
haruspex
Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Curated Ghidra scripts to automate reverse engineering and vulnerability analysis: locate insecure functions, extract decompiler pseudocode, fix…

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

MCP server plugin for JEB Pro that enables AI-assisted decompilation, method/field inspection, and automated renaming during APK reverse engineering.

Python Command-Line Ghidra Decompiler

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Easy setup of static analysis tools for Android and Java projects.

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.


Web-based Source Code Vulnerability Scanner

Static code analysis plugin for Android project. (Checkstyle, PMD)