
360WFP_Exploit
BYOVD: Use 360 WFP driver to block EDR/XDR network connection.

BYOVD: Use 360 WFP driver to block EDR/XDR network connection.

BYOVD hunter to help prioritize windows drivers worth manual analysis

Python tool and library to help analyze files during malware triage and analysis.

A Not So Very Intelligent Fuzzer: An advanced fuzzing framework designed to find vulnerabilities in C/C++ code.

my advisory, poc, slides and scripts related to IoT/protocol security

An application to test windows and linux shellcodes

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Lightweight library which allows the ability to map both native and managed assemblies into memory by either using process injection of a process…

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents

A script to detect stack-strings by using emulation (leveraging Unicorn)

Collection of different ways to execute code outside of the expected entry points

Research project related to memory address analysis

Register-level invariant-guided fuzzing framework for closed-source binaries, leveraging likely invariant violations to discover crashes and bugs in…