
external_libexif_AOSP10_CVE-2020-0452
C library for parsing, editing, and saving EXIF data, with a focus on addressing CVE-2020-0452 in AOSP10. Provides API for metadata extraction and…

C library for parsing, editing, and saving EXIF data, with a focus on addressing CVE-2020-0452 in AOSP10. Provides API for metadata extraction and…

C library for stream-oriented XML parsing, with a focus on analyzing and reproducing CVE-2024-28757 vulnerability in Expat 2.1.0.

Configuration Extractors for Malware

Java library for XML serialization and deserialization, with a focus on the CVE-2020-26217 deserialization vulnerability exploit.

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Java library for XML serialization and deserialization, with a focus on CVE-2020-26217 exploitation. Enables converting Java objects to XML and back,…

Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.

Radare2 AI plugin using local or remote LLMs for decompilation, function explanation, vulnerability detection, renaming, and scripted reverse…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

C library for parsing, editing, and saving EXIF metadata, with a focus on addressing CVE-2020-0198 in AOSP10.

Source code repository for Expat 2.1.0, a stream-oriented XML parser library, with focus on analyzing and addressing CVE-2022-43680.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Private end-to-end sanitizer reproduction package for six GDCM findings

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

The code of VulTriage: Triple-Path Context Augmentation for LLM-Based Vulnerability Detection

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

Research runtime for differentiable neural computers, GPU-based CPU emulation, and program synthesis. Features neural ALU, constant-time crypto, JEPA…