
MappedImagesDetector
Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current privilege…

Automated scanner for discovering DLL search order hijacking candidates in Windows executables, featuring import table parsing, runtime module…

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

Program for determining types of files for Windows, Linux and MacOS.

Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

Static Binary Instrumentation tool for Windows x64 executables

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

XMachOViewer is a Mach-O viewer for Windows, Linux and MacOS

🛡️ Open-source binary protection toolkit for Windows PE. Nanomite, VM protection, anti-debug, and more.

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Kernel-mode syscall wrapper with Zydis-based dynamic pattern finding for Windows 10/11

PE file viewer/editor for Windows, Linux and MacOS.

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

Exploit code for CVE-2017-8481, a Windows privilege escalation vulnerability.