
lighthouse
A Coverage Explorer for Reverse Engineers

A Coverage Explorer for Reverse Engineers

Reverse engineer anything with agents, from app behavior down to native binaries.

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Static analysis tool for Android/iOS apps focusing on security issues outside the source code

0-day malware detection for binaries, source & scripts (that doesn't suck)

Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

Static analysis CLI that scans AI-generated code for vulnerabilities like SQL injection, unsafe reflection, and hardcoded secrets, with SARIF export…

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

.NET Decompiler with support for PDB generation, ReadyToRun, Metadata (&more) - cross-platform!

AI-Powered Reverse Engineering Plugin for IDA Pro

Trace-assisted VMProtect devirtualization research platform: version front-ends feed a shared Remill/LLVM backend to lift handlers, recover dataflow,…

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

Top-level repository for LFI: Practical, Efficient, and Secure Software-based Sandboxing

Dependency-free static analyzer for zk circuit soundness bugs in o1js/Mina zkApps and Noir circuits

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…