
AutoPiff
Semantic analysis engine for detecting vulnerability fixes in Windows kernel driver patches — 58 YAML rules, Ghidra decompilation, reachability…

Semantic analysis engine for detecting vulnerability fixes in Windows kernel driver patches — 58 YAML rules, Ghidra decompilation, reachability…

RetDec is a retargetable machine-code decompiler based on LLVM.

Static analyzer for PE executables with plugin-based detection of packers, compilers, suspicious imports, cryptographic constants, and ClamAV…

Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.

Create Anti-Copy DRM Malware

Technical Analysis of Bibi-Windows Wiper Targeting Israeli Organizations

Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

SoftICE-like kernel debugger for Windows 11

An application to test windows and linux shellcodes

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

Generates LNK files with crafted _IDCONTROLW structures to research Windows Shell spoofing vulnerabilities CVE-2026-21510 and CVE-2026-32202,…

Tools and PoCs for Windows syscall investigation.

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

BYOVD research performed by KOSEC. Includes vulnerable drivers and writeups (CVE-2026-0828).

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

Library to access the Windows Shell Item format

C++ tool that patches Windows API calls to bypass sandbox RAM size checks, enabling malware to evade detection in isolated analysis environments.