
masq
Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

Vulnerability research assistant that locates calls to potentially insecure API functions in a binary file.


Exports disassembly from IDA Pro, Ghidra, and Binary Ninja into compact protobuf files for fast, standalone binary analysis and program manipulation…

IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix…

IDA plugin that resolves PPL calls to the actual underlying PPL function.

Collection of YARA rules designed for usage through VirusTotal.com.

IDA python scripts to decrypt strings from KPOT and set those as comments

This is a little plugin to copy disassembly in a way that is usable in YARA rules!


A Binary Ninja plugin that uses bruteforced XFG hashes to recover precise function prototypes


Watchguard Sysa-dl file format

Reverse engineering assistant that uses a locally running LLM to aid with pseudocode analysis.

Finding Java/C# gadget chains with CodeQL

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…