
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Deobfuscator for javascript-obfuscator 5.x output (string arrays, control-flow flattening, self-defending, RC4/base64)

Fil-C: completely compatible memory safety for C and C++

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

A wrapper around grep, to help you grep for things

A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Unofficial frida extension for VSCode

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Scriptable debugger for Android Dalvik VM using JDWP/DDM interfaces to hook methods, inspect process state, and modify runtime behavior without…

x64 Dynamic Reverse Engineering Toolkit

Android DEX → Java decompiler in Rust, built for speed — full apps in seconds, queries in milliseconds. Progressive analysis, javac-verified output,…

Fermion, an electron wrapper for Frida & Monaco.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

Documentation and reverse engineering of reCAPTCHA