
xyntia
Xyntia, the black-box deobfuscator

Xyntia, the black-box deobfuscator

Distributed coverage-guided fuzzing engine compatible with libFuzzer targets; scales to thousands of concurrent jobs, uses sanitizers and corpus…

GNU IFUNC is the real culprit behind CVE-2024-3094

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Fuzzing Framework for Modules in Apache HTTPD Server

A script to detect stack-strings by using emulation (leveraging Unicorn)

Golang bindings for PE-sieve

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

Python exploit script for CVE-2020-28458, a prototype pollution vulnerability in DataTables. It sends crafted payloads to target URLs, supports proxy…

Academic research on N-Day Linux kernel vulnerabilities, analyzing CVE-2024-36886 in the TIPC networking subsystem, lifecycle, impact, and mitigation…

Laravel debug mode - Remote Code Execution (RCE)

.NET deobfuscator and unpacker.

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

A wrapper around grep, to help you grep for things

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.