
fuzzable
Static analysis framework that identifies fuzzable function targets in source code and binaries, generates harness templates, and integrates with…

Static analysis framework that identifies fuzzable function targets in source code and binaries, generates harness templates, and integrates with…

Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

Vibe Reverse Engineer with IDA SQL: An interface for IDA in SQL via live virtual tables

Search for code cave in all binaries

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Proof-of-concept for CVE-2023-4863, a heap buffer overflow in WebP image decoding. Demonstrates the code_lengths trigger mechanism discovered by…

Use IDA PRO HexRays decompiler with OpenAI(ChatGPT) to find possible vulnerabilities in binaries

A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing, YARA scanning, and heuristic risk scoring.

Technical deep-dive and anti-POC for CVE-2022-3602, a punycode buffer overflow in OpenSSL 3.0.x, with reproduction scripts, stack analysis, and…

The Binarly Firmware Hunt (FwHunt) rule format was designed to scan for known vulnerabilities in UEFI firmware.

Psychological warfare in reverse engineering

Binary-only firmware historian that learns to locate functions in raw binaries by extracting known functions from similar binaries, enabling fast…

Tool to make in memory man in the middle

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

Go package that aids in binary analysis and exploitation

Interactive program analysis suite using Code Property Graphs to hunt for bugs in C and C++ code, unifying application-specific and low-level…

Vulnerability research assistant that locates calls to potentially insecure API functions in a binary file.