
IronPE
Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Java bytecode analyzer customizable via JSON rules

PDB file inspection tool

Windows link file (shortcuts) examiner

AndroidDriveSignity is a Python utility designed to bypass driver signature verification in Android kernel(ARMv8.3), facilitating the loading of…

This repository contains an IDA processor for loading and disassembling compiled yara rules.

Extracts and analyzes PE file security characteristics (ASLR, DEP, CFG, NO_SEH) from DLLs and EXEs across directories, storing results in a SQLite…

A disassembler & experimental decompiler for TLOU2 DC Scripts.

A monthly Windows PE baseline dataset for Cyber security researchers

Simple decrypter for Java AdWind, jRAT, jBifrost trojan

Tool that can be used to trim useless things from a PE file such as the things a file pumper would add.

Proof-of-Concept of the CVE-2025-9491 using invisible characters in the arguments of a Windows shortcut file (.lnk)

Zip file format fuzzer and multi-tool.

Static Decryptor for IcedID Malware

Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129

Proof-of-concept exploit for ImageMagick CVE-2017-15277 memory leak vulnerability, designed for use with the gifoeb fuzzing framework.

Analysis for stage1 shellcode loader from hacking

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303