
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

Obfuscates x86-64 assembly with instruction injection, junk code, constant obfuscation, and runtime decryption to hinder reverse engineering and…

Reconstructs legacy Windows binaries into C source by pairing Ghidra decompiler exports with local LLMs, producing compile-checked candidates and…

CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)

iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

Patches Android ARMv8.3 kernel binaries to disable driver signature verification, enabling custom kernel module loading for development and security…

C++ plugin demonstrating an improved anti-debugging concept inspired by VMProtect (formerly AmogusPlugin) for debugger detection and software…

C++ reverse-engineering IDE with PE/ELF parsing, x86/x64 disassembly, Pcode IR, decompilation, function detection, and a Qt GUI.

Obfuscates C/C++ through LLVM passes: string encryption, control-flow flattening, MBA rewriting, and anti-analysis to defeat reverse engineering.

Complete firmware vulnerability analysis for CVE-2020-9373 Netgear R6400 UPnP stack overflow, including unpacking, reverse engineering, static…

Simple Anti-cheat library for applications that use C++ on windows. #PastedProtection

Kernel-mode syscall wrapper with Zydis-based dynamic pattern finding for Windows 10/11

Headless IDA Pro MCP server for AI-assisted binary analysis, powered by idalib

MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools.