
dr_checker
DR.CHECKER : A Soundy Vulnerability Detection Tool for Linux Kernel Drivers

DR.CHECKER : A Soundy Vulnerability Detection Tool for Linux Kernel Drivers

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

C-based detection tool for CVE-2017-2793, enabling identification and analysis of the specific vulnerability in affected systems.

Automated steganography detection tool that scans websites, web servers, and local directories using AI-driven object/text recognition and deep file…

Simulate the behavior of AV/EDR for malware development training.

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

Static analyzer for PE executables with plugin-based detection of packers, compilers, suspicious imports, cryptographic constants, and ClamAV…

PowerShell module for automatic detection of P/Invoke, Dynamic P/Invoke, and D/Invoke in .NET assemblies. Reveals unmanaged API calls, MDTokens, and…

Generalized VMProtect devirtualizer supporting versions 1.x–3.x. Standalone CLI tool and Ghidra plugin for automated bytecode decoding, handler…

Command-line and GUI tool for decompiling Android Dex and APK files into readable Java source code, with resource decoding, deobfuscation, and Smali…

A tool for reverse engineering Android apk files

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

APKinspector is a powerful GUI tool for analysts to analyze the Android applications.

IDAPython tool for creating automatic C++ virtual tables in IDA Pro

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Windows tool for dumping malware PE files from memory back to disk for analysis.

Robber is open source tool for finding executables prone to DLL hijacking