
VMUnprotect.Dumper
VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Pishi is a code coverage tool like kcov for macOS.

A tool for effective testing the binding layer of scripting languages

Application Hijack Scanner for macOS

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Xyntia, the black-box deobfuscator

GNU IFUNC is the real culprit behind CVE-2024-3094

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Golang bindings for PE-sieve

Scanner: CVE-2026-31431 Linux kernel algif_aead Copy Fail vulnerability checker — Python PoC for heap overflow path

.NET deobfuscator and unpacker.

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Static Binary Instrumentation tool for Windows x64 executables

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

A powerful and user-friendly binary analysis platform!