
apkprobe
APK decompiler & secrets scanner for Android security research! Extract leaked API keys, hardcoded credentials, endpoints from APK files. apk2url,…

APK decompiler & secrets scanner for Android security research! Extract leaked API keys, hardcoded credentials, endpoints from APK files. apk2url,…

Provenance-aware Linux kernel vulnerability research harness used in the investigation of CVE-2026-53075

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome…

Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…

A machine learning tool that ranks strings based on their relevance for malware analysis.

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Advanced Static malware analyzer that reveals 8 injection techniques, critical API calls, hidden strings, exports PE sections (.text, .rdata) as…

Visualizes repeated byte sequences in binary files to reveal hidden structure, supporting reverse engineering and pattern discovery without…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

IDA python scripts to decrypt strings from KPOT and set those as comments

A reversing plugin for cross-decompiler collaboration, built on git.

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers
