
radare2
UNIX-like reverse engineering framework and command-line toolset

UNIX-like reverse engineering framework and command-line toolset

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

A security focused static analysis tool for Android and Java applications.

Main repo for hosting release binaries

Ghidra is a software reverse engineering (SRE) framework

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Agent skill for Android APK reverse engineering: dex patching, unpacking, repacking, ad and paywall removal, native .so analysis, and runtime…

A native APK and DEX decompiler written in Rust

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Plugin for JADX to integrate MCP server

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

An easy-to-learn/use static analysis framework for Java and Android

Static taint analysis platform for Android apps that detects vulnerabilities and compliance issues using customizable rule-based scanning and…

PoC for CVE-2026-17633 — Authenticated RCE in IBM Langflow OSS 1.0.0–1.10.3 via custom_component endpoint. Includes CVE-2026-17632 AST scanner bypass…

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.