
BinDiffHelper
Ghidra Extension to integrate BinDiff for function matching

Ghidra Extension to integrate BinDiff for function matching

Kernel Driver for x64 Window System which allows you to read/write Virtual/Physical Memory hooking Win32k

KeyPatch Enhanced — IDA Pro plugin for symbol-aware x86/x64 assembly patching, powered by Keystone Engine. Fork of Keypatch with automatic IDA symbol…

Extended kernel lazy importer for Windows drivers that resolves APIs at runtime with encrypted, cached import names to hide kernel function usage…

Reverse engineering write-up of Python shellcode that APC-injects into AnyDesk, exfiltrates to a C2 over HTTPS with AES/RSA, and persists via…

iOS 27 kernelcache RE: SEP dispatch map, AMFI diff, Ghidra workflow

Cross-platform instrumentation and introspection library written in C

Reverse engineer anything with agents, from app behavior down to native binaries.

Binary Ninja plugin that scans glibc libio for FSOP code paths capable of hijacking control flow and stack pointer, aiding heap exploitation research.

Statically compiled ARM binaries for debugging and runtime analysis

Neutralize KEPServerEX anti-debugging techniques

A Coverage Explorer for Reverse Engineers

Binary, coverage-guided fuzzer for Windows, macOS, Linux and Android

Extracts and decrypts inner payloads from Donut obfuscator samples by detecting loader shellcode signatures, parsing the DONUT_INSTANCE structure,…


Statically extracts and decrypts AES-CBC/XOR-obfuscated shellcode from laZzzy-wrapped PE binaries via signature matching and RIP-relative address…

Reverse bytenode .jsc (V8 code cache) to JavaScript — static, pure Rust, no patched V8/Node. Node 8→26 / V8 5.8–14.6; 25k .jsc tested, 0 fail.

Modified luadec version to decompile TP-Link Archer C7 LUA firmware.