
sec-af
AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

Hashes for vulnerable LOG4J versions

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Script to audit GitHub Action Workflow files for potential vulnerabilities.

LD_PRELOAD-based tool that hijacks gcc to inject malicious code into binaries during linking, enabling stealthy backdoor deployment without source…

Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

Signing-key abuse and update exploitation framework

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

Presentation materials for my Black Hat USA 2022 Briefing and Arsenal talks

GNU IFUNC is the real culprit behind CVE-2024-3094

Breaking git with a carriage return and cloning RCE

Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security…