
vmp2
Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Inject code into running Python processes

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Fil-C: completely compatible memory safety for C and C++

The Swiss Army knife for automated Web Application Testing

A wrapper around grep, to help you grep for things

Cargo subcommand for coverage-guided Rust fuzzing with libFuzzer: create and run fuzz targets, minimize failures and corpora, and report coverage.

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Differential testing framework for HTTP implementations

A security scanner for your LLM agentic workflows

Coverage-guided fuzzer that uses taint tracking and scalar optimization to solve path constraints without symbolic execution, improving branch…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

An strace-like program for the Windows 'native' API

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…