


Xyntia, the black-box deobfuscator

Pishi is a code coverage tool like kcov for macOS.

Fuzzing Framework for Modules in Apache HTTPD Server

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

A vulnerable version of Rails that follows the OWASP Top 10

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Markdown XSS leads to RCE in VNote version <=3.18.1






Seal Security example — vulnerable npm app (EJS CVE-2022-29078) remediated to sealed versions; GitHub Actions + Jenkins integration

Seal Security example — vulnerable Maven app (SnakeYAML CVE-2022-1471) remediated to sealed versions; GitHub Actions + Jenkins integration

cve-2025-4615 poc & deep dive

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.