
XPEViewer
PE file viewer/editor for Windows, Linux and MacOS.

PE file viewer/editor for Windows, Linux and MacOS.

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Low-level library for encoding and decoding IA32/Intel64 x86 instructions, exposing APIs for instruction length, operands, categories, control-flow…

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

Kernel-mode syscall wrapper with Zydis-based dynamic pattern finding for Windows 10/11

MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools.

Assortment of hashing algorithms used in malware

Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

XMachOViewer is a Mach-O viewer for Windows, Linux and MacOS

Analysis Plugin and Tools for Vivisect

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix…

Select Bugs From Binary Where Pattern Like CVE-1337-Days

Toy scripts for playing with WinDbg JS API

A Binary Genetic Traits Lexer Framework

Use YARA rules on Time Travel Debugging traces