
radare2
UNIX-like reverse engineering framework and command-line toolset

UNIX-like reverse engineering framework and command-line toolset

Set of tools to assess and improve LLM security.

Pluggable linting tool to prevent committing credential.

0-day malware detection for binaries, source & scripts (that doesn't suck)

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.

A contextual security auditing system for research artifacts

Pivotal CRM's patch for an initial deserialization vulnerability was incomplete. The fix switched from BinaryFormatter to JSON.NET but left…

OWASP Thick Client Application Security Verification Standard

Binary Ninja plugin for reverse engineering PTX -- the virtual instruction set architecture of CUDA-based GPUs.

We've set up an environment to test CVE-2025-57833. This environment was built using AI, so it's subject to ongoing modification.

Exploit for CVE-2020-35460 targeting MPXJ project management library, enabling arbitrary code execution via crafted project files in Java, .Net, and…

Proof-of-concept exploit for CVE-2025-53367, a vulnerability in the DjVuLibre library. Demonstrates exploitation of a memory corruption bug in DjVu…

FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis

PoC of CVE-2024-33883, RCE vulnerability of ejs.

Proof-of-concept for CVE-2023-4863, a heap buffer overflow in WebP image decoding. Demonstrates the code_lengths trigger mechanism discovered by…