
DOMPurify
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Bleach is an allowed-list-based HTML sanitizing library that escapes or strips markup and attributes


Macro-header for compile-time C obfuscation (tcc, win x86/x64)

Run PowerShell with rundll32. Bypass software restrictions.

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Spartacus DLL/COM Hijacking Toolkit

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

PowerShell Obfuscation Detection Framework

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

👮 👊 RegEx Denial of Service (ReDos) Scanner

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会