
vbSparkle
VBScript & VBA source-to-source deobfuscator with partial-evaluation

VBScript & VBA source-to-source deobfuscator with partial-evaluation

client-side prototype pullution vulnerability scanner

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

A list of awesome penetration testing tools and resources.

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

NCC Code Navigator

The Secure Coding Practices Quick-reference Guide from OWASP

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Checklist and tools for increasing security of Apache Airflow

SAST CLI for scanning Java, JavaScript, and .NET applications plus AWS Lambda functions, detecting code vulnerabilities and over-permissive IAM…

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Vulnerability Assessment Scanner with Report Generation

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.