
CVE-2026-64705
Root-cause analysis and proof-of-concept for CVE-2026-64705, a macOS HFS xattr kernel heap overflow. Includes weaponized HFS+ image, patcher, parser,…

Root-cause analysis and proof-of-concept for CVE-2026-64705, a macOS HFS xattr kernel heap overflow. Includes weaponized HFS+ image, patcher, parser,…

Ghidra extension for PC firmware reverse engineering, providing loaders for PCI option ROMs, Intel Flash Descriptor, coreboot CBFS, and UEFI firmware…

Reverse-engineered runtime engine for Roblox/Luau with VM hooking, opcode remapping, capability escalation, and UNC script environment for executing…

Unofficial frida extension for VSCode

A Ghidra plugin for locating object file boundaries.

WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.

Microsoft HEIF Extension (msheif_store.dll) OOB-read

An LLM extension for Ghidra to enable AI assistance in RE.

WinDbg plugin to trace module transitions from a debugged driver.

Denial-of-Service PoC | Writeup | Header with CLFS structures | Imhex pattern for .blf extension

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

CERT Kaiju is a binary analysis framework extension for the Ghidra software reverse engineering suite. This repository is a "mirror" -- please file…

Ghidra extension bridging static and dynamic analysis via Frida, enabling scriptable runtime instrumentation for reverse engineering binaries on…

The new bridge between Burp Suite and Frida!

A Chrome extension that demonstrates bypassing Widevine L3 DRM

The FLARE team's open-source extension to add Python 3 scripting to Ghidra.