
AMSIDetection
Proof-of-concept tool for detecting AMSI (Antimalware Scan Interface) bypasses and malicious in-memory script activity on Windows endpoints.

Proof-of-concept tool for detecting AMSI (Antimalware Scan Interface) bypasses and malicious in-memory script activity on Windows endpoints.

Linux system-call monitor using ptrace to trace file, process, network, and memory activity, with namespace isolation and machine learning…

Open-source automated malware analysis sandbox that runs suspicious files and URLs in isolated VMs and generates detailed behavioral reports.

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

A dynamic unpacking tool

bash script to facilitate some aspects of an Android application assessment

A Generic Windows Memory Scraping Tool

Umap2 is the second revision of NCC Group's python based USB host security assessment tool.

Traces user inputs to detect injection vulnerabilities in Java methods via JDWP and Frida, identifying potential command and SQL injection points.

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

Security profiling for blackbox iOS

Fuzzer for the Sparkplug B IIoT protocol


🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Some tools to help mitigating Apache Log4j 2 CVE-2021-44228

Go tool and Nuclei template for testing James Kettle's (CVE-2025-32094) HTTP/1.1 must die: the desync endgame

This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.

C library for stream-oriented XML parsing with handler registration, supporting UTF-8/UTF-16 encoding, and autoconf-based build system. Includes…