
sleigh
CMake build of Ghidra's SLEIGH processor specification library, providing standalone disassembly and p-code lifting engines for reverse engineering…

CMake build of Ghidra's SLEIGH processor specification library, providing standalone disassembly and p-code lifting engines for reverse engineering…

Reverse bytenode .jsc (V8 code cache) to JavaScript — static, pure Rust, no patched V8/Node. Node 8→26 / V8 5.8–14.6; 25k .jsc tested, 0 fail.

0-day malware detection for binaries, source & scripts (that doesn't suck)

Agent-native CLI wrapping IDA Pro IDALib for stateless, JSON-output binary analysis: disassembly, Hex-Rays decompilation, CFG, xrefs, strings, and…

Proof-of-concept exploit for CVE-2026-3909, a Chromium Skia out-of-bounds vulnerability, with patches and crash analysis for reliable triggering in…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Fermion, an electron wrapper for Frida & Monaco.

Xyntia, the black-box deobfuscator

x64 Dynamic Reverse Engineering Toolkit

Golang bindings for PE-sieve

A OWASP Based Checklist With 80+ Test Cases

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Pishi is a code coverage tool like kcov for macOS.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.