
LFISuite
Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

A collection of awesome penetration testing resources and tools

Runtime Windows API interception library for hooking, monitoring, and instrumenting function calls. Supports binary rewriting and DLL injection,…

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Sample extensions, scripts, and API uses for WinDbg.

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Scriptable debugger for Android Dalvik VM using JDWP/DDM interfaces to hook methods, inspect process state, and modify runtime behavior without…

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

Documentation and reverse engineering of reCAPTCHA

MCP server packaging a three-tier penetration-testing methodology: attack-surface reconnaissance, source-to-sink static analysis, and live finding…

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

Maps attack surface of GWT applications by extracting obfuscated RPC endpoints and generating serialized request payloads for security testing.

A native APK and DEX decompiler written in Rust

Windows NT ioctl bruteforcer and modular fuzzer