
JShunter
jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A fast, simple, recursive content discovery tool written in Rust.

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

The Swiss Army knife for automated Web Application Testing

The repo contains a series of challenges for learning Frida for Android Exploitation.

LLM powered fuzzing via OSS-Fuzz.

Sample extensions, scripts, and API uses for WinDbg.

An strace-like program for the Windows 'native' API

Documentation and reverse engineering of reCAPTCHA

Time Travel Debugging IDA plugin

A DTrace on Windows Reimplementation


Exploit for Jenkins serialization vulnerability - CVE-2016-0792

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

GNU IFUNC is the real culprit behind CVE-2024-3094

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)