
draytek-arsenal
Reverse Engineering and Observability toolkit for Draytek firewalls

Reverse Engineering and Observability toolkit for Draytek firewalls

Droidefense: Advance Android Malware Analysis Framework

An architecture-agnostic ELF file flattener for shellcode

A tool to extract RTTI information from Delphi executables, written in pure Python

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Security profiling for blackbox iOS

A tool that automatically creates fuzzing harnesses based on a library

PowerShell module for automatic detection of P/Invoke, Dynamic P/Invoke, and D/Invoke in .NET assemblies. Reveals unmanaged API calls, MDTokens, and…

C library for stream-oriented XML parsing, providing handlers for parsing structures in documents. Includes xmlwf tool and supports UTF-16 encoding.

IDA Pro plugin for query based searching within the binary useful mainly for vulnerability research.

Binary and Directory tree comparison tool using Fuzzy Hashing

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

The Redexer binary instrumentation framework for Dalvik bytecode

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

Write your BPF programs in Go, not C. gobee transpiles a Go subset to BPF C and generates typed cilium/ebpf bindings.

A machine learning tool that ranks strings based on their relevance for malware analysis.

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies