
RansomCoinPublic
A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Neto | A tool to analyse browser extensions

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

Data exfiltration and covert communication tool


A tool to decrypt all Synology encrypted archives (SPK, PAT, ...)

Research tool for studying vulnerable cryptographic key generation (brainwallet, PRNG, milksad, LCG, xorshift)

This tool generates BIP-39 mnemonic phrases derived from Unix timestamps, exploring the 'Milk Sad' vulnerability's implications (CVE-2023-39910)

A tool to check if your lnd node was targeted by CVE-2019-12999

Hash database builder and reverse lookup tool — SHA256, RIPEMD160, Keccak256, BLAKE3 and more

Proof-of-concept local privilege escalation tool exploiting a kernel XFRM/ESP vulnerability (CVE-2026-43503) via crafted AES-CBC encrypted payloads…

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

CLI tool to scan codebases for quantum-vulnerable cryptography

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

eWeLinkESPT is a tool that automatically decodes and decrypts the WiFi network credentials transmitted to a supported ESP-based IoT device by the…

CLI Encryption tool written in Go

A tool for decrypting Ivanti device initrd images by reverse-engineering the kernel's bzImage to locate and use the embedded AES key.

Tool to check whether a PGP client is affected by CVE-2021-33560