
SliverMirage
Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants

Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants

UNIX-like reverse engineering framework and command-line toolset.

Reconstructs legacy Windows binaries into C source by pairing Ghidra decompiler exports with local LLMs, producing compile-checked candidates and…

Time Travel Debugging IDA plugin

Ressources and papers related to my conferences and work on (un)RASPs. These work is in progress, please be patient :) Don't hesitate to contribute /…

asadbg is a framework of tools to aid in automating live debugging of Cisco ASA devices

This repository contains a IDA Python script to recover PrideLocker ESX encryptor strings and a YARA rule


A collection of resources for OSX/iOS reverse engineering.

AI-powered skill router pack for reverse engineering, penetration testing, and security research. Routes AI agents to correct methodologies and…

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

Ghidra processor description module for NEC/Renesas v810 and v830 families

pefile is a Python module to read and work with PE (Portable Executable) files

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Tools to work with android .dex and java .class files

Platform independent peCloak fork based on Capstone

scripts/plugins for IDA Pro