
CVE-2026-42945
这是一个面向防守和内网排查的 CVE-2026-42945 静态检测工具,用于检查 NGINX ngx_http_rewrite_module 相关配置是否存在高风险 rewrite 组合。

这是一个面向防守和内网排查的 CVE-2026-42945 静态检测工具,用于检查 NGINX ngx_http_rewrite_module 相关配置是否存在高风险 rewrite 组合。

Maintained fork of node-ip with the unpatched SSRF advisory (CVE-2024-29415) fixed

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

iblessing is an iOS security exploiting toolkit, it mainly includes application information gathering, static analysis and dynamic analysis. It can…

.NET/PowerShell/VBA Offensive Security Obfuscator

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

Documentation and reverse engineering of reCAPTCHA

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

.NET deobfuscator and unpacker.

Demonstrates CVE-2015-10034 in a vulnerable Java application, including SARIF analysis results from J-TAS Action for educational security testing.

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

(deprecated) Android application vulnerability analysis and Android pentest tool

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Firmware Analysis and Comparison Tool

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…