
drltrace
Drltrace is a library calls tracer for Windows and Linux applications.

Drltrace is a library calls tracer for Windows and Linux applications.

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

IDA 2016 plugin contest winner! Symbolic Execution just one-click away!

Incident Response & Digital Forensics Debugging Extension

Sample extensions, scripts, and API uses for WinDbg.

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

Go-based MITM HTTP/HTTPS proxy with HTTP/2 and HTTP/1.1 interception, local CA/per-host cert generation, CONNECT/WebSocket tunneling, disk caching,…

Obfuscates x86-64 assembly with instruction injection, junk code, constant obfuscation, and runtime decryption to hinder reverse engineering and…

Debugger utilizing stealth hooks to hide from debugger detection

Proof-of-concept exploit for CVE-2025-29824, a use-after-free vulnerability in the Windows CLFS kernel driver, demonstrating privilege escalation to…

PoCs and tools for investigation of Windows process execution techniques

UNIX-like reverse engineering framework and command-line toolset.

Malware Configuration And Payload Extraction

Step-by-step guide to exploit a buffer overflow in FreeFloat FTP Server using Python fuzzing, Immunity Debugger with mona.py, and IDA Free for binary…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

ret-sync is a set of plugins that helps to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with IDA/Ghidra/Binary Ninja…

UNIX-like reverse engineering framework and command-line toolset