
qvm-tool
Static analysis and structure recovery toolkit for ACE .qvm0-protected PE images

Static analysis and structure recovery toolkit for ACE .qvm0-protected PE images

CMake build of Ghidra's SLEIGH processor specification library, providing standalone disassembly and p-code lifting engines for reverse engineering…

Experimental x86-64 to LLVM IR lifter in Python that translates machine code into analyzable IR for reverse engineering, optimization, and VM handler…

Open source binary analysis framework and decompiler built on LLVM and QEMU, lifting binaries to a readable intermediate representation for reverse…

Greybox Synthesizer geared for deobfuscation of assembly instructions.

Benchmark datasets and synthesis artifacts for QSynth, containing Tigress-obfuscated C functions, x86_64 binaries, execution traces, ground truth,…

IDA 6.8 plugin that devirtualizes Themida's FISH virtual machine (2.2.5.0-2.2.7.0), restoring native code from protected binaries for reverse…

Ghidra Extension to integrate BinDiff for function matching

Extended kernel lazy importer for Windows drivers that resolves APIs at runtime with encrypted, cached import names to hide kernel function usage…

Cross-platform instrumentation and introspection library written in C

Reverse engineer anything with agents, from app behavior down to native binaries.

Statically compiled ARM binaries for debugging and runtime analysis

A Coverage Explorer for Reverse Engineers


Statically extracts and decrypts AES-CBC/XOR-obfuscated shellcode from laZzzy-wrapped PE binaries via signature matching and RIP-relative address…

Reverse bytenode .jsc (V8 code cache) to JavaScript — static, pure Rust, no patched V8/Node. Node 8→26 / V8 5.8–14.6; 25k .jsc tested, 0 fail.

Lua Decompiler for lua 5.1 , 5.2 and 5.3

Windows artifact analysis toolkit that maps AV detections to PE offsets, sections, RVA/VA and strings, with YARA, AMSI, capa and multi-engine…