
silifuzz
Fuzzes CPU implementations by generating test inputs from software proxies, then executes them on real hardware to detect microarchitecture defects…

Fuzzes CPU implementations by generating test inputs from software proxies, then executes them on real hardware to detect microarchitecture defects…

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Symbolic execution tool

A tool that is used to hunt vulnerabilities in x64 WDM drivers

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Binary Ninja plugin to identify obfuscated code and other interesting code constructs

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

Detection of malicious VHD files for CVE-2025-24985

A tool to detect and crash Cuckoo Sandbox

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…

Detect images that likely exploit CVE-2022-44268

Linux Kernel Runtime Integrity with eBPF

An eBPF program to detect attacks on CVE-2022-0847