
ComfyEngine
ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

.NET Decompiler with support for PDB generation, ReadyToRun, Metadata (&more) - cross-platform!

Source-level debugger for Go with CLI, API, and headless modes; supports breakpoints, variable inspection, and execution tracing for efficient…

Multi-architecture disassembly framework providing a lightweight, thread-safe API for binary analysis, reverse engineering, and malware research…

Record and replay framework for deterministic debugging of multi-threaded applications, enabling reverse execution, hardware watchpoints, and…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Runtime Windows API interception library for hooking, monitoring, and instrumenting function calls. Supports binary rewriting and DLL injection,…

Plasma is an interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax.

MCP Server for Ghidra

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Memory Debugger for Windows, Linux, Mac, and Android

MCP server bridging Ghidra's reverse engineering with AI tools: 256 tools for decompilation, P-code emulation, live debugging, data flow analysis,…

Library for lifting machine code to LLVM bitcode

Low-level library for encoding and decoding IA32/Intel64 x86 instructions, exposing APIs for instruction length, operands, categories, control-flow…

Hex-Rays Decompiler plugin for better code navigation

IDAPython tool for creating automatic C++ virtual tables in IDA Pro

Python decompiler for 3.7-3.8 Stripped down from uncompyle6 so we can refactor and start to fix up some long-standing problems

Exploitation script for exposed Java Debug Wire Protocol (JDWP) services, enabling pentesters to inject Java code and execute arbitrary OS commands…