
sqlancer
Automated testing to find logic and performance bugs in database systems

Automated testing to find logic and performance bugs in database systems

nextpnr portable FPGA place and route tool

Quickly find differences and similarities in disassembled code

Zerologon (CVE-2020-1472) Proof-of-Concept application - Critical Active Directory vulnerability exploitation tool.

Automated static analysis tools for binary programs

Azure Sentinel detection lab for MCP attack patterns, providing 5 analytics rules and 7 KQL hunting queries against SSRF token theft, tool poisoning,…

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

In-depth technical analysis of CVE-2026-41940, a critical pre-authentication CRLF injection in cPanel/WHM enabling unauthenticated root session…

Proof-of-concept exploit for CVE-2026-24061, a critical authentication bypass in GNU inetutils-telnetd. Provides unauthenticated remote root shell…

Client-side scanner that detects CVE-2024-4367 (PDF.js RCE) on any website via JavaScript bundle analysis, version fingerprinting, and exploitation…

NocoDB Shared-Base Links Could Invite Real Base Members and Survive Share Revocation

N-gram-based type recovery tool for binaries, recovering structures and function signatures from decompiled code with high throughput and actionable…

Rule-based CLI tool that grades organizational defenses against MITRE ATT&CK and D3FEND frameworks, detects security gaps, and proposes mitigations.…

Detailed disclosure of CVE-2025-67511, a command injection vulnerability in the CAI framework's SSH tool that allows AI agents to be tricked into…

CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool

This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made available…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Automated testing tool for CVE-2025-65862 (SLiMS Bulian v9.7.2 arbitrary file upload to RCE). Uploads ZIP payloads to verify vulnerability in target…