
Android-Projector-C2-Malware
Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

0-day malware detection for binaries, source & scripts (that doesn't suck)

Technical case study of the XZ Utils backdoor (CVE-2024-3094), covering supply-chain trust abuse, malicious release artifacts, build-stage injection,…

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

GNU IFUNC is the real culprit behind CVE-2024-3094

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.

CVE-2026-43813: CloudAttestation enforceEnvironment bypass

a systems programming language prioritizing verifiable correctness, determinism, and performance

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and CVE.

Critical supply-chain vulnerability research on NiceHash QuickMiner update mechanism (CVE-2025-56513). Includes technical analysis, attack scenarios,…

Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

PoC demonstrating SHA-1 code signing forgery and missing High Entropy ASLR in CyberGhostVPN installer, enabling trust bypass and predictable memory…

Proof-of-concept code for Android APEX key reuse vulnerability

Cargo exploit from CVE-2023-38497