
slides
CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Checklist and tools for increasing security of Apache Airflow

SAST CLI for scanning Java, JavaScript, and .NET applications plus AWS Lambda functions, detecting code vulnerabilities and over-permissive IAM…

AST-based Python code transformation & deobfuscation framework

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.


Curated weggli queries for static analysis of C/C++ code to identify dangerous functions, stack issues, and malloc overflow vulnerabilities.

Vulnerability Assessment Scanner with Report Generation

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…


BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Static analysis CLI that scans AI-generated code for vulnerabilities like SQL injection, unsafe reflection, and hardcoded secrets, with SARIF export…

Dependency-free static analyzer for zk circuit soundness bugs in o1js/Mina zkApps and Noir circuits


Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…