
nullorigin
Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

Complete firmware vulnerability analysis for CVE-2020-9373 Netgear R6400 UPnP stack overflow, including unpacking, reverse engineering, static…

Semantic static analysis engine and query library for detecting security vulnerabilities in source code, enabling automated code scanning and CI/CD…

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Security hardening toolkit for COBOL legacy — detects Trojan Source (CVE-2021-42574) and Glassworm invisible Unicode in GnuCOBOL / Zowe pipelines

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Language server for YARA rule development, providing code completion, linting, formatting, navigation, and debugging support inside IDEs.

CQ, a code security scanner

jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512

A list of awesome penetration testing tools and resources.

VBScript & VBA source-to-source deobfuscator with partial-evaluation

UT based automated fuzz driver generation

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Batch-decompile binaries with Ghidra from the command line, generating per-function C files, callgraphs, BSim signatures, and optional SAST results…

Curated catalog of Solidity smart contract vulnerability patterns with categorized examples, prevention methods, and LLM-optimized references for…

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…