
CVE-2014-4109
Proof-of-concept exploit for a use-after-free vulnerability in Internet Explorer's MSHTML engine, triggered via a crafted URL and documented with…

Proof-of-concept exploit for a use-after-free vulnerability in Internet Explorer's MSHTML engine, triggered via a crafted URL and documented with…

ANE kernel r/w exploit for iOS 15 and macOS 12

AST-level Python obfuscation engine with AES-256 encryption, runtime payload protection, and control-flow flattening for security research and…

Highly advanced Linux anti-exploitation and anti-tamper binary protector for ELF.

Go library for parsing and executing Sigma detection rules against log entries, supporting field modifiers, CIDR matching, and custom field resolvers…

A toy symbolic execution engine, supporting the blog article ...

Reverse engineering of the engine powering the PriPara games on arcade.

A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine…

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

ngxray — nginx config security scanner

Critical Vulnerability (9.8) - RecordedFuture Triage dynamic analysis engine can fail to record malicious behavior when samples produce very…

Code obfuscation, virtualization, and anti-tamper protector for x86-64 Windows binaries (EXE/DLL/SYS) and .NET modules, with beta ELF support.…

Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.


LLVM-based security research toolchain: NeverC, a C23 cross-compiler, and NeverD, a binary analysis and decompilation engine that lifts PE, ELF,…

CVE-2018-19321
