
SafeLine
Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Linux ptrace-based process tracing and debugging utility for inspecting system calls, memory, and program execution flow.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

Tool for reverse engineering macOS/OS X

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Agent-native CLI wrapping IDA Pro IDALib for stateless, JSON-output binary analysis: disassembly, Hex-Rays decompilation, CFG, xrefs, strings, and…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

An Interactive Binary Patching Plugin for IDA Pro

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.