
awesome-appsec
A curated list of resources for learning about application security

A curated list of resources for learning about application security

An NFC research toolkit application for Android

Comprehensive open-source book on SELinux covering kernel components, userspace libraries, policy toolchain, and policy language. Includes build…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

This project shows the kind of data a rogue iPhone application can collect.

A tool for effective testing the binding layer of scripting languages

GNU IFUNC is the real culprit behind CVE-2024-3094

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

The Intelligent Process Lifecycle of Active Cyber Defenders

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Proof Of Concept for Android. NoFrak is designed to prevent fracking attacks, as described in "Breaking and Fixing Origin-Based Access Control in…

Technical analysis, root cause breakdown, and non-destructive detection methodology for CVE-2026-63030.

Walkthrough: ingress-nginx Configuration Injection via rewrite-target Annotation

Stored XSS proof-of-concept for OpenKM notes section, demonstrating a javascript: bypass of sanitization rules, with CVSS 3.1 scoring and…

This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!

Rule-based CLI tool that grades organizational defenses against MITRE ATT&CK and D3FEND frameworks, detects security gaps, and proposes mitigations.…

Proof-of-concept demonstrating React2shell vulnerability (CVE-2025-66478) in a Next.js application, providing a base for reproduction and…

Proof-of-concept exploit for CVE-2025-52399, demonstrating SQL injection in the loginlinkfaculty endpoint of Institute-of-Current-Students, enabling…