
snapchange
Lightweight fuzzing of a memory snapshot using KVM

Lightweight fuzzing of a memory snapshot using KVM

Toy scripts for playing with WinDbg JS API

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

Python exploit script for CVE-2020-28458, a prototype pollution vulnerability in DataTables. It sends crafted payloads to target URLs, supports proxy…

Documentation and reverse engineering of reCAPTCHA

GUI Burp Plugin to ease discovering of security holes in web applications

Distributed coverage-guided fuzzing engine compatible with libFuzzer targets; scales to thousands of concurrent jobs, uses sanitizers and corpus…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

x64 Dynamic Reverse Engineering Toolkit

A DTrace on Windows Reimplementation

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

GNU IFUNC is the real culprit behind CVE-2024-3094

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Source-level debugger for Go with CLI, API, and headless modes; supports breakpoints, variable inspection, and execution tracing for efficient…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Runtime Windows API interception library for hooking, monitoring, and instrumenting function calls. Supports binary rewriting and DLL injection,…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Fil-C: completely compatible memory safety for C and C++