
wpscan
WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Record and replay framework for deterministic debugging of multi-threaded applications, enabling reverse execution, hardware watchpoints, and…

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Fil-C: completely compatible memory safety for C and C++

A wrapper around grep, to help you grep for things

The Swiss Army knife for automated Web Application Testing

Cargo subcommand for coverage-guided Rust fuzzing with libFuzzer: create and run fuzz targets, minimize failures and corpora, and report coverage.

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Differential testing framework for HTTP implementations

Sample extensions, scripts, and API uses for WinDbg.

An Interactive Binary Patching Plugin for IDA Pro

A security scanner for your LLM agentic workflows

Tool for reverse engineering macOS/OS X

Coverage-guided fuzzer that uses taint tracking and scalar optimization to solve path constraints without symbolic execution, improving branch…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

An strace-like program for the Windows 'native' API

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.