
cve-2020-35498-flag
C-based exploit tool to detect and trigger CVE-2020-35498 via raw socket injection with BPF filter, targeting wireless interfaces for vulnerability…

C-based exploit tool to detect and trigger CVE-2020-35498 via raw socket injection with BPF filter, targeting wireless interfaces for vulnerability…

Rust-based tool to detect and mitigate CVE-2024-39930 ptrace exploitation, providing binary-level analysis and defensive countermeasures for Linux…

A dynamic unpacking tool

Ghidra plugin that enhances reverse engineering by fixing missed disassembly, detecting functions, labeling crypto constants, and renaming functions…

Program for determining types of files for Windows, Linux and MacOS.

Symbolic execution tool

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

A tool that is used to hunt vulnerabilities in x64 WDM drivers

Detect images that likely exploit CVE-2022-44268

Exploit for CVE-2022-4510 enabling remote command execution in Binwalk firmware analysis tool. Provides proof-of-concept code for security testing…

Generalized VMProtect devirtualizer supporting versions 1.x–3.x. Standalone CLI tool and Ghidra plugin for automated bytecode decoding, handler…

C library for stream-oriented XML parsing, providing handlers for parsing structures in documents. Includes xmlwf tool and supports UTF-16 encoding.

Lightweight Windows disassembler, PE inspection and patch-assistance tool for native EXE/DLL files.

An eBPF program to detect attacks on CVE-2022-0847

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks