#1Tools for dissecting, understanding, and reverse engineering malicious software behavior.
Kitploit recommended

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…
The RF and reverse engineering framework for everyone. Follow and ★ to show your support!

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

Standalone MCP server plugin for IDA Pro.

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

Dynamic and static analysis with Real Time Malware Analysis with Antivirus for Windows, including open-source XDR (3 EDR projects), ClamAV, YARA-X,…

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Device-specific Linux 5.10 kernel root exploit for Sharp AQUOS R7 (CVE-2026-43499), granting temporary UID 0 with SELinux permissive and an su daemon.

No-root network monitor, firewall and PCAP dumper for Android

A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Sandbox untrusted code with safe access to the host.

Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI…

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

A language and library for specifying syscall filtering policies.