
path-auditor
Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

Tools and PoCs for Windows syscall investigation.

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Decompiles serialized V8 bytecode (JSC files) into high-level readable JavaScript-like code, with support for multiple V8 versions, tree output, and…

APKinspector is a powerful GUI tool for analysts to analyze the Android applications.

HardeningMeter is an open-source Python tool carefully designed to comprehensively assess the security hardening of binaries and systems.

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).


A function tracer

A tool that is used to hunt vulnerabilities in x64 WDM drivers

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

C-shellcode to hex converter, handy tool for paste & execute shellcodes in IDA PRO, gdb, windbg, radare2, ollydbg, x64dbg, immunity debugger & 010…

Main repository to pull all NCC Group Cisco ASA-related tool projects.

IDA Pro plugin for query based searching within the binary useful mainly for vulnerability research.

Robber is open source tool for finding executables prone to DLL hijacking

Tool that can be used to trim useless things from a PE file such as the things a file pumper would add.

Patching ROP-encoded shellcodes into PEs