


Android DEX → Java decompiler in Rust, built for speed — full apps in seconds, queries in milliseconds. Progressive analysis, javac-verified output,…

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Web vulnerability scanner written in Python3

A native APK and DEX decompiler written in Rust

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Unofficial frida extension for VSCode


GNU IFUNC is the real culprit behind CVE-2024-3094

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

A fast, simple, recursive content discovery tool written in Rust.

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Pishi is a code coverage tool like kcov for macOS.