standard

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

A vulnerable version of Rails that follows the OWASP Top 10

CVE-2026-42533 Nginx

OWASP Thick Client Application Security Verification Standard

Toolbox containing research notes & PoC code for weaponizing .NET's DLR