
SafeLine
Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

A native APK and DEX decompiler written in Rust

0-day malware detection for binaries, source & scripts (that doesn't suck)

Linux ptrace-based process tracing and debugging utility for inspecting system calls, memory, and program execution flow.

A Android malware analysis tool that creates comprehensive runtime profiles by hooking into application behavior across cryptography, file systems,…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

Extract the managed (.NET) assemblies out of a MAUI Android assembly store.

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

Agent-native CLI wrapping IDA Pro IDALib for stateless, JSON-output binary analysis: disassembly, Hex-Rays decompilation, CFG, xrefs, strings, and…

A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

Tool for reverse engineering macOS/OS X

DEX → Java decompiler in Rust — fast, progressive analysis, bilingual CLI

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.