
Forbidden-Buster
A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Automated cyber reasoning system that discovers and analyzes software vulnerabilities through fuzzing, binary analysis, and program reasoning for…

Reverse engineering software using a full system simulator

ARM64 ELF Virtual Machine Protection System

Linux x86_64 kernel system call fuzzer using AFL and QEMU to find crashes and vulnerabilities via dynamic analysis and instrumentation.

QEMU/AFL-based fuzzing platform for embedded OS kernels with binary instrumentation, system call translation, and memory access monitoring to detect…

This is the full file system fuzzing framework that I presented at the Hack in the Box 2020 Lockdown Edition conference in April.

Dracula OS is a Linux operating system meticulously designed for OSINT (Open Source Intelligence) and Cyber Intelligence missions.

System call fuzzing of OpenBSD amd64 using TriforceAFL (i.e. AFL and QEMU)

Proof-of-concept exploit for CVE-2023-20052, an information leak vulnerability in ClamAV's DMG file parser. Generates a malicious DMG file to trigger…

Proof-of-concept exploit for CVE-2019-12594, a vulnerability in DOSBox 0.74-2 that allows arbitrary code execution on the host system.

Multi-engine vulnerability scanner with built-in Nuclei Lite, Afrog, and XRay engines. Features asset discovery via FOFA/Shodan, OOB interaction…

Proof-of-concept exploit for CVE-2026-24688, a critical DoS vulnerability in pypdf's circular outline parsing causing infinite memory allocation and…

Proof of Concept (PoC) for a stack-based buffer overflow in Steghide 0.5.1. Demonstrates how long file paths trigger a crash (DoS) and leak sensitive…

Industrial control system security testing tool that enumerates and rewrites SCADA controller registers (coils, inputs, holding registers) in safe,…

Proof-of-concept exploit for CVE-2023-38545, a curl heap buffer overflow. Includes SOCKS5 proxy and HTTP server to trigger the vulnerability and…

C library for stream-oriented XML parsing with handler registration, supporting UTF-8/UTF-16 encoding, and autoconf-based build system. Includes…