
HookTools
Basic injectable for analyzing the behavior of evasive malware

Basic injectable for analyzing the behavior of evasive malware
IDAPython tool for creating automatic C++ virtual tables in IDA Pro

Tool for reverse engineering macOS/OS X


ATrace is a tool for tracing execution of binaries on Windows.

C-shellcode to hex converter, handy tool for paste & execute shellcodes in IDA PRO, gdb, windbg, radare2, ollydbg, x64dbg, immunity debugger & 010…

ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solutions that clash…

Portable debugger-based crash triage tool for fuzzing outputs. Supports parallel triage, crash deduplication, sanitizer report parsing, and multiple…

A command line Windows API tracing tool for Golang binaries.


Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

N-gram-based type recovery tool for binaries, recovering structures and function signatures from decompiled code with high throughput and actionable…

Lightweight Windows disassembler, PE inspection and patch-assistance tool for native EXE/DLL files.

Record and replay framework for deterministic debugging of multi-threaded applications, enabling reverse execution, hardware watchpoints, and…

BPF-based Linux IPC tracer for pipes, signals, Unix sockets, loopback, and pseudoterminals with metadata and content capture, filtering, and JSON…

Deobfuscator for ConfuserEx 2.

PDB file inspection tool

Terminal UI for real-time monitoring and inspection of eBPF programs and maps using bpftool, enabling live debugging and analysis of kernel-level…