
godirb
Fast and easy-to-use directory brute-forcer written in Go.

Fast and easy-to-use directory brute-forcer written in Go.

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Evidence-driven Linux kernel vulnerability research harness used in the investigation of CVE-2026-31720

Binary visualiser and triage tool — entropy, byte-class and Hilbert surfaces, dot plots and control-flow graphs over one shared address-space model.

Automated scanner for CVE-2021-44228 (Log4Shell) that tests single or multiple web targets for the vulnerability using remote callback servers.

A Log4j vulnerability scanner is used to identify the CVE-2021-44228 and CVE_2021_45046

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.


Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

Coverage-guided fuzzer that uses taint tracking and scalar optimization to solve path constraints without symbolic execution, improving branch…

A curated list of resources related to Industrial Control System (ICS) security.

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

Cargo subcommand for coverage-guided Rust fuzzing with libFuzzer: create and run fuzz targets, minimize failures and corpora, and report coverage.

🐢 Open-Source Evaluation & Testing library for LLM Agents

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Web vulnerability scanner written in Python3

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

Curated bug-bounty methodology library with runbooks, recon/fuzz playbooks, checklists, and CLI helpers for target scoping, cert enumeration, and…