
StegoScan
Automated steganography detection tool that scans websites, web servers, and local directories using AI-driven object/text recognition and deep file…

Automated steganography detection tool that scans websites, web servers, and local directories using AI-driven object/text recognition and deep file…


JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current privilege…

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

Windows link file (shortcuts) examiner

CVE-2026-50416: Windows 11 KASLR bypass

Free XP on bug bounty, vulnerability scanning by wrapping well maintained tools, to perform automated tests. Alongside AI agents for binary analysis,…

Python dumper/explorer for MCD Runtime Projects used by ODIS

Kernel Stack info leak at exportObjectToClient function

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.


Reverse engineering analysis of PureRAT RAT abusing msbuild.exe, extracting C2 infrastructure, .NET evasion APIs, file system manipulation, and…

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Proof-of-concept exploit for CVE-2021-1656, an information disclosure vulnerability in the Windows TPM driver (tpm.sys). Demonstrates kernel memory…

iOS Syscall Explorer for IDA 9.X

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public…