
Process-Dump
Windows tool for dumping malware PE files from memory back to disk for analysis.

Windows tool for dumping malware PE files from memory back to disk for analysis.

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

x64 Dynamic Reverse Engineering Toolkit

A revival of the classic and legendary KsDumper

Binary-level directed fuzzer specialized in detecting Use-After-Free vulnerabilities via ordering-aware input metrics and static analysis, enabling…

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Proof of concept & details for CVE-2025-21298

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

Process heap analysis framework - Windows/Linux - record type inference and forensics

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Xyntia, the black-box deobfuscator

Pishi is a code coverage tool like kcov for macOS.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…