
xnuspy
an iOS kernel function hooking framework for checkra1n'able devices

an iOS kernel function hooking framework for checkra1n'able devices

Local risk assessment script for CVE-2026-42945 (nginx-rift). Checks version, vulnerable rewrite+set config, ASLR status, and compile hardening to…

pefile is a Python module to read and work with PE (Portable Executable) files

A PowerShell Module Dedicated to Reverse Engineering

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

machofile is a module to parse Mach-O binary files

WinDbg plugin to trace module transitions from a debugged driver.

This module fixes an issue in the kernels filesystem layer (CVE-2021-33909) by kprobe-replacing vulnerable functions during runtime