
polytracker
An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Static Binary Instrumentation tool for Windows x64 executables

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

An API hooking framework for intercepting and monitoring Windows applications

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

.NET deobfuscator and unpacker.

x64 Dynamic Reverse Engineering Toolkit

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

GNU IFUNC is the real culprit behind CVE-2024-3094

Golang bindings for PE-sieve

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Code Coverage Exploration Plugin for Ghidra

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

Swiss Army knife for raw bytes manipulation & interception