
polypyus
Binary-only firmware historian that learns to locate functions in raw binaries by extracting known functions from similar binaries, enabling fast…

Binary-only firmware historian that learns to locate functions in raw binaries by extracting known functions from similar binaries, enabling fast…

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

.NET deobfuscator and unpacker.

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

GNU IFUNC is the real culprit behind CVE-2024-3094

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

x64 Dynamic Reverse Engineering Toolkit

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

Code Coverage Exploration Plugin for Ghidra

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Static Binary Instrumentation tool for Windows x64 executables

C/C++ interactive reverse engineering tool for Android applications, enabling fast static analysis and binary inspection of APK files.

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…