


A static + runtime security scanner for MCP (Model Context Protocol) servers

Obfuscates x86-64 assembly with instruction injection, junk code, constant obfuscation, and runtime decryption to hinder reverse engineering and…

Detects LLM context-leakage attacks by training lightweight behavior probes on log-probabilities, with vLLM offline/server detection pipelines.

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Generates fully valid fake identities in Spanish format, including names, emails, bank details, and extended info, with optional zip compression and…

Obfuscates x86-64 assembly with instruction injection, junk code, constant obfuscation, and runtime decryption to hinder reverse engineering and…


Detects LLM context-leakage attacks by training lightweight behavior probes on log-probabilities, with vLLM offline/server detection pipelines.

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Generates fully valid fake identities in Spanish format, including names, emails, bank details, and extended info, with optional zip compression and…

Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2

Curated collection of payloads for ethical security testing and bug bounty hunting, covering common web vulnerabilities and attack vectors.

A practical framework identifying and prioritizing the top security risks in AI datacenter infrastructure, covering hardware, networking, management…

Modular network scanning framework that integrates diverse tools and external databases to detect vulnerabilities and configuration errors, producing…

The vulnerable application that will teach you how to hack WebSockets

Nuclei template and PoC for exploiting ZooKeeper unauthorized access vulnerability (CVE-2014-085), enabling automated security testing against target…

A sealed benchmark for LLM-driven bug discovery: 77 challenges across 43 open-source projects (C/C++/Java). Each challenge is an answer-free Docker…

Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.

Binary visualiser and triage tool — entropy, byte-class and Hilbert surfaces, dot plots and control-flow graphs over one shared address-space model.

Demonstration of Abusing the Vulnerable driver AmdTools64.sys for Physical R/W.

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…