AhnMo's Stars
microsoft/garnet
Garnet is a remote cache-store from Microsoft Research that offers strong performance (throughput and latency), scalability, storage, recovery, cluster sharding, key migration, and replication features. Garnet can work with existing Redis clients.
microsoft/restler-fuzzer
RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.
radi-cho/awesome-gpt4
A curated list of prompts, tools, and resources regarding the GPT-4 language model.
Storyyeller/Krakatau
Java decompiler, assembler, and disassembler
googleprojectzero/fuzzilli
A JavaScript Engine Fuzzer
lunasec-io/lunasec
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
TalEliyahu/Threat_Model_Examples
A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security risks.
sslab-gatech/pwn2own2020
Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities
Nautilus-Institute/quals-2022
Source code for the 2022 DEF CON Qualifiers.
seleniumhq-community/docker-seleniarm
Multi-Arch (arm64/armhf/amd64) Docker images for the Selenium Grid Server
Samsung/UTopia
UT based automated fuzz driver generation
Song-Li/ODGen
ODGen is a JavaScript Static Analysis tool to detect multiple types of vulnerabilities in Node.js packages.
june5079/soFrida
soFrida - Dynamic Analysis Tool for Mobile Applications
WSP-LAB/FUGIO
FUGIO: Automatic Exploit Generation for PHP Object Injection Vulnerabilities
sefcom/Witcher
Witcher is the first framework for using AFL to fuzz web applications.
prosyslab-classroom/cs524-program-analysis
Nautilus-Institute/finals-2022
Source code for the 2022 DEF CON Finals.
WSP-LAB/HiddenCPG
HiddenCPG: Large-Scale Vulnerable Clone Detection Using Subgraph Isomorphism of Code Property Graphs
WOOSEUNGHOON/V0Finder-public
The repo for V0Finder (Security 21)
WSP-LAB/Link
Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement Learning
mikewest/deprecating-document-domain
`document.domain` intentionally weakens the only security boundary we have. Perhaps we can dump it?
B2R2-org/FunProbe
FunProbe: Probing Functions from Binary Code through Probabilistic Analysis (ESEC/FSE '23)
w3c/secure-the-web-forward-workshop
Materials for a proposed W3C workshop "Secure the Web Forward"
WSP-LAB/DiffCSP
DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential Testing
shhnjk/Safe-Blob-URL
A Web Platform API proposal for Blob URL
Firework471/ClickScanner
WSP-LAB/FUGIO-artifact
aaronxyliu/PTdetector
A chrome extension used for library detection. ASE 2023 paper artifact.
wspr-ncsu/urlparsing-framework
mikewest/purposeful-permissions