
rizin
UNIX-like reverse engineering framework and command-line toolset.

UNIX-like reverse engineering framework and command-line toolset.

AI-powered skill router pack for reverse engineering, penetration testing, and security research. Routes AI agents to correct methodologies and…

pefile is a Python module to read and work with PE (Portable Executable) files

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants

Reconstructs legacy Windows binaries into C source by pairing Ghidra decompiler exports with local LLMs, producing compile-checked candidates and…

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

A True Instrumentable Binary Emulation Framework

Ghidra processor description module for NEC/Renesas v810 and v830 families

scripts/plugins for IDA Pro

Firmware Analysis Tool

Time Travel Debugging IDA plugin

An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general…

Tools to work with android .dex and java .class files

Identifies the bytes that Microsoft Defender flags on.

This repository contains a IDA Python script to recover PrideLocker ESX encryptor strings and a YARA rule

Ressources and papers related to my conferences and work on (un)RASPs. These work is in progress, please be patient :) Don't hesitate to contribute /…