
pefile
pefile is a Python module to read and work with PE (Portable Executable) files

pefile is a Python module to read and work with PE (Portable Executable) files

GhostLock One-Tap Execution App (CVE-2026-43499)

Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

An IDAPython module for enhancing c++ support on top of ida_kernelcache

PoC and analysis of a local stack-buffer-overflow in dataSIMS Avionics ARINC 664-1 v4.5.3, with payload breakdown, reproduction script, and CVE…

Build and query a graph database representation of source code

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

Parse BIOS/Intel ME/UEFI firmware related structures: Volumes, FileSystems, Files, etc

Local risk assessment script for CVE-2026-42945 (nginx-rift). Checks version, vulnerable rewrite+set config, ASLR status, and compile hardening to…

Magisk module that auto-packages renef_server (dynamic instrumentation for Android)

In-depth technical analysis of Linux kernel CVE-2026-31431 (Copy Fail), a local privilege escalation via AF_ALG in-place scatterlist bug, including…

Ghidra processor description module for NEC/Renesas v810 and v830 families

machofile is a module to parse Mach-O binary files

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

WinDbg plugin to trace module transitions from a debugged driver.

nanoMIPS module for Ghidra

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025