
wapiti
Web vulnerability scanner written in Python3

Web vulnerability scanner written in Python3

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Proof-of-concept for CVE-2026-62958: crafts a malformed ELF to trigger an out-of-bounds read in Libriscv and crash the sandbox with SIGSEGV.

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Desktop workbench for AFL++ fuzzing, cross-architecture QEMU emulation, harness development, Ghidra headless analysis, custom mutators, and patch…

Binary visualiser and triage tool — entropy, byte-class and Hilbert surfaces, dot plots and control-flow graphs over one shared address-space model.

A curated list of resources related to Industrial Control System (ICS) security.

Generate mutations over a wordlist

Security analysis toolkit for proprietary car protocols


A collection of various awesome lists for hackers, pentesters and security researchers

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

Proof-of-concept exploit for CVE-2019-2107, demonstrating remote code execution via crafted HEVC video on Android media framework. Includes crash…

GUSTAVE is a fuzzing platform for embedded OS kernels. It is based on QEMU and AFL (and all of its forkserver siblings). It allows to fuzz OS kernels…

A lightweight dynamic instrumentation library

PoC exploit server for CVE-2015-7547

Fuzz 401/403/404 pages for bypasses