
dalfox
Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

An strace-like program for the Windows 'native' API

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Documentation and reverse engineering of reCAPTCHA

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

An API hooking framework for intercepting and monitoring Windows applications

Fuzzing Framework for Modules in Apache HTTPD Server

Differential testing framework for HTTP implementations

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

GNU IFUNC is the real culprit behind CVE-2024-3094

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

LLM powered fuzzing via OSS-Fuzz.

A script to detect stack-strings by using emulation (leveraging Unicorn)