Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord
A Precise and General Dynamic Deobfuscation Method for PowerShell Scripts
xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".
利用阿里云oss对象存储,来转发http流量实现(cs)Cobalt Strike、msf 上线等 这之间利用阿里云的相关域名进行通信。
Corax for Java: A general static analysis framework for java code checking.
AutoGeaconC2: 一键读取Profile自动化生成geacon实现跨平台上线CobaltStrike
CodeQL extractor for java, which don't need to compile java source
Runtime code generation for the Java virtual machine.
WebGoat is a deliberately insecure application
obfuscated any constant encryption in compile time on any platform
Unfixed Windows PowerShell Filename Code Execution POC
An implementation and proof-of-concept of Process Forking.
PrintNightmare , Local Privilege Escalation of CVE-2021-1675 or CVE-2021-34527
A faster, simpler way to drive browsers supporting the Chrome DevTools Protocol.
Dumping LSASS with a duplicated handle from custom LSA plugin