
CVE-2026-56848
Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Laravel debug mode - Remote Code Execution (RCE)

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

GUI Burp Plugin to ease discovering of security holes in web applications

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

A script to detect stack-strings by using emulation (leveraging Unicorn)

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Scriptable debugger for Android Dalvik VM using JDWP/DDM interfaces to hook methods, inspect process state, and modify runtime behavior without…

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

Differential testing framework for HTTP implementations

Automatic SSTI detection tool with interactive interface

x64 Dynamic Reverse Engineering Toolkit