
scan
0-day malware detection for binaries, source & scripts (that doesn't suck)

0-day malware detection for binaries, source & scripts (that doesn't suck)

Firmware Analysis and Comparison Tool

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Agent-native CLI wrapping IDA Pro IDALib for stateless, JSON-output binary analysis: disassembly, Hex-Rays decompilation, CFG, xrefs, strings, and…

Reverse bytenode .jsc (V8 code cache) to JavaScript — static, pure Rust, no patched V8/Node. Node 8→26 / V8 5.8–14.6; 25k .jsc tested, 0 fail.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

.NET deobfuscator and unpacker.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

GNU IFUNC is the real culprit behind CVE-2024-3094

Static Binary Instrumentation tool for Windows x64 executables

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

Xyntia, the black-box deobfuscator

The iOS Security Testing Framework

iblessing is an iOS security exploiting toolkit, it mainly includes application information gathering, static analysis and dynamic analysis. It can…