
ROPInjector
Patching ROP-encoded shellcodes into PEs

Patching ROP-encoded shellcodes into PEs

C++ tool that patches Windows API calls to bypass sandbox RAM size checks, enabling malware to evade detection in isolated analysis environments.

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

Nim Library for Offensive Security Development

Userland exec PoC to be used as attack vector technique

Platform independent peCloak fork based on Capstone

Windows malware emulation framework that executes binaries, drivers, and shellcode in a modeled runtime, emulating APIs, process/thread behavior,…

Tools and PoCs for Windows syscall investigation.

My musings with PowerShell

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

Some of my publicly available Malware analysis and Reverse engineering.

PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and AV…

helps visualize heap operations for pwn and debugging

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Walk x86-64 page tables by hand in qemu and gdb. Decompose a virtual address, follow cr3 through all levels of physical memory, and extract a flag…

autonomous red teaming platform; multi-agent offensive-security meta-harness

UPX - the Ultimate Packer for eXecutables

CVE-2026-50416: Windows 11 KASLR bypass