
Agentic-Bug-Hunter
AI-powered bug bounty hunting toolkit that works with or without subscription.

AI-powered bug bounty hunting toolkit that works with or without subscription.

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

A list of awesome penetration testing tools and resources.

VBScript & VBA source-to-source deobfuscator with partial-evaluation

Python Command-Line Ghidra Decompiler

A collection of smart contract vulnerabilities along with prevention methods

OSWE, OSEP, OSED, OSEE

Specialized reasoning LLM for source-code vulnerability detection in C/C++ and Python, with dataset construction, SFT/DPO training, and…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

Curated weggli queries for static analysis of C/C++ code to identify dangerous functions, stack issues, and malloc overflow vulnerabilities.

Clickbait. The CVE is AI slop.

A Bitbucket Pipe to trigger SonarCloud analysis

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Educational lab demonstrating CVE-2020-11023 jQuery XSS vulnerability with attack payloads, mitigation techniques (text(), CSP, input validation),…