
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!

Android virtual machine and deobfuscator

Automated hypervisor-level malware analysis sandbox with agentless guest introspection, web-based result exploration, and guided installer for…

A tool that helps you easy trace classes, functions, and modify the return values of methods on iOS platform

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Modular file scanning/analysis framework

AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Scalable fuzzing infrastructure with coverage-guided engines (libFuzzer, AFL, Honggfuzz), automated crash deduplication, bug filing, and regression…

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Triton is a dynamic binary analysis library. Build your own program analysis tools, automate your reverse engineering, perform software verification…

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware…

Symbolic execution tool

Makes reverse engineering Android apps easier, automating repetitive tasks like pulling, decoding, rebuilding and patching an APK.