


Offensive Software Exploitation Course

A lightweight dynamic instrumentation library

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could…

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

A tool for logging data/testing devices with a Wiegand Interface. Can be used to create a portable RFID reader or installed directly into an existing…

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

Fast HTTP enumerator

A tool that is used to hunt vulnerabilities in x64 WDM drivers

Edge-coverage-guided fuzzer for PHP libraries that detects bugs via crashes, timeouts, and warnings. Supports corpus management, crash minimization,…

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

Coverage-based fuzzer for python applications

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

System call fuzzing of OpenBSD amd64 using TriforceAFL (i.e. AFL and QEMU)

This POC exploits a format validation vulnerability in the RTSP service of the Hipcam RealServer/V1.0, inducing a crash for approximately 45 seconds…