#1Tools for dissecting, understanding, and reverse engineering malicious software behavior.
Kitploit recommended

Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for…

indent guides plugin for hex-rays decompiler

PowerShell module for automatic detection of P/Invoke, Dynamic P/Invoke, and D/Invoke in .NET assemblies. Reveals unmanaged API calls, MDTokens, and…

Debugger utilizing stealth hooks to hide from debugger detection


SVG Analysis and generation tools for commonly seen SVG attachment phishing

The fastest LoongArch sandbox

A lightweight hex editor and decompiler to solve your binary file analysis problems.

Go library for parsing and executing Sigma detection rules against log entries, supporting field modifiers, CIDR matching, and custom field resolvers…

Decodes PlugX traffic and encrypted/compressed artifacts

Semantic analysis engine for detecting vulnerability fixes in Windows kernel driver patches — 58 YAML rules, Ghidra decompilation, reachability…

IDA plugin that resolves PPL calls to the actual underlying PPL function.

Detections for CVE-2021-44228 inside of nested binaries

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

An Integrity-Check Monitoring Pintool

A spiritual .NET equivalent to the Gargoyle memory scanning evasion technique

A powerful and flexible tool to apply active attacks for disrupting stegomalware

nanoMIPS module for Ghidra