
pefile
pefile is a Python module to read and work with PE (Portable Executable) files

pefile is a Python module to read and work with PE (Portable Executable) files

Extensible debugger UI toolkit providing customizable register, disassembly, stack, memory, breakpoint, and backtrace views for LLDB, GDB, VDB, and…

IDA plugin which queries language models to speed up reverse-engineering

Binary analysis and modification platform for unpacking, analyzing, modifying, and repacking firmware and executable formats via GUI and Python API.

A toolset for reverse engineering and fuzzing Protobuf-based apps

A helper script for unpacking and decompiling EXEs compiled from python code.

Python parser for extracting CobaltStrike Beacon configurations from PE files, memory dumps, and C2 URLs using heuristic XOR decryption and…

BARF : A multiplatform open source Binary Analysis and Reverse engineering Framework

IPython console integration for IDA Pro

Dynamic symbolic execution and binary analysis framework with taint analysis, constraint solving, multi-arch emulation via Ghidra's Sleigh, and…

A reverse engineering framework written in Python.

binary patching from Python

Python Command-Line Ghidra MCP

IDA Python plugin for fast, location-driven matching of open-source library symbols in binaries, enabling efficient reverse engineering and…

An integration for IDA and VS Code which connects both to easily execute and debug IDAPython scripts.

Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks

DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.

Python AV Evasion Tools