
lightkeeper
Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Reverse engineering toolkit for PerimeterX's bytecode VM, featuring a CFG-based disassembler, 5-layer decryption pipeline, opcode table…

A BOF designed to inspect processes memory and addresses

Obfuscates C/C++ through LLVM passes: string encryption, control-flow flattening, MBA rewriting, and anti-analysis to defeat reverse engineering.

Process-independent interface to Linux system calls

How to write a CrackMe for a CTF competition. Source code, technical explanation, anti-debugging and anti reverse-engineering tricks.


Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.

Debugger utilizing stealth hooks to hide from debugger detection

A lightweight hex editor and decompiler to solve your binary file analysis problems.

A disassembler & experimental decompiler for TLOU2 DC Scripts.

GNU IFUNC is the real culprit behind CVE-2024-3094

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Select Bugs From Binary Where Pattern Like CVE-1337-Days

A C# PE loader for x64 and x86 PE files.

Solutions and write-ups for Flare-On 11 CTF challenges, showcasing reverse engineering, binary analysis, and malware analysis techniques with…

Proof-of-concept for CVE-2025-27363 demonstrating a heap buffer overflow in FreeType 2.13.0 via a crafted variable font, with ASAN-verified crash…

Toolkit for decoding, inspecting, and modifying UEFI firmware volumes and variable stores. Supports secure boot certificate enrollment, PE binary…