
CoBRA
Coefficient-Based Reconstruction of Arithmetic — a Mixed Boolean-Arithmetic (MBA) expression simplifier for deobfuscation

Coefficient-Based Reconstruction of Arithmetic — a Mixed Boolean-Arithmetic (MBA) expression simplifier for deobfuscation

Rust Demangler & Normalizer plugin for IDA

Ghidra scripts for recovering string definitions in Go binaries

VBScript & VBA source-to-source deobfuscator with partial-evaluation

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

Analysis of the vulnerability

A collection of small scripts and tools for deobfuscation and malware analysis.

WslinkVMAnalyzer is a tool to facilitate analysis of code protected by a virtual machine featured in Wslink malware

AST-based Python code transformation & deobfuscation framework

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

World's first hazard checker for NVIDIA Blackwell (sm_120), with an assembler and scheduler matched against their own compiler byte for byte. The…

Output high level Pcode (PcodeAST) in Ghidra

C# source-code obfuscator that replaces character and string literals with emojis and randomizes class, interface, method, and variable names using…

CVE-2022-3653 just the c++ component in Vulkan for later study

Lifts x86-64 binary loops into closed-form SMT constraints via strided interval analysis, enabling O(1) symbolic execution and crackme key recovery.

Detaped is a Python disassembler and decompiler for Duktape. The intended use is for source code review and analysis in situations where you only…


Cargo exploit from CVE-2023-38497