
fnprint
match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools.

Time Travel Debugging IDA plugin

Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

The first analysis framework for CPU microcode

A DTrace on Windows Reimplementation

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

A script to detect stack-strings by using emulation (leveraging Unicorn)

YARI is an interactive debugger for YARA Language.

Sample extensions, scripts, and API uses for WinDbg.

Fermion, an electron wrapper for Frida & Monaco.

Xyntia, the black-box deobfuscator


Toy scripts for playing with WinDbg JS API

Detours implementation (x64/x86) which used only ntdll import