Starred repositories
Ghidra is a software reverse engineering (SRE) framework
A tool for reverse engineering Android apk files
A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
An Android NFC app for reading, writing, analyzing, etc. MIFARE Classic RFID tags.
SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
Quickly find differences and similarities in disassembled code
BinNavi is a binary analysis IDE that allows to inspect, navigate, edit and annotate control flow graphs and call graphs of disassembled code.
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.
jSQL Injection is a Java application for automatic SQL database injection.
A tool to dump Java serialization streams in a more human readable form.
Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.
Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.
WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University Bochum (https://nds.rub.de/ ) and the Hackmanit G…
RMIScout uses wordlist and bruteforce strategies to enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilities