
SafeLine
Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Differential testing framework for HTTP implementations

Automatic SSTI detection tool with interactive interface

Fermion, an electron wrapper for Frida & Monaco.


Windows NT ioctl bruteforcer and modular fuzzer

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会


ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.



A fast DOM based XSS vulnerability scanner with simplicity.