
NtWarden
Windows Analysis and Research Toolkit

Windows Analysis and Research Toolkit

Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks

An open source script to perform malware static analysis on Portable Executable

Extract Windows Defender database from vdm files and unpack it

REmatch, a complete binary diffing framework that is free and strives to be open source and community driven.

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

A Full-Featured HexEditor compatible with Linux/Windows/MacOS

Native multi-arch disassembler & decompiler - PE/ELF/Mach-O, x86/x64/ARM64, Lua scripting, RTTI recovery

SAFE embeddings to match functions in yara

Automates repair of malformed UPX headers in ELF binaries, restoring magic, filesize, blocksize, and overlay fields so standard unpackers can process…

A function tracer

Java bytecode analyzer customizable via JSON rules

Traces user inputs to detect injection vulnerabilities in Java methods via JDWP and Frida, identifying potential command and SQL injection points.

Advanced Static malware analyzer that reveals 8 injection techniques, critical API calls, hidden strings, exports PE sections (.text, .rdata) as…

Obfuscates x86-64 assembly with instruction injection, junk code, constant obfuscation, and runtime decryption to hinder reverse engineering and…

IDA python scripts to decrypt strings from KPOT and set those as comments

Scans an executable and determines if it was wrapped in an Electron version vulnerable to the Chromium vulnerability CVE-2023-4863/ CVE-2023-5129

Watchguard Sysa-dl file format