
lightkeeper
Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Xyntia, the black-box deobfuscator

Pishi is a code coverage tool like kcov for macOS.

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

GNU IFUNC is the real culprit behind CVE-2024-3094

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Static Binary Instrumentation tool for Windows x64 executables

Code Coverage Exploration Plugin for Ghidra

Golang bindings for PE-sieve

x64 Dynamic Reverse Engineering Toolkit

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

A tool for effective testing the binding layer of scripting languages