
Nemesis
.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

Open-source Android client for VirusTotal. Scan files, URLs, and installed apps against 70+ antivirus engines. View detailed reports with hashes,…

Intercept, modify, repeat and attack Android's Binder transactions using Burp Suite

Android Antivirus which doesn't require root, adb, ca install and cloud with many features and ways to detect more zero-day malware

Main repo for hosting release binaries

Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

Endpoint detection & Malware analysis software

Information flow analysis tool for Android applications

Flutter Reverse Engineering Framework

A frida tool to dump dex in memory to support security engineers analyzing malware.

All-in-One malware analysis tool.

Mobile Edge-Dynamic Unified Security Analysis

bash script to facilitate some aspects of an Android application assessment

PoC Frida script to view Android libbinder traffic

Agent Skill for operating renef.io — Android ARM64 dynamic instrumentation: hook native/Java, patch memory, trace syscalls, bypass SSL pinning/root…

Collaborative application security testing between humans and agents via CLI and MCP

Malware Configuration And Payload Extraction