
pefile
pefile is a Python module to read and work with PE (Portable Executable) files

pefile is a Python module to read and work with PE (Portable Executable) files

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

machofile is a module to parse Mach-O binary files

Security Analysis tool for WebAssembly module (wasm) and Blockchain Smart Contracts (BTC/ETH/NEO/EOS)

Parse BIOS/Intel ME/UEFI firmware related structures: Volumes, FileSystems, Files, etc

Build and query a graph database representation of source code

PoC and analysis of a local stack-buffer-overflow in dataSIMS Avionics ARINC 664-1 v4.5.3, with payload breakdown, reproduction script, and CVE…

A PowerShell Module Dedicated to Reverse Engineering

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Ghidra module for disassembling, decompiling, and analyzing Ethereum smart contract bytecode. Detects insecure instructions, extracts hidden methods,…

An IDAPython module for enhancing c++ support on top of ida_kernelcache

Research and proof-of-concept for module stomping, a technique to hide malicious code in legitimate Windows modules, with documentation and…

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

Automated scanner for discovering DLL search order hijacking candidates in Windows executables, featuring import table parsing, runtime module…

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

PowerShell module for automatic detection of P/Invoke, Dynamic P/Invoke, and D/Invoke in .NET assemblies. Reveals unmanaged API calls, MDTokens, and…

nanoMIPS module for Ghidra