
drltrace
Drltrace is a library calls tracer for Windows and Linux applications.

Drltrace is a library calls tracer for Windows and Linux applications.

All reasonably stable tools

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Dumping processes using the power of kernel space !

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

A small utility to deal with malware embedded hashes.

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

DrSemu - Sandboxed Malware Detection and Classification Tool Based on Dynamic Behavior

A lightweight dynamic instrumentation library

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

A revival of the classic and legendary KsDumper

An API hooking framework for intercepting and monitoring Windows applications

Analysis and PoC for CVE-2025-14174 - ANGLE Metal OOB write (iOS Safari, macOS Chrome)

Red Team C code repo

x64 Dynamic Reverse Engineering Toolkit