
dissect.cobaltstrike
Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

An automatic unpacker and logger for DotNet Framework targeting files

Memoro: A Detailed Heap Profiler

Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.

Notes, binaries, and related information from analysis of the CVE-2015-7755 & CVE-2015-7756 issues within Juniper ScreenOS

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

A modern syscall tracer built on eBPF. Think strace, but with a real TUI, smart filters, TLS decryption, and output that's actually readable.

asadbg is a framework of tools to aid in automating live debugging of Cisco ASA devices

A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine…

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

Process heap analysis framework - Windows/Linux - record type inference and forensics

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

my advisory, poc, slides and scripts related to IoT/protocol security

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.