
vulmap
Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

Coverage-guided fuzzer that uses taint tracking and scalar optimization to solve path constraints without symbolic execution, improving branch…

Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

PwnXSS: Vulnerability (XSS) scanner exploit

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

.NET deobfuscator and unpacker.

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

A wrapper around grep, to help you grep for things

Library and CLI for mutating structured data (JSON, XML, X.509) to support grammar-based fuzzing, with multiple mutation strategies and integration…

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Windows NT ioctl bruteforcer and modular fuzzer

A PoC Java Stager which can download, compile, and execute a Java file in memory.

An automatic XSS discovery tool

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

GUI Burp Plugin to ease discovering of security holes in web applications

Acunetix 0day RCE