Showing 24 of 24 projects
A software reverse engineering framework for analyzing compiled code across multiple platforms, offering disassembly, decompilation, and scripting.
Course materials for a university-level class on vulnerability research, reverse engineering, and binary exploitation.
A university course repository teaching vulnerability research, reverse engineering, and binary exploitation through hands-on labs.
A curated list of resources for learning about vehicle security, car hacking, and automotive tinkering.
A library and tool to generate PHP unserialize() payloads for exploiting gadget chains in popular frameworks.
A curated collection of proof-of-concept exploits for Common Vulnerabilities and Exposures (CVEs).
A curated collection of disclosed Android security reports from HackerOne and educational resources for vulnerability research.
A comprehensive tutorial series on modern Linux binary exploitation techniques, from stack overflows to heap vulnerabilities.
A command-line utility for performing hash length extension attacks against vulnerable cryptographic hash functions.
A curated collection of resources for security research, vulnerability discovery, and pentesting of Electron.js applications.
A curated list of Bluetooth security resources covering vulnerabilities, tools, research, and conference talks for BR/EDR, LE, and Mesh.
A curated collection of offensive security research, techniques, and tools for attacking CI/CD pipelines and software supply chains.
Research presentation and paper analyzing prototype pollution attacks in Node.js, presented at NorthSec 2018.
A binary diffing and patch analysis tool for reverse engineering and vulnerability research.
A curated collection of CVEs, research, tools, and resources for WebSocket security testing and vulnerability research.
An improved exploit implementation for CVE-2016-6366 (EXTRABACON) targeting Cisco ASA devices with extended version support.
A reverse engineering assistant that uses a locally running LLM to analyze Hex-Rays pseudocode for improved code understanding.
A fast IDA Pro headless plugin that extracts decompiled pseudocode for vulnerability research and static analysis.
A fast IDA Pro plugin that finds calls to insecure API functions in binaries to aid vulnerability research.
A type-aware kernel fuzzing framework for Windows that uses static binary analysis to infer system call types for more effective fuzzing.
A fast IDA Pro headless plugin that extracts strings and related pseudocode from binary files for reverse engineering.
A honeypot that detects and logs exploitation attempts targeting the Log4Shell vulnerability (CVE-2021-44228).
A repository containing Cure53's security audit reports, white papers, academic publications, and security tools.
A collection of security tools, exploits, proof-of-concept code, shellcodes, and scripts for educational purposes.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.