Discovering vulnerabilities in firmware through concolic analysis and function clustering.
-
Updated
Sep 17, 2020 - Python
Discovering vulnerabilities in firmware through concolic analysis and function clustering.
漏洞挖掘神器 | 浏览器插件 | 发现页面和JS中的隐藏接口和敏感信息、URL批量打开 & Vulnerability Mining Tool | Browser Plugin | Discover Hidden Interfaces, Sensitive Information in Pages and JS, Open Multiple URLs | Notepad
A Binary Ninja plugin using backward slicing of variables as a driver for static taint analysis
A project that uses Binary Ninja and GRAKN.AI to perform static analysis on binary files with the goal of identifying bugs in software.
AI 驱动的自主渗透测试平台:输入目标,AI agent 自动完成侦察→规划→主动测试→漏洞验证→报告生成。黑板引擎+多 worker+SRC 验收门禁。仅供学术与安全研究使用。
Outside-in replication of Anthropic's Mythos Preview / Project Glasswing — open-source agentic vulnerability-discovery scaffold on Claude Opus 4.7. Eight-phase sink-guided pipeline, ~$1/run, OSS self-scan and coordinated disclosure.
This search engine automates the discovery of sensitive information using customized dorks across GitHub, Google, and Shodan.
Mythos-class autonomous vulnerability discovery from any strong coding model (Opus 4.7, GPT-5.5, DeepSeek V4, Gemini). Long-running, email-driven, self-distills skills, mutates its own code.
基于 pi 的渗透测试 / SRC 漏洞挖掘 Agent:确定性信息收集 + LLM 编排挖洞 + 漏洞复审 + Vue3 Web 指挥台
A collection of security research papers, tools about monolithic firmware.
Multi-agent vulnerability discovery pipeline following the Project Glasswing / Cloudflare methodology. Hunt, validate, dedupe, trace, and POC vulnerabilities at scale with LLM agents.
PHP/Java/Python/Go/.NET 多语言代码审计 Codex Skill:Source-to-Sink、PoC、修复建议、CNVD/CVE 提交型报告
FirmHound 固件猎犬:IoT 固件漏洞挖掘自动化流水线(挑战杯揭榜挂帅·网络安全赛题第一队作品)。解包→攻击面→二进制分析→静态审计→十维评分→反证验证→动态验证→证据报告。
High-performance, baseline-aware fuzzing and vulnerability discovery framework for multi-target security testing, with adaptive mutation, coverage feedback, corpus management, crash detection, minimization, structured evidence, and reproducible fuzzing campaigns.
This repository contains the source code for our paper "Broken Promises: Measuring Confounding Effects in Learning-based Vulnerability Discovery" that was accepted at AISec '23.
授权安全测试技能库:Tri-Ring 三环并行编排(广度发现 / 深度攻击 / 创造探索 + 仲裁门控)× 四端分仓(Claude Code / Codex / opencode / Pi),31 个主干 skill + 187 个上游方法论弹药库,内置 CNVD/EduSRC 报告模板与提交前证据门禁
Resource repository for Mole
An AI-augmented hybrid fuzzer built on AFL++ to bypass validity barriers in structured parsers. By feeding AFL++ with structurally valid inputs generated via local AI, it penetrates initial validation layers to uncover deep-logic, real-world bugs under a responsible disclosure framework.
三环并行渗透测试 dsh 插件 — discovery/deep/creative 三环 + 独立 verify 闭环,Kuzu 图黑板共享状态,多 agent 自调度、按角色模型策略、自学习知识脑。仅用于授权安全测试(SRC/靶场/自有资产)。
To associate your repository with the vulnerability-discovery topic, visit your repo's landing page and select "manage topics."