
YaraVM
This repository contains an IDA processor for loading and disassembling compiled yara rules.

This repository contains an IDA processor for loading and disassembling compiled yara rules.

Cisco RV110w UPnP stack overflow

A Qt Widgets desktop UI for exploring Python bytecode with pycdc/pycdas, inspecting native decompilation, and using AI fallback for unsupported code…

A Windows runtime analysis toolkit combining memory scanning, debugging, automation, and AI-friendly APIs.

Windows kernel-level debugger with OllyDbg/IDA-style UI, software and hardware breakpoints, PDB symbols, decompiler, and 17 plugins for reverse…

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

Analysis Plugin and Tools for Vivisect

a systems programming language prioritizing verifiable correctness, determinism, and performance

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

Enable Microsoft PDB support in Ghidra without installing Visual Studio

A disassembler & experimental decompiler for TLOU2 DC Scripts.


Local-first, deterministic MCP server for IDA Pro/Home: 109 strict-schema reverse-engineering operations, evidence-backed findings, and policy-gated…

MCP server for automated binary diffing.

An API hooking framework for intercepting and monitoring Windows applications

iOS Syscall Explorer for IDA 9.X

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…