Stars
CTF framework and exploit development library
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC, MIPS, RISC-V 64, a…
Wiki-like CTF write-ups repository, maintained by the community. 2013
Wiki-like CTF write-ups repository, maintained by the community. 2014
Wiki-like CTF write-ups repository, maintained by the community. 2016
A repository for learning various heap exploitation techniques.
Source code of the Coccinelle project (mirror of the main Coccinelle repository located at Inria)
syzkaller is an unsupervised coverage-guided kernel fuzzer
Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)
A wrapper to get de-optimized dex from odex/oat/vdex.
AFWall+ (Android Firewall +) - iptables based firewall for Android
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
POC for CVE-2015-6620, AMessage unmarshal arbitrary write
Community guide to securing and improving privacy on macOS.
A collected list of awesome security talks
Cuckoo Sandbox is an automated dynamic malware analysis system
memdump allows you to dump processes memory at any given time and view its contents. Most programs store critical information in memory that may lead to security breaches. This memory dumper search…
Android Xposed Module to bypass SSL certificate validation (Certificate Pinning).
A rootkit for Android. Based on "Android platform based linux kernel rootkit" from Phrack Issue 68
Google's Python IP address manipulation library
A pattern based Dalvik deobfuscator which uses limited execution to improve semantic analysis
Wiki-like CTF write-ups repository, maintained by the community. 2015
An xposed module that disables SSL certificate checking for the purposes of auditing an app with cert pinning