
mora-hwbp
Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

POC about how to detect windows kernel debug by pool tag.

MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools.

Time Travel Debugging IDA plugin

Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

The first analysis framework for CPU microcode

A DTrace on Windows Reimplementation

PoCs and tools for investigation of Windows process execution techniques

Tools for Linux kernel debugging on Bochs (including symbols, native Bochs debugger and IDA PRO)

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

YARI is an interactive debugger for YARA Language.

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

Sample extensions, scripts, and API uses for WinDbg.

Fermion, an electron wrapper for Frida & Monaco.


A curated list of IDA x64DBG, Ghidra and OllyDBG plugins.

Toy scripts for playing with WinDbg JS API