
patriot
In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck

Reverse Engineering and Observability toolkit for Draytek firewalls

Collaborative Reverse Engineering plugin for IDA Pro & Hex-Rays

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

This project contains the source code for the CERT Basic Fuzzing Framework (BFF) and the CERT Failure Observation Engine (FOE).

Raw binary firmware analysis software

Minimal Rust project demonstrating CVE-2021-42574 with compile-time behavior differences between patched and vulnerable rustc versions for…

Tools and PoCs for Windows syscall investigation.

Object-oriented Python API to simplify interaction with IDA for reverse engineering, enabling plugin development and automation of disassembly…

Security research project on fuzzing libpng with OSS-Fuzz. Includes seed corpus analysis, custom read/write fuzzers, and a proof-of-concept exploit…

Rust Demangler & Normalizer plugin for IDA

Research project reverse-engineering Windows Security Center COM interfaces to trace AV registration through ATL, vtable, WSCAPI, and RPC, with…

Static config extractor for SmokeLoader samples that deobfuscates, unpacks, and emulates protected routines to recover final-stage C2 settings.

The unofficial Official FirmWare, a complete latest PSP firmware reverse engineering project

idenLib - Library Function Identification [This project is not maintained anymore]

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…