
recomposer
Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

BYOVD: Use 360 WFP driver to block EDR/XDR network connection.

IDA Pro plugin that imports runtime-resolved symbols in .NET Native binaries, parsing SharedLibrary.dll and its PDB to restore missing imports for…

GNU IFUNC is the real culprit behind CVE-2024-3094

Golang bindings for PE-sieve

AOSP Bluetooth stack repository modified for CVE-2021-0435, providing a patched or vulnerable version for analysis and testing of Bluetooth…

Android Bluetooth stack (Fluoride) with a specific patch for CVE-2021-0431, enabling analysis and testing of Bluetooth vulnerabilities in AOSP 10.

Android Bluetooth stack (Fluoride) with build instructions for AOSP and Linux, including dependency setup and GN/Ninja build steps.


Free and Open Source Reverse Engineering Platform powered by rizin

A collection of malware samples caught by several honeypots i manage

Course materials for Advanced Binary Deobfuscation by NTT Secure Platform Laboratories

Meltdown Exploit / Proof-of-concept / checks whether system is affected by Variant 3: rogue data cache load (CVE-2017-5754), a.k.a MELTDOWN.

Vulnerability detection framework by Binarly's REsearch team

A dynamic VMP dumper and import fixer, powered by VTIL.

Fuzzes CPU implementations by generating test inputs from software proxies, then executes them on real hardware to detect microarchitecture defects…

Run Beacon Object Files (BOFs) outside Cobalt Strike by parsing 64-bit COFF object files, with Beacon-compatible argument generation and helper…

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…