
Voidgate
A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

makin - reveal anti-debugging and anti-VM tricks [This project is not maintained anymore]

Drltrace is a library calls tracer for Windows and Linux applications.

Multi-engine framework for unpacking and analyzing VM-protected binaries using dynamic taint tracking, symbolic execution, pattern classification,…

SHAREM is a shellcode analysis framework, capable of emulating more than 45,000 WinAPIs and virutally all Windows syscalls. It also contains its own…

A comprehensive binary emulation and instrumentation platform.

Universal mobile devtool for Agents & Humans - control iOS Simulators, Android Emulators, and real devices from a single dashboard and CLI

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Open-source firmware for HydraBus, a multi-tool for embedded hardware debugging, hacking, and penetration testing, supporting protocols like SPI,…

Detect, analyze and uniquely identify crashes in Windows applications

BPF-based Linux IPC tracer for pipes, signals, Unix sockets, loopback, and pseudoterminals with metadata and content capture, filtering, and JSON…

cerberus-re is a local Apple-focused reverse-engineering workbench for building a repeatable three-headed static/dynamic/instrumentation loop around…

Public repository of statically compiled GDB and GDBServer

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Easily retargetable and hackable interactive disassembler with IDAPython-compatible plugin API

helps visualize heap operations for pwn and debugging

Hardware breakpoint hooking engine for Windows that uses debug registers to hook functions, bypass ETW/AMSI, and evade user-land EDR monitoring.

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.