
magic-extractor
Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Tool that can be used to trim useless things from a PE file such as the things a file pumper would add.

Frida-based tool that ports Cheat Engine's MonoDataCollector to Android and iOS, enabling runtime Mono/IL2CPP data collection and memory inspection…

Linux process identity cloaking tool that spoofs comm, argv, cmdline, environ, exe path, and VMAs via an 11-phase prctl pipeline to impersonate…

A desktop tool that allows injecting DLLs, hooking WinAPI functions like CreateFileW, and modifying process behavior at runtime — designed for…

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

IDAPython tool for creating automatic C++ virtual tables in IDA Pro


A malware analysis and classification tool.

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

Advanced Static malware analyzer that reveals 8 injection techniques, critical API calls, hidden strings, exports PE sections (.text, .rdata) as…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

The Redexer binary instrumentation framework for Dalvik bytecode

A function tracer

A small utility to deal with malware embedded hashes.

Java bytecode analyzer customizable via JSON rules

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

Watchguard Sysa-dl file format