
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Exploit for Drupal CVE-2018-7602 remote code execution vulnerability via double URL encoding bypass of sanitize() filter. Includes Docker-based lab…

Automatic SSTI detection tool with interactive interface

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

CVE-2025-31324, SAP Exploit

CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44294, CVE-2026-44295 - protobuf.js

Automated testing suite with live traffic record and replay

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…

Executable security regression testing for agentic applications and MCP-integrated systems.

SSLPinDetect is a tool for analyzing Android APKs to detect SSL pinning implementations by scanning for known patterns in decompiled code. It helps…

Exploit code for CVE-2023-40127, a vulnerability in Android MediaProvider, demonstrating the flaw for security research and testing.

Ghidra is a software reverse engineering (SRE) framework

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

UNIX-like reverse engineering framework and command-line toolset

Main repo for hosting release binaries

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Plugin for JADX to integrate MCP server