
HyperDeceit
HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.

🪅 Windows & Linux userspace emulator

Tool for reverse engineering macOS/OS X

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

GNU IFUNC is the real culprit behind CVE-2024-3094

NeuroCore is a native macOS application that visualizes the internal structure of binary files using a Hilbert Curve mapping and Shannon Entropy…

Generate Objective-C headers from Mach-O files.

iOS and macOS Decompiler

a Ghidra framework for iOS kernelcache reverse engineering

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.

FairPlay decryptor (dump iPA) for iOS Application that running on macOS with SIP-enabled, using CVE-2025-24204. Support macOS 15.0-15.2

An IDAPython module for enhancing c++ support on top of ida_kernelcache

IDA plugin that resolves PPL calls to the actual underlying PPL function.

An updated Frida iOS dump tool supporting the latest Frida 17.5.2 APIs

CVE-2026-43805 IOKit IODMACommand race analysis and proof of concept