
frida
Main repo for hosting release binaries

Main repo for hosting release binaries

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

UNIX-like reverse engineering framework and command-line toolset

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Ghidra is a software reverse engineering (SRE) framework

A security focused static analysis tool for Android and Java applications.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

pluck-CMS-4.7.20-code-injection-vulnerability

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Proof-of-concept exploit for CVE-2025-3248, an unauthenticated remote code execution vulnerability in Langflow, demonstrating code injection via the…

Django application that performs SAST and Malware Analysis for Android APKs

An easy-to-learn/use static analysis framework for Java and Android

Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.

Automatic SSTI detection tool with interactive interface

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Proof-of-concept exploit for CVE-2026-19626, an authenticated remote code execution in SecurityCenter report generation, demonstrating a non-admin…

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.