
fnprint
match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)

Headless IDA Pro MCP server for AI-assisted binary analysis, powered by idalib

MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools.

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

Time Travel Debugging IDA plugin

WslinkVMAnalyzer is a tool to facilitate analysis of code protected by a virtual machine featured in Wslink malware

Ressources and papers related to my conferences and work on (un)RASPs. These work is in progress, please be patient :) Don't hesitate to contribute /…

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

Collection of some easy of use tools - in powershell.

A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck

Tools for Linux kernel debugging on Bochs (including symbols, native Bochs debugger and IDA PRO)

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.