
security-audit-skill
A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

GNU IFUNC is the real culprit behind CVE-2024-3094

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Academic research on N-Day Linux kernel vulnerabilities, analyzing CVE-2024-36886 in the TIPC networking subsystem, lifecycle, impact, and mitigation…