
Brovan
User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

A native APK and DEX decompiler written in Rust

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.


DEX → Java decompiler in Rust — fast, progressive analysis, bilingual CLI

GNU IFUNC is the real culprit behind CVE-2024-3094

Web vulnerability scanner written in Python3

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

A fast, simple, recursive content discovery tool written in Rust.

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Pishi is a code coverage tool like kcov for macOS.

Reproduces the CVE-2026-70638 integer overflow in llama.cpp Android JNI with a safe arithmetic demo, malicious GGUF generator, and Frida hook for…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…