#1Tools for dissecting, understanding, and reverse engineering malicious software behavior.
Kitploit recommended

Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands of Windows…
Assortment of hashing algorithms used in malware

Resources to learn more about Chinese-language cybercrime actors.

Datalog-based disassembler producing reassemblable assembly from ELF/PE binaries, with GTIRB intermediate representation for binary analysis and…

Reconstruct and validate C/C++ code from compiled programs with AI.

A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing, YARA scanning, and heuristic risk scoring.

Some setup scripts for security research tools.

Run Radmin VPN on Linux via Wine — custom driver, TAP bridge, zero packet loss

A disassembler & experimental decompiler for TLOU2 DC Scripts.

Hermes Proxy - HTTP Traffic Analyzer

Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your…

Offline scanner for CVE-2026-29000 (CVSS 10.0) in org.pac4j:pac4j-jwt. Inspects jars/fat-jars directly, so it works where mvn dependency:tree cannot.…

Offline Java tool that scans application jars to determine exposure to 14 Netty codec-http CVEs, identifying the exact patched version…

Fully dockerized Linux kernel debugging environment

Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

Signatures and IoCs from public Volexity blog posts.

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…