
DECAF
DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

A pattern based Dalvik deobfuscator which uses limited execution to improve semantic analysis

C/C++ interactive reverse engineering tool for Android applications, enabling fast static analysis and binary inspection of APK files.

Disassemble ANY files including .so (NDK, JNI), Windows PE(EXE, DLL, SYS, etc), linux binaries, libraries, and any other files such as pictures,…

Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names.

Binder Trace is a tool for intercepting and parsing Android Binder messages. Think of it as "Wireshark for Binder".


BootStomp: a bootloader vulnerability finder

Fermion, an electron wrapper for Frida & Monaco.

Droidefense: Advance Android Malware Analysis Framework

memory search and patch tool on debuggable apk without root & ndk

Scala-based static analysis framework for Android and Java bytecode with flow analysis, decompilation, and native code analysis via symbolic…

Ninja Reverse Engineering on Android APK packages

Python utility for parsing Xamarin AssemblyStore blob files


The Redexer binary instrumentation framework for Dalvik bytecode

A native APK and DEX decompiler written in Rust

Ressources and papers related to my conferences and work on (un)RASPs. These work is in progress, please be patient :) Don't hesitate to contribute /…