
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

A wrapper around grep, to help you grep for things

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

x64 Dynamic Reverse Engineering Toolkit

Documentation and reverse engineering of reCAPTCHA

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Code Coverage Exploration Plugin for Ghidra

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Windows NT ioctl bruteforcer and modular fuzzer

Pishi is a code coverage tool like kcov for macOS.

Xyntia, the black-box deobfuscator

Exploit for Jenkins serialization vulnerability - CVE-2016-0792