


A native APK and DEX decompiler written in Rust

Web vulnerability scanner written in Python3

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

A security scanner for your LLM agentic workflows

Android DEX → Java decompiler in Rust, built for speed — full apps in seconds, queries in milliseconds. Progressive analysis, javac-verified output,…

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

A fast, simple, recursive content discovery tool written in Rust.

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

LLM powered fuzzing via OSS-Fuzz.
