
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

Automatic SQL injection and database takeover tool

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Tool for reverse engineering macOS/OS X

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

Pishi is a code coverage tool like kcov for macOS.

An API hooking framework for intercepting and monitoring Windows applications

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

A fast, simple, recursive content discovery tool written in Rust.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Static Binary Instrumentation tool for Windows x64 executables

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…