
schrodingers-toctou
Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

Easy setup of static analysis tools for Android and Java projects.

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

C++ python bytecode disassembler and decompiler

Web-based Source Code Vulnerability Scanner

解决网络安全漏洞

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

The iOS Security Testing Framework

A collection of my Semgrep rules to facilitate vulnerability research.

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

MCP server plugin for JEB Pro that enables AI-assisted decompilation, method/field inspection, and automated renaming during APK reverse engineering.

Link sources to sinks in C# applications.

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…

Static code analysis plugin for Android project. (Checkstyle, PMD)

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.