Orchestrate AI agents to find real vulnerabilities in code.
-
Updated
Jul 23, 2026 - JavaScript
Orchestrate AI agents to find real vulnerabilities in code.
🌐🐧 Browsable Linux kernel syscall tables built with Systrack (https://github.com/mebeim/systrack)
Reverse engineering TikTok's JavaScript VM - 77 opcodes mapped, string deobfuscation, bytecode disassembly, and crypto function identification. Educational VM analysis toolkit.
Complete reverse engineering of PerimeterX (HUMAN Security) anti-bot SDK · pure-algo _px3/_px2 generator (no browser, no Selenium) · iFood + Grubhub + Bundle 10/10 verified · WASM PoW solved · 68 production gotchas · AI Skill included.
An all-in-one Shodan & ZoomEye supported tool to search, browse, preview and dump data leakage across 20+ services. Pulls real exposure straight from the sources instead of guessing. Drop it into your workflow and watch it surface leaks you won't find anywhere else.
hCaptcha hsj/hsw master-key extraction — byte-accurate per build
Bun decompiler-style JavaScript extractor for Bun-compiled executables. Zero-dependency Python tool for reverse engineering, malware analysis, and code recovery.
A professional, high-fidelity de-anonymization and vulnerability diagnostic framework. Features a zero-coupling modular architecture for browser-based intelligence gathering, hardware fingerprinting, and security research.
CVE hunting harness for Claude Code - 20 skills, 5-agent team, systematic vulnerability research with false positive elimination
High-fidelity Claude Fable 5 (Mythos) environment emulation and automated multi-agent jailbreak (Pack Hunt) research laboratory.
These are my tools, the 4ndr0tools.
FeedHenry Mobile Security
Proof of Concept for CVE-2026-23745: Arbitrary File Overwrite vulnerability in node-tar (versions < 7.5.3).
Why Claude Code leaked: a deep dive into npm packaging failures, source map exposure, and modern supply chain security risks.
FexCam | Advanced OSINT & Web API Exposure Tool. Captures Metadata, Geolocation, and Media Streams for security awareness and educational research. Supports Cloudflare & Ngrok.
the PoC that became a product - blocks story seen, DM read, typing indicators, and online presence on Instagram
Offensive security methodology & reference hub for OSCP, OSEP, and red team operators. Full PT lifecycle: recon → AD compromise → privesc → post-exploitation. 8 files, copy-ready commands, curated toolset.
A modular browser telemetry & fingerprinting research toolkit — explores Web APIs, device metadata, sensors, geolocation, media, and storage. Streams collected data via WebSocket and Telegram. Built for authorised security research and browser API experimentation.
Evidence-linked reconstruction of Claude Code internals from the native Bun executable
Decrypt and verify PerimeterX payloads - Client-side decoder for reverse engineering analysis
Add a description, image, and links to the security-research topic page so that developers can more easily learn about it.
To associate your repository with the security-research topic, visit your repo's landing page and select "manage topics."