
HolyGrail
BYOVD hunter to help prioritize windows drivers worth manual analysis

BYOVD hunter to help prioritize windows drivers worth manual analysis

Pointer Sequence Reverser - enable you to see how Windows C++ application is accessing a particular data member or object.

Command-line and Python debugger for instrumenting and modifying native software behavior on Windows and Linux.

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

Kernel-mode syscall wrapper with Zydis-based dynamic pattern finding for Windows 10/11

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Run Radmin VPN on Linux via Wine — custom driver, TAP bridge, zero packet loss

Step-by-step tutorial on using Google's Gemma 4 E4B local AI model to reverse engineer a Windows crackme with Ghidra, including setup for local…

Proof-of-Concept of the CVE-2025-9491 using invisible characters in the arguments of a Windows shortcut file (.lnk)

realtime cross-tool collaborative reverse engineering

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

A tutorial on how to write a packer for Windows!

Research project reverse-engineering Windows Security Center COM interfaces to trace AV registration through ATL, vtable, WSCAPI, and RPC, with…

r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems

Emulates Windows PE execution using Unicorn engine for malware analysis, unpacking packed binaries, and decrypting VMProtect strings and imports.

Penetration testing utility and antivirus assessment tool.

Python AV Evasion Tools