
smack
Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Toolbox containing research notes & PoC code for weaponizing .NET's DLR


Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

Pishi is a code coverage tool like kcov for macOS.

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

All-in-one tool for managing vulnerability reports from AppSec pipelines

The Web Exploit Detector is a Node.js application used to detect possible infections, malicious code and suspicious files in web hosting environments

Modular framework to detect and prevent dependency confusion attacks by analyzing package manifests across multiple sources and package management…

A scanner that files with compromised or untrusted code signing certificates written in python.

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security,…

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Xyntia, the black-box deobfuscator

Detect exposed API keys on GitHub commits.

Fuzzing Framework for Modules in Apache HTTPD Server