
fil-c
Fil-C: completely compatible memory safety for C and C++

Fil-C: completely compatible memory safety for C and C++

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

GNU IFUNC is the real culprit behind CVE-2024-3094

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Pishi is a code coverage tool like kcov for macOS.


Cargo subcommand for coverage-guided Rust fuzzing with libFuzzer: create and run fuzz targets, minimize failures and corpora, and report coverage.

Fuzzing Framework for Modules in Apache HTTPD Server

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Differential testing framework for HTTP implementations

A collection of useful resources for hacking WordPress and it's plugins and themes

LLM powered fuzzing via OSS-Fuzz.