
dynamorio
Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Open source binary analysis framework and decompiler built on LLVM and QEMU, lifting binaries to a readable intermediate representation for reverse…

Adversarial image attacks on vision-language web agents, from visual grounding to browser execution


Python framework for building LLM workflows as state machines with formal verification via Z3 theorem proving, CTL model checking, and conformal…

MCP-enabled multi-agent framework for declarative YAML-driven agentic workflows, used for AI-assisted code auditing, vulnerability triage, and…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Code deobfuscation framework to simplify Mixed Boolean-Arithmetic (MBA) expressions

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Rust macros and Cargo subcommand to automate fuzzing with afl.rs, including corpus generation and harness implementation, integrated with Rust's…

An easy-to-learn/use static analysis framework for Java and Android

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

Qiskit-based resource estimation framework for space-efficient quantum modular inversion and affine point-addition circuits used in elliptic-curve…

Agentic Framework for Synthesizing CodeQL Queries

Static Analyzer for Solidity and Vyper

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

AST-based Python code transformation & deobfuscation framework

Spring Framework CVE-2022-22965 本地影响条件验证、版本升级修复与复测项目