



A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

[Official] Android reverse engineering tool focused on dynamic instrumentation automation leveraging Frida. It disassembles dex, analyzes it…

A collection of custom security tools for quick needs.

Extendable pentesting framework for automotive UDS interfaces, enabling reproducible scans, diagnostic trouble code reading, and post-processing via…

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in Android's MatroskaExtractor reachable via a…

WiFi Penetration Testing & Auditing Tool

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Fast and easy-to-use directory brute-forcer written in Go.

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

Set of tools to audit SIP based VoIP Systems

Mobile Edge-Dynamic Unified Security Analysis

In-depth analysis and proof-of-concept for CVE-2026-27280, an out-of-bounds write in Adobe DNG SDK's dng_render_task::ProcessArea, reachable via…