
gf
A wrapper around grep, to help you grep for things

A wrapper around grep, to help you grep for things

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Black-box deobfuscator synthesizing semantics of obfuscated binary code via program synthesis, execution sampling, grammar search, and inference…

Static binary rewriter that instruments XNU kernel and kexts, enabling targeted function/file-level coverage and feedback-aware fuzzing for macOS…

Fuzzing Framework for Modules in Apache HTTPD Server

Reproducer for CVE-2026-49042: demonstrates prompt injection in Apache Camel's langchain4j-tools leading to RCE via unfiltered Exchange headers.…

PoC reproducer for CVE-2026-53913 demonstrating a fail-open authentication bypass in Apache Camel's camel-keycloak, leading to unauthenticated RCE…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Reproducer for CVE-2026-46455 demonstrating Apache Camel camel-keycloak authentication bypass via missing TokenVerifier.IS_ACTIVE check, allowing…

Automatic SSTI detection tool with interactive interface

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

Laravel debug mode - Remote Code Execution (RCE)

Admission control and runtime guardrails for agentic AI. Scans skills, MCP servers, plugins, and code before execution; inspects prompts,…

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…