
aether
Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

PDB file inspection tool

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

Automated reasoning tool based on the SMACK verifier that detects SGX enclave bugs from trusted boundary violations, including invalid pointer…

Tool for solving BPF filters and crafting packets based on these.

N-gram-based type recovery tool for binaries, recovering structures and function signatures from decompiled code with high throughput and actionable…

Python based tool for generating Shellcode from PIC C

ELF anti-reversing tool that overwrites section headers with nullbytes to prevent static analysis by disassemblers and debuggers, rendering functions…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

WslinkVMAnalyzer is a tool to facilitate analysis of code protected by a virtual machine featured in Wslink malware

Lightweight Windows disassembler, PE inspection and patch-assistance tool for native EXE/DLL files.

A tool to extract RTTI information from Delphi executables, written in pure Python

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Tool that can be used to trim useless things from a PE file such as the things a file pumper would add.

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public…