
ICSFuzz
Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

Fuzzing Framework for Modules in Apache HTTPD Server

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Linux ptrace-based process tracing and debugging utility for inspecting system calls, memory, and program execution flow.

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Library and CLI for mutating structured data (JSON, XML, X.509) to support grammar-based fuzzing, with multiple mutation strategies and integration…

Static Binary Instrumentation tool for Windows x64 executables

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Scriptable debugger for Android Dalvik VM using JDWP/DDM interfaces to hook methods, inspect process state, and modify runtime behavior without…

Unofficial frida extension for VSCode

Fermion, an electron wrapper for Frida & Monaco.

The ARTful library for dynamically modifying the Android Runtime

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Reproduces the CVE-2026-70638 integer overflow in llama.cpp Android JNI with a safe arithmetic demo, malicious GGUF generator, and Frida hook for…

Linux Kernel Sanitizers, fast bug-detectors for the Linux kernel


Automatic SSTI detection tool with interactive interface