
pefile
pefile is a Python module to read and work with PE (Portable Executable) files

pefile is a Python module to read and work with PE (Portable Executable) files

GhostLock One-Tap Execution App (CVE-2026-43499)

An IDAPython module for enhancing c++ support on top of ida_kernelcache

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

Parse BIOS/Intel ME/UEFI firmware related structures: Volumes, FileSystems, Files, etc

Local risk assessment script for CVE-2026-42945 (nginx-rift). Checks version, vulnerable rewrite+set config, ASLR status, and compile hardening to…

Magisk module that auto-packages renef_server (dynamic instrumentation for Android)

Ghidra processor description module for NEC/Renesas v810 and v830 families

machofile is a module to parse Mach-O binary files

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

WinDbg plugin to trace module transitions from a debugged driver.

nanoMIPS module for Ghidra

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Simple Anti-cheat library for applications that use C++ on windows. #PastedProtection

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

Security Analysis tool for WebAssembly module (wasm) and Blockchain Smart Contracts (BTC/ETH/NEO/EOS)

Technical analysis and proof-of-concept bypass for CVE-2023-33668 in DigiExam proctoring software, demonstrating weak VM detection and native module…

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…