
hobbits
A multi-platform GUI for bit-based analysis, processing, and visualization

A multi-platform GUI for bit-based analysis, processing, and visualization

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.

Tool to make in memory man in the middle

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Search for ROP gadgets in ELF, PE, Mach-O, and Raw binaries across x86, ARM, MIPS, and RISC-V architectures. Supports automated ROP chain generation…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

All reasonably stable tools

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

Python Command-Line Ghidra Decompiler

A small utility to deal with malware embedded hashes.

UPX - the Ultimate Packer for eXecutables

Diaphora, the most advanced Free and Open Source program diffing tool.

Multi-architecture assembler framework that converts assembly source into machine code for Arm, x86, MIPS, PowerPC, RISC-V, and more, with a…

Firmware Analysis and Comparison Tool

Intel, AMD, VIA & Freescale Microcode Extraction Tool

A tool to recover a fully analyzable .ELF from a raw kernel, through extracting the kernel symbol table (kallsyms)