
NullSection
ELF anti-reversing tool that overwrites section headers with nullbytes to prevent static analysis by disassemblers and debuggers, rendering functions…

ELF anti-reversing tool that overwrites section headers with nullbytes to prevent static analysis by disassemblers and debuggers, rendering functions…

Automated reasoning tool based on the SMACK verifier that detects SGX enclave bugs from trusted boundary violations, including invalid pointer…

IDA plugin that resolves PPL calls to the actual underlying PPL function.

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

Rogue Binary Model Context Protocol (MCP): a Docker-packaged binary analysis lab for AI agents. It supports reverse engineering, malware triage, and…

Magisk module that auto-packages renef_server (dynamic instrumentation for Android)

A game modding utility that makes injecting C/C++ code easier.

A plugin that provides resources for beginners to learn reverse engineering using Binary Ninja. It automatically installs several other plugins, and…

A PyQt5 frontend to the binjatron plugin for Binary Ninja that includes highlighting features aimed at making it easier for beginners to learn about…

This is a little plugin to copy disassembly in a way that is usable in YARA rules!

libtalloc is a python script for use with GDB that can be used to analyse the "trivial allocator" (talloc)

Tool that can be used to trim useless things from a PE file such as the things a file pumper would add.

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

NeuroCore is a native macOS application that visualizes the internal structure of binary files using a Hilbert Curve mapping and Shannon Entropy…

A Binary Ninja plugin that uses bruteforced XFG hashes to recover precise function prototypes

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…