
VivisectION
Analysis Plugin and Tools for Vivisect

Analysis Plugin and Tools for Vivisect

Step-by-step guide to exploit a buffer overflow in FreeFloat FTP Server using Python fuzzing, Immunity Debugger with mona.py, and IDA Free for binary…

Historical archive of reverse engineering and unpacking tutorials covering commercial protectors (Armadillo, ASProtect, Themida) with classic tools…

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

All reasonably stable tools

CVE-2020-9992 - A design flaw in MobileDevice.framework/Xcode and iOS/iPadOS/tvOS Development Tools allows an attacker in the same network to gain…

List of awesome reverse engineering resources

Record and replay framework for deterministic debugging of multi-threaded applications, enabling reverse execution, hardware watchpoints, and…

Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

ret-sync is a set of plugins that helps to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with IDA/Ghidra/Binary Ninja…

A curated list of IDA x64DBG, Ghidra and OllyDBG plugins.

Full featured multi arch/os debugger built on top of PyQt5 and frida

Some of my publicly available Malware analysis and Reverse engineering.

FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause analysis of smartphone baseband firmwares

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

Multi-engine framework for unpacking and analyzing VM-protected binaries using dynamic taint tracking, symbolic execution, pattern classification,…

SHAREM is a shellcode analysis framework, capable of emulating more than 45,000 WinAPIs and virutally all Windows syscalls. It also contains its own…