
ASC
Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

Android DEX → Java decompiler in Rust, built for speed — full apps in seconds, queries in milliseconds. Progressive analysis, javac-verified output,…

A native APK and DEX decompiler written in Rust

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

A security scanner for your LLM agentic workflows

Web vulnerability scanner written in Python3

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Unofficial frida extension for VSCode

YARI is an interactive debugger for YARA Language.

Toy scripts for playing with WinDbg JS API

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

x64 Dynamic Reverse Engineering Toolkit

Golang bindings for PE-sieve