
CVE-2023-33668
Technical analysis and proof-of-concept bypass for CVE-2023-33668 in DigiExam proctoring software, demonstrating weak VM detection and native module…

Technical analysis and proof-of-concept bypass for CVE-2023-33668 in DigiExam proctoring software, demonstrating weak VM detection and native module…

Ghidra module for disassembling, decompiling, and analyzing Ethereum smart contract bytecode. Detects insecure instructions, extracts hidden methods,…

Research and proof-of-concept for module stomping, a technique to hide malicious code in legitimate Windows modules, with documentation and…

PowerShell module for automatic detection of P/Invoke, Dynamic P/Invoke, and D/Invoke in .NET assemblies. Reveals unmanaged API calls, MDTokens, and…

nanoMIPS module for Ghidra

Ghidra processor description module for NEC/Renesas v810 and v830 families

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

Kernel hardware debugger module for dumping rootkit operations and inspecting kernel-level activity for malware analysis and reverse engineering.

An IDAPython module for enhancing c++ support on top of ida_kernelcache

GhostLock One-Tap Execution App (CVE-2026-43499)

Security Analysis tool for WebAssembly module (wasm) and Blockchain Smart Contracts (BTC/ETH/NEO/EOS)

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

Parse BIOS/Intel ME/UEFI firmware related structures: Volumes, FileSystems, Files, etc

Magisk module that auto-packages renef_server (dynamic instrumentation for Android)

Simple Anti-cheat library for applications that use C++ on windows. #PastedProtection

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

Automated scanner for discovering DLL search order hijacking candidates in Windows executables, featuring import table parsing, runtime module…

Android frameworks_av module with modifications addressing CVE-2020-0245, a vulnerability in media framework. Provides patched source code for AOSP…