vi3tL0u1s/security-research
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
Academic profile page
The PHP Interpreter
The official repository of "GraphSPD: Graph-Based Security Patch Detection with Enriched Code Semantics". The paper will appear in the IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, May 22-26, 2023.
The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!
A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security risks.
A de-socketing tool that is 10x faster than desock (Preeny) in fuzzing network protocols
collection of V8 design documents
Proof of concept & details for CVE-2025-21298
Sourcetrail - free and open-source interactive source explorer
A JavaScript Engine Fuzzer
A collection of out-of-tree LLVM passes for teaching and learning
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
JavaScript Fuzzing framework for v8
Tutorials, examples, discussions, research proposals, and other resources related to fuzzing
Advanced Fuzzing Library - Slot your Fuzzer together in Rust! Scales across cores and machines. For Windows, Android, MacOS, Linux, no_std, ...
This is the replication package of V-SZZ, which has been accepted by ICSE2022
Websec interview questions by tib3rius answered
:orange_book: Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report