
kiterunner
High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Differential testing framework for HTTP implementations

An strace-like program for the Windows 'native' API

x64 Dynamic Reverse Engineering Toolkit

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Code Coverage Exploration Plugin for Ghidra

Windows NT ioctl bruteforcer and modular fuzzer

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

GUI Burp Plugin to ease discovering of security holes in web applications

A tool for effective testing the binding layer of scripting languages

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

GNU IFUNC is the real culprit behind CVE-2024-3094