
CVE-2025-43504
Technical deep-dive into CVE-2025-43504, a remote pre-authentication global buffer overflow in LLDB's debugserver for iOS, with PoC code and…

Technical deep-dive into CVE-2025-43504, a remote pre-authentication global buffer overflow in LLDB's debugserver for iOS, with PoC code and…

Datalog-based disassembler producing reassemblable assembly from ELF/PE binaries, with GTIRB intermediate representation for binary analysis and…

Command-line and GUI tool for decompiling Android Dex and APK files into readable Java source code, with resource decoding, deobfuscation, and Smali…

Step-by-step exploit analysis of WhatsApp's CVE-2019-11932 double-free vulnerability using GEF-GDB debugger for dynamic debugging and arbitrary code…

PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"

An Interactive Binary Patching Plugin for IDA Pro

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Injectable real-mode x86 debugger for BIOS reverse engineering and arbitrary real-mode code debugging via serial cable, with GDB integration and…

N-gram-based type recovery tool for binaries, recovering structures and function signatures from decompiled code with high throughput and actionable…

PoC for CVE-2022-21974 "Roaming Security Rights Management Services Remote Code Execution Vulnerability"

Linux kernel 4.1.15 source code with a focus on CVE-2022-45934, providing a reference for vulnerability analysis and exploitation research.

A game modding utility that makes injecting C/C++ code easier.

SWD debug probe library for RP2350 RISC-V cores. Provides halt/resume/step, register and memory access, code execution, and instruction tracing over…

Exploitation script for exposed Java Debug Wire Protocol (JDWP) services, enabling pentesters to inject Java code and execute arbitrary OS commands…

Proof-of-concept exploit for CVE-2025-49844 targeting a Redis heap vulnerability, with GDB-assisted crash analysis and fuzzing attempts to achieve…

In-depth technical analysis and proof-of-concept for CVE-2017-9822, an insecure deserialization vulnerability in DotNetNuke leading to remote code…

Technical notes and debugger analysis for CVE-2014-4140, a use-after-free vulnerability in MSHTML's CHtmRootParseCtx::AddText leading to remote code…