
fnprint
match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

.NET deobfuscator and unpacker.

x64 Dynamic Reverse Engineering Toolkit

Fermion, an electron wrapper for Frida & Monaco.

Detect, analyze and uniquely identify crashes in Windows applications

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Code Coverage Exploration Plugin for Ghidra

Static Binary Instrumentation tool for Windows x64 executables

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Xyntia, the black-box deobfuscator

A tool for effective testing the binding layer of scripting languages

Pishi is a code coverage tool like kcov for macOS.


Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…