
tooling-playground
A collection of small scripts and tools for deobfuscation and malware analysis.

A collection of small scripts and tools for deobfuscation and malware analysis.

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Collection of Offensive C# Tooling

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Bash script to detect CVE-2025-55182 (React2Shell) and credential exposure in Next.js projects. Zero dependencies.


Fast filesystem scanner for CVE-2021-44228

Scanners for Jar files that may be vulnerable to CVE-2021-44228

Collection of some easy of use tools - in powershell.

Fast and accurate AI powered file content types detection

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A collection of my Semgrep rules to facilitate vulnerability research.

Collection of different ways to execute code outside of the expected entry points