


The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

RMIScout uses wordlist and bruteforce strategies to enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilities

Coverage-guided fuzzer that uses taint tracking and scalar optimization to solve path constraints without symbolic execution, improving branch…

Evidence-driven Linux kernel vulnerability research harness used in the investigation of CVE-2026-31720

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

Proof-of-concept exploit for CVE-2026-85769, a heap out-of-bounds read in libtpms TPM 2.0 state deserialization, demonstrating denial of service via…

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…

Headless Binary Ninja MCP server — giving AI agents deep reverse-engineering capabilities via 180 tools.

Fuzzing Framework for Modules in Apache HTTPD Server

UT based automated fuzz driver generation

Proof-of-concept exploit for CVE-2024-27619 causing denial of service on D-Link DIR-3040/3060 routers via FTP memory exhaustion without…

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

Automated reasoning tool based on the SMACK verifier that detects SGX enclave bugs from trusted boundary violations, including invalid pointer…

PJSIP DNS Compression Pointer Heap OOB Read (Remote DoS)

Bash-based fuzzing tool that leverages Google Dorking for stealthy enumeration of directories, files, subdomains, and parameters without direct…