
progpilot
PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

Rust Weaponization for Red Team Engagements.

Dynamic and static analysis with Real Time Malware Analysis with Antivirus for Windows, including open-source XDR (3 EDR projects), ClamAV, YARA-X,…

Stack overflow in LibXMP

Detailed CVE-2024-55187 advisory with proof-of-concept for a remote code execution vulnerability in phpIpam, exploiting path poisoning and PHAR file…

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Scan code for invisible bidirectional Unicode characters (Trojan Source attack prevention, CVE-2021-42574)

Proof-of-concept exploit for CVE-2021-40905, a remote code execution vulnerability in CheckMK Management Web Console via crafted .mkp extension…

0-day malware detection for binaries, source & scripts (that doesn't suck)

More than a ReClass port to the .NET platform.

A Bitbucket Pipe to trigger SonarCloud analysis

cve-2025-4615 poc & deep dive

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

A collection of my Semgrep rules to facilitate vulnerability research.


Step-by-step technical analysis of CVE-2019-1698, a WordPress plugin SQL injection vulnerability, with code diff review, vulnerable function…