
fnprint
match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Build and query a graph database representation of source code

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

An API hooking framework for intercepting and monitoring Windows applications

GNU IFUNC is the real culprit behind CVE-2024-3094

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

A proxy for net.tcp-based WCF traffic.

Windows named pipe hooking toolkit

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths,…

Vulnerability Found on Squid Proxy.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Static Binary Instrumentation tool for Windows x64 executables

Frida-based in-process fuzzing suite with AFL++ proxy, standalone active/passive modes, and shared memory communication for high-performance…

Generate a proxy dll for arbitrary dll

Code Coverage Exploration Plugin for Ghidra

Golang bindings for PE-sieve