
scan
0-day malware detection for binaries, source & scripts (that doesn't suck)

0-day malware detection for binaries, source & scripts (that doesn't suck)

An LLM-driven fuzzing pipeline powered by the GitHub Security Lab Taskflow Agent

A native APK and DEX decompiler written in Rust

Extract the managed (.NET) assemblies out of a MAUI Android assembly store.

REx@Skill - Agentic Reverse Engineering eXecution Skill for binary vulnerability discovery

Agent-native CLI wrapping IDA Pro IDALib for stateless, JSON-output binary analysis: disassembly, Hex-Rays decompilation, CFG, xrefs, strings, and…

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

Audit harness testing whether the CVE-2026-0994 Any-unwrapping recursion bug class affects upb's C core in Ruby and PHP protobuf bindings, with…

Fix-Like Artifacts With Embedded Defects

C++ reimplementation of Ghidra's analytical core without JVM dependencies, providing embeddable binary analysis, Pcode/Sleigh foundations, and…

Standalone reproducer for CVE-2026-90781: 1-byte OOB write in alsa-lib __snd_ctl_ascii_elem_id_parse() name= parsing (quoted and unquoted)

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Exhaustive differential validation of all 4.3B AArch64 instruction encodings.

Private end-to-end sanitizer reproduction package for six GDCM findings

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Evidence-driven Linux kernel vulnerability research harness used in the investigation of CVE-2026-31720

LuaJIT FFI bindings for libinjection, providing SQL injection and XSS detection with context-specific APIs for web application security.

Binary visualiser and triage tool — entropy, byte-class and Hilbert surfaces, dot plots and control-flow graphs over one shared address-space model.