
zairo
Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

A security scanner for your LLM agentic workflows

A wrapper around grep, to help you grep for things

Record and replay framework for deterministic debugging of multi-threaded applications, enabling reverse execution, hardware watchpoints, and…

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Web vulnerability scanner written in Python3

A DTrace on Windows Reimplementation

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Sample extensions, scripts, and API uses for WinDbg.

Toy scripts for playing with WinDbg JS API

Distributed coverage-guided fuzzing engine compatible with libFuzzer targets; scales to thousands of concurrent jobs, uses sanitizers and corpus…

x64 Dynamic Reverse Engineering Toolkit

Golang bindings for PE-sieve

Lightweight fuzzing of a memory snapshot using KVM

The repo contains a series of challenges for learning Frida for Android Exploitation.

Differential testing framework for HTTP implementations