
ifuncd-up
GNU IFUNC is the real culprit behind CVE-2024-3094

GNU IFUNC is the real culprit behind CVE-2024-3094

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

A wrapper around grep, to help you grep for things

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Differential testing framework for HTTP implementations

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

A fast, simple, recursive content discovery tool written in Rust.

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

An API hooking framework for intercepting and monitoring Windows applications

A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…


The ARTful library for dynamically modifying the Android Runtime

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

Next generation web scanner

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

An strace-like program for the Windows 'native' API