#1Tools for dissecting, understanding, and reverse engineering malicious software behavior.
Kitploit recommended

Proof-of-concept web app built on top of Frida

Circuit-level PDP-11/34 emulator

Binary template repository for 010 Editor, providing .bt scripts for parsing executables, filesystem images, registry hives, and forensic artifacts…

Make an Linux Kernel rootkit visible again.

批量无损检测CVE-2022-22965

A collection of vulnerabilities & exploits against modern GCS

Discover input surfaces and security issues in compiled .NET assemblies — without running them.

A proof-of-concept for CVE-2020-12753

Firmware for Raspberry Pi Pico W that creates a driverless USB Wi-Fi adapter with transparent layer-2 bridging, WPA2/WPA3 authentication, and…

Provides a chat-based, LLM-assisted reverse engineering experience within Ghidra

Technical whitepaper dissecting JioPC cloud VDI architecture, including hardware specs, session termination mechanisms, and security limitations,…

A defense tool - detect web shells in local directories via md5sum

Generative AI-based CyberSecurity-focused Prompt Dataset for Benchmarking Large Language Models

Decrypt and extract FortiOS 8.0.0 firmware images.

GNU IFUNC is the real culprit behind CVE-2024-3094

Select Bugs From Binary Where Pattern Like CVE-1337-Days

100 Days of YARA to be updated with rules & ideas as the year progresses

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…