
capa
Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

agent runtime security - zero trust, zero setup, zero latency micro sandboxes

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

My experiments in weaponizing Nim (https://nim-lang.org/)

Plugin for JADX to integrate MCP server

Mind-Maps of Several Things

Source code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards…

A wrapper around grep, to help you grep for things

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Collection of Offensive C# Tooling

More than a ReClass port to the .NET platform.

Extract URLs, paths, secrets, and other interesting bits from JavaScript

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

A tool to capture all the git secrets by leveraging multiple open source git searching tools

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Run PowerShell with rundll32. Bypass software restrictions.

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.