
splinter
Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode


This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…


Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

LLM powered fuzzing via OSS-Fuzz.

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Documentation and reverse engineering of reCAPTCHA

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

Windows NT ioctl bruteforcer and modular fuzzer

A PoC Java Stager which can download, compile, and execute a Java file in memory.

A collection of useful resources for hacking WordPress and it's plugins and themes

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Xyntia, the black-box deobfuscator