
CyberChef
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

Cryptographic and general-purpose routines for Secure Systems Lab projects at NYU

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

Automated steganalysis platform that detects hidden data in images using 16 parallel analyzers, bit-layer visualization, and an in-app wiki for CTF…

Web interface to change and reset password in an LDAP directory

Testing TLS/SSL encryption anywhere on any port

Pre-execution intent verification for AI agents. Audits what your AI is about to do, not what it says. Zero dependencies, deterministic, hash-sealed.

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Implementation of the Google Zero-Knowledge library for Identity Protocols.

Cryptographically signed, replay-verifiable evidence layer for AI agents. Governs actions in the loop, produces Ed25519-signed receipts linked into a…

Some setup scripts for security research tools.

Technical analysis and PoC of CVE-2026-52824: default APP_SECRET in the Kimai Docker image enabling unauthenticated login link forgery. Affects <=…

Real-time crypto intelligence platform for token scanning, wallet forensics, multi-chain market data, and scam detection across 96 blockchains via a…

PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

Passive OSINT triage console for email, username, domain, IP, and crypto wallet reconnaissance. Features case management, curated resource links, and…

Live cryptojacking toolkit with CVE-2026-31431 LPE exploit, container escape, kernel rootkit, and XMRig Monero miner, captured from real attacks for…