
secretlint
Pluggable linting tool to prevent committing credential.

Pluggable linting tool to prevent committing credential.

A tool for generating fake code signing certificates or signing real ones

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

VisualCodeGrepper - Code security scanning tool.

Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.

This is the main repository for metasm, a free assembler / disassembler / compiler written in ruby

Burp Suite JS Beautifier

Regex-based scanner for detecting hard-coded credentials in codebases, designed for CI/CD integration with suppression comment support and low…


Java bytecode analyzer customizable via JSON rules

Hunt for AI coding artifacts containing secrets.

Pre-execution intent verification for AI agents. Audits what your AI is about to do, not what it says. Zero dependencies, deterministic, hash-sealed.

Detect and fix log4j log4shell vulnerability (CVE-2021-44228)

Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.

Mautic < 5.2.3 Authenticated RCE

Proof-of-concept exploit for CVE-2023-46694: authenticated remote code execution via arbitrary file upload in Vtenext 21.02 Ckeditor file manager.

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall