
SnipRecover-CLI
Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

Windows kernel-level debugger with OllyDbg/IDA-style UI, software and hardware breakpoints, PDB symbols, decompiler, and 17 plugins for reverse…

A tool that is used to hunt vulnerabilities in x64 WDM drivers

Zeek plugin to detect and decrypt XOR-encrypted EXEs

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.

A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.

Obfuscate specific windows apis with different apis

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

Manul is a coverage-guided parallel fuzzer for open-source and blackbox binaries on Windows, Linux and MacOS

Static analysis walkthrough of a Metasploit Windows shellcode: PowerShell payload decoding, XOR obfuscation, PEB walking, and Export Address Table…

Swiss Army knife for raw bytes manipulation & interception

Windows artifact analysis toolkit that maps AV detections to PE offsets, sections, RVA/VA and strings, with YARA, AMSI, capa and multi-engine…

Debugger utilizing stealth hooks to hide from debugger detection

PoC Implementation of a fully dynamic call stack spoofer

Reverse engineering research of ASRock AsrDrv103.sys (CVE-2020-15368), covering its driver interface, encrypted request protocol, and privileged…

A Chrome extension that demonstrates bypassing Widevine L3 DRM

ATrace is a tool for tracing execution of binaries on Windows.