
ifuncd-up
GNU IFUNC is the real culprit behind CVE-2024-3094

GNU IFUNC is the real culprit behind CVE-2024-3094

MCP server bridging Ghidra's reverse engineering with AI tools: 256 tools for decompilation, P-code emulation, live debugging, data flow analysis,…

0-day malware detection for binaries, source & scripts (that doesn't suck)

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Quickly find differences and similarities in disassembled code

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Agent-native CLI wrapping IDA Pro IDALib for stateless, JSON-output binary analysis: disassembly, Hex-Rays decompilation, CFG, xrefs, strings, and…

Standalone PoC for CVE-2026-90782: status-clobbering NULL dereference in S2OPC alloc_notification_message_items() (DataChange fails, Event succeeds)

Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands of Windows…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Xyntia, the black-box deobfuscator

Automatically find and execute fault injection attacks

Display information about files in different file formats and find gadgets to build rop chains for different architectures (x86/x86_64, ARM/ARM64,…

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

x64 PE bin2bin obfuscator which doesn't add a section to the binary

Pishi is a code coverage tool like kcov for macOS.

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…