
goLoL
goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current privilege…

goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current privilege…

Windows link file (shortcuts) examiner

Python dumper/explorer for MCD Runtime Projects used by ODIS

Kernel Stack info leak at exportObjectToClient function

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Analysis Plugin and Tools for Vivisect

Reverse engineering analysis of PureRAT RAT abusing msbuild.exe, extracting C2 infrastructure, .NET evasion APIs, file system manipulation, and…

Proof-of-concept exploit for CVE-2021-1656, an information disclosure vulnerability in the Windows TPM driver (tpm.sys). Demonstrates kernel memory…

iOS Syscall Explorer for IDA 9.X

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public…

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

POC for CVE-2021-1699

POC For CVE-2022-24483

The FreeRDP - Out-of-Bounds Read (CVE-2024-32459) vulnerability concerns FreeRDP, a free implementation of Remote Desktop Protocol. FreeRDP-based…

CVE-2020-25578 and CVE-2020-25579: Some FreeBSD info leak bugs I found in 2020.

cldflt.sys information disclosure vulnerability (KB5034765 - KB5035853, Win 11).

Claude Code skill for reverse-engineering 32-bit little-endian x86 C++ binaries (vtables, RTTI, inheritance recovery)