
BurpIA
Extensión de Burp Suite que incorpora detección pasiva de vulnerabilidades mediante inteligencia artificial.

Extensión de Burp Suite que incorpora detección pasiva de vulnerabilidades mediante inteligencia artificial.

UAC bypass PoC abusing the UIAccess QuickAssist binary to load an attacker-controlled DLL via WebView2 BrowserExecutableFolder, then hijack elevated…

Android Chromium fork with built-in ad blocking, anti-fingerprinting mitigations, DNS-over-HTTPS, and hardened privacy and security defaults.

Privacy and security hardened Chromium build providing the WebView and default browser for GrapheneOS, with OS-level hardening and compatibility…

Defender framework for LLM agent security that compiles task contracts, validates capability manifests, and checks effects via PLANT/WRAP proof…

Open-source detection engineering tool that traces security detections end to end and identifies the first failing stage.

Burp Suite extension that extends active and passive scanning with checks for host header attacks, XXE, expression language injection, shellshock and…

Burp plugin that clusters responses to show an overview of received responses

Burp Suite extension that extends active and passive scanning with checks for host header attacks, XXE, code injection, and known CVEs like…

Ruby library implementing the SAML Service Provider side of SSO, handling authn requests, response validation, XML signature checks, and IdP metadata…

Runtime Application Self Protection for Python web servers, serverless functions and MCP servers, detecting attacks, prompt injection and data leaks…

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

Disabled TLS Certificate Verification for HashiCorp Vault KMS in confluent-kafka

Defensive analysis, patch breakdown, and passive detection scanner for CVE-2026-103752 (WordPress Authorizer Plugin <= 3.15.3).

End-to-end agentic smart contract fuzzing and threat hunting

Defensive analysis, patch breakdown, and detection scanner for CVE-2026-14378 (WordPress DevKit Pro Plugin <= 2.3.0).

A desktop workbench for writing, validating, compiling, and testing YARA rules.

Safe unauthenticated patch-state checker for Check Point CPM RCE CVE-2026-93616; probes the UpgradeSvcRemote SOAP login on TCP 19009 without…