
pe-bear
Portable Executable reversing tool with a friendly GUI

Portable Executable reversing tool with a friendly GUI

Static analyzer for PE executables with plugin-based detection of packers, compilers, suspicious imports, cryptographic constants, and ClamAV…

Intel Pin-based tracer for API calls, syscalls, and instructions with anti-debug evasion, used for malware analysis and reverse engineering of packed…

A powerful static binary rewriting tool

Simulate the behavior of AV/EDR for malware development training.

Deobfuscator for ConfuserEx 2.

Automated steganography detection tool that scans websites, web servers, and local directories using AI-driven object/text recognition and deep file…

PDB file inspection tool

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

This repository contains an IDA processor for loading and disassembling compiled yara rules.

A disassembler & experimental decompiler for TLOU2 DC Scripts.

An API hooking framework for intercepting and monitoring Windows applications

PETriage: A symbol-unified PE file reader for triage, built for multi-platform and multi-interface use.

Universal signature generation for any system function from all Windows Builds using Winbindex

Command-line and Python debugger for instrumenting and modifying native software behavior on Windows and Linux.

Automated static analysis tools for binary programs

Perform ECDSA and DSA nonce reuse private key recovery attacks to analyze signature vulnerabilities and recover private keys from blockchain…

PE-bear (builds only)