
Pishi
Pishi is a code coverage tool like kcov for macOS.

Pishi is a code coverage tool like kcov for macOS.

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

GNU IFUNC is the real culprit behind CVE-2024-3094

A tool for effective testing the binding layer of scripting languages

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

A collection of useful resources for hacking WordPress and it's plugins and themes

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Distributed coverage-guided fuzzing engine compatible with libFuzzer targets; scales to thousands of concurrent jobs, uses sanitizers and corpus…

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Fuzzing Framework for Modules in Apache HTTPD Server

A script to detect stack-strings by using emulation (leveraging Unicorn)

Golang bindings for PE-sieve

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

通过 jvm 启动参数 以及 jps pid进行拦截非法参数