
wycheproof
Project Wycheproof tests crypto libraries against known attacks.

Project Wycheproof tests crypto libraries against known attacks.

Small and highly portable detection tests based on MITRE's ATT&CK.

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

9 MITRE ATT&CK-mapped KQL detections on a live Microsoft Sentinel + Defender XDR environment (control-plane, endpoint, identity), with a PR-gated…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

AI-driven CLI for testing Android and iOS apps using natural language. Generates, runs, and fixes end-to-end tests on emulators/simulators with…

Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)

🔐 CVE-2026-57821 - Apache Fineract SQL Injection Toolkit 📚 Two Python scripts for authorized security testing: verifier.py (safe detection, no…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Technical Reference to multiple relay techniques

The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP

AI Smart Contract Security Analysis and PoC Generation Framework

Free XP on bug bounty, vulnerability scanning by wrapping well maintained tools, to perform automated tests. Alongside AI agents for binary analysis,…

Evaluation framework that tests whether large language models follow invisible Unicode-encoded instructions embedded in normal-looking text, with…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

This repository contains a few vulnerabilities that were found and reported during vulnerability assessments.

Python based tool for generating Shellcode from PIC C