
graphql-cop
Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

Code Coverage Exploration Plugin for Ghidra

The first analysis framework for CPU microcode

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Toy scripts for playing with WinDbg JS API

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

Pishi is a code coverage tool like kcov for macOS.

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

A tool for effective testing the binding layer of scripting languages

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

YARI is an interactive debugger for YARA Language.

A collection of useful resources for hacking WordPress and it's plugins and themes

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.