
flare-vm
A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Drltrace is a library calls tracer for Windows and Linux applications.

Technical analysis and proof-of-concept exploit for CVE-2023-28252, a Windows Common Log File System (CLFS) driver privilege escalation vulnerability…

idenLib - Library Function Identification [This project is not maintained anymore]

An Interactive Binary Patching Plugin for IDA Pro

SoftICE-like kernel debugger for Windows 11

POC about how to detect windows kernel debug by pool tag.

Elevates a low-privilege Windows process to SYSTEM via a gdb-assisted ROP token-swap chain, demonstrating CVE-2026-62737 in a lab-only QEMU…

Pointer Sequence Reverser - enable you to see how Windows C++ application is accessing a particular data member or object.

Command-line and Python debugger for instrumenting and modifying native software behavior on Windows and Linux.

Step-by-step tutorial on using Google's Gemma 4 E4B local AI model to reverse engineer a Windows crackme with Ghidra, including setup for local…

Hardware breakpoint hooking engine for Windows that uses debug registers to hook functions, bypass ETW/AMSI, and evade user-land EDR monitoring.

IDA Pro utilities from FLARE team

Windows kernel-level debugger with OllyDbg/IDA-style UI, software and hardware breakpoints, PDB symbols, decompiler, and 17 plugins for reverse…

A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.

Proof-of-concept exploit for CVE-2025-29824, a use-after-free vulnerability in the Windows CLFS kernel driver, demonstrating privilege escalation to…

Educational lab documenting step-by-step exploitation of CVE-2025-5548 (Stack Buffer Overflow) on Windows 11, from fuzzing and crash analysis to…

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…