
zairo
Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

A wrapper around grep, to help you grep for things

Source-level debugger for Go with CLI, API, and headless modes; supports breakpoints, variable inspection, and execution tracing for efficient…

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

YARI is an interactive debugger for YARA Language.

Xyntia, the black-box deobfuscator

Detours implementation (x64/x86) which used only ntdll import

Pishi is a code coverage tool like kcov for macOS.

Fuzzing Framework for Modules in Apache HTTPD Server

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Automatic SSTI detection tool with interactive interface

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

Laravel debug mode - Remote Code Execution (RCE)

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会