
lightkeeper
Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Automatic SSTI detection tool with interactive interface

Pishi is a code coverage tool like kcov for macOS.

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Xyntia, the black-box deobfuscator

Fuzzing Framework for Modules in Apache HTTPD Server


Laravel debug mode - Remote Code Execution (RCE)

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Static Binary Instrumentation tool for Windows x64 executables

pyREtic is an extensible framework for in-memory Python 2.x bytecode reverse engineering

Detours implementation (x64/x86) which used only ntdll import

YARI is an interactive debugger for YARA Language.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)