
Curveball
PoC for CVE-2020-0601 - CryptoAPI exploit

PoC for CVE-2020-0601 - CryptoAPI exploit

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall

Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and…

WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)

Static Decryptor for IcedID Malware

Config Extractor for Asyncrat/Dcrat/VenomRat

Bithoven is a smart contract language for composing powerful and secure instruments on Bitcoin. LR(1) parser with static analysis for compile-time…

Paranoid's library contains implementations of checks for well known weaknesses on cryptographic artifacts.

ROCA: Infineon RSA key vulnerability

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Formalizing np1sec using Tamarin and other FM (see https://github.com/equalitie/np1sec)

Reimplementation of CVE-2017-15361 checker in C

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

Trail of Bits Testing Handbook - appsec.guide

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Project Wycheproof tests crypto libraries against known attacks.

Coefficient-Based Reconstruction of Arithmetic — a Mixed Boolean-Arithmetic (MBA) expression simplifier for deobfuscation

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…