
themida-unmutate
Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.

Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.

The Redexer binary instrumentation framework for Dalvik bytecode

An architecture-agnostic ELF file flattener for shellcode

Native multi-arch disassembler & decompiler - PE/ELF/Mach-O, x86/x64/ARM64, Lua scripting, RTTI recovery

REmatch, a complete binary diffing framework that is free and strives to be open source and community driven.

SAFE embeddings to match functions in yara

find dll base addresses without PEB WALK


Automated scanner for discovering DLL search order hijacking candidates in Windows executables, featuring import table parsing, runtime module…

Python Command-Line Ghidra Decompiler

Automates repair of malformed UPX headers in ELF binaries, restoring magic, filesize, blocksize, and overlay fields so standard unpackers can process…

A function tracer

A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck

Reverse Engineering and Observability toolkit for Draytek firewalls

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

Windows link file (shortcuts) examiner

A small utility to deal with malware embedded hashes.