
duckdb
Jepsen-based transactional correctness testing framework for DuckDB, detecting isolation anomalies like G2-item and SSI violations via randomized…

Jepsen-based transactional correctness testing framework for DuckDB, detecting isolation anomalies like G2-item and SSI violations via randomized…

Advisories, proof of concept files and exploits that have been made public by @pedrib.

Cisco ASA Software and ASDM Security Research

Python exploit chain for SPIP CVEs 2026-72708/72709/72710, chaining unauthenticated SQL injection to account takeover and remote code execution.

Automated Penetration Testing Agentic Framework Powered by Large Language Models

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Proof-of-concept and writeup for bypassing the initial patch of CVE-2024-0044, an Android framework vulnerability enabling privilege escalation from…

The Redexer binary instrumentation framework for Dalvik bytecode

Open-source instrumentation framework for Android apps and Java middleware, modifying code during on-device compilation via the ART compiler.…

Reverse engineering framework with disassembly, decompilation, taint analysis, version diffing and semantic search, plus LLM-driven autonomous binary…

OWASP Ontology-driven Threat Modelling framework

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

OWASP framework cataloging the top 10 security risks in neocloud and AI data center infrastructure, covering hardware, networking, isolation,…

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

Image-based Android malware detection framework tackling obfuscation and concept drift. Includes curated datasets and Python code for training…

Defender framework for LLM agent security that compiles task contracts, validates capability manifests, and checks effects via PLANT/WRAP proof…

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

PoC and red team app for CVE-2026-28576, a zero-permission SQL injection in the Android Contacts Provider enabling full contacts database…