
dalfox
Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…


A fast DOM based XSS vulnerability scanner with simplicity.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

GUI Burp Plugin to ease discovering of security holes in web applications

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

Fermion, an electron wrapper for Frida & Monaco.

Detect, analyze and uniquely identify crashes in Windows applications

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Differential testing framework for HTTP implementations

LLM powered fuzzing via OSS-Fuzz.

Automatic SSTI detection tool with interactive interface

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

x64 Dynamic Reverse Engineering Toolkit