
defenseclaw
Admission control and runtime guardrails for agentic AI. Scans skills, MCP servers, plugins, and code before execution; inspects prompts,…

Admission control and runtime guardrails for agentic AI. Scans skills, MCP servers, plugins, and code before execution; inspects prompts,…

Static binary rewriter that instruments XNU kernel and kexts, enabling targeted function/file-level coverage and feedback-aware fuzzing for macOS…

Reproducer for CVE-2026-49042: demonstrates prompt injection in Apache Camel's langchain4j-tools leading to RCE via unfiltered Exchange headers.…

Reproducer for CVE-2026-46455 demonstrating Apache Camel camel-keycloak authentication bypass via missing TokenVerifier.IS_ACTIVE check, allowing…

PoC reproducer for CVE-2026-53913 demonstrating a fail-open authentication bypass in Apache Camel's camel-keycloak, leading to unauthenticated RCE…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Fuzzing Framework for Modules in Apache HTTPD Server

Automatic SSTI detection tool with interactive interface

Black-box deobfuscator synthesizing semantics of obfuscated binary code via program synthesis, execution sampling, grammar search, and inference…

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

A wrapper around grep, to help you grep for things

Laravel debug mode - Remote Code Execution (RCE)

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Exploit for Jenkins serialization vulnerability - CVE-2016-0792