
mole
Framework for identifying and exploiting out-of-band (OOB) application vulnerabilities with a custom DNS/token server, Burp Suite extension, and…

Framework for identifying and exploiting out-of-band (OOB) application vulnerabilities with a custom DNS/token server, Burp Suite extension, and…

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Software Component Verification Standard (SCVS)

Pattern recognition for hosts, services, and content

Framework for auditing blockchain ecosystems, identifying smart contract vulnerabilities, and generating structured findings with multi-platform…

Multi-engine framework for unpacking and analyzing VM-protected binaries using dynamic taint tracking, symbolic execution, pattern classification,…

Exploit toolkit targeting CVE-2019-15477 in the Jooby micro web framework, enabling vulnerability analysis and exploitation of Java/Kotlin web…

Modular credential validation framework with active and passive (regex-based) checking modes for penetration testers. Supports multiple services via…

Network protocol fuzzer that replays PCAP traffic through a mutational engine (Radamsa) to quickly discover vulnerabilities in target hosts via…

Tools for auditing WAFS

WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University…

Fuzzing framework written in python

PROJECT DELTA: SDN SECURITY EVALUATION FRAMEWORK

This is the full file system fuzzing framework that I presented at the Hack in the Box 2020 Lockdown Edition conference in April.

This is the community edition of GitLab's protocol fuzzing framework. This framework is based on Peach Fuzzer Professional with some features removed.

A loader for bitbucket 2022 rce (cve-2022-36804)

Register-level invariant-guided fuzzing framework for closed-source binaries, leveraging likely invariant violations to discover crashes and bugs in…

Chrome V8 exploit for CVE-2019-5825 targeting version 73.0.3683.86 with --no-sandbox. Includes proof-of-concept code and integration with Metasploit…