
FalconEye
Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

x64 Dynamic Reverse Engineering Toolkit

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Vulnerability Found on Squid Proxy.

Reproduces fuzzing and crash analysis for CVE-2024-1441 using AFL++ and CASR, with detailed setup and commands for libvirt.

Lightweight library which allows the ability to map both native and managed assemblies into memory by either using process injection of a process…

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

A lightweight dynamic instrumentation library

DrSemu - Sandboxed Malware Detection and Classification Tool Based on Dynamic Behavior

Penetration testing utility and antivirus assessment tool.

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

A dynamic VMP dumper and import fixer, powered by VTIL.

Drltrace is a library calls tracer for Windows and Linux applications.

Red Team C code repo

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

Frida-based in-process fuzzing suite with AFL++ proxy, standalone active/passive modes, and shared memory communication for high-performance…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…