#1Tools for dissecting, understanding, and reverse engineering malicious software behavior.
Kitploit recommended

Headless Binary Ninja MCP server — giving AI agents deep reverse-engineering capabilities via 180 tools.

Multi-architecture disassembly framework providing a lightweight, thread-safe API for binary analysis, reverse engineering, and malware research…

A foundational C library for building operationally credible offensive capabilities

Command-line tool that allows you to search for iOS, iPadOS, tvOS, visionOS, and macOS apps on the App Store, and download .ipa or macOS .pkg app…

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

A tool for reverse engineering Android apk files

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

An easy-to-learn/use static analysis framework for Java and Android

MCP server packaging a three-tier penetration-testing methodology: attack-surface reconnaissance, source-to-sink static analysis, and live finding…

.NET Decompiler with support for PDB generation, ReadyToRun, Metadata (&more) - cross-platform!

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Semantic graph-based version control for AI-written code. Tracks entities and relations instead of file diffs, enabling blast radius analysis, shadow…

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.


Research notes and PoC development for CVE-2026-43499 (GhostLock) kernel UAF on vivo Y200i Android 14, covering futex PI-chain stack-reclaim…