
Brovan
User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Source-level debugger for Go with CLI, API, and headless modes; supports breakpoints, variable inspection, and execution tracing for efficient…

Runtime Windows API interception library for hooking, monitoring, and instrumenting function calls. Supports binary rewriting and DLL injection,…

Record and replay framework for deterministic debugging of multi-threaded applications, enabling reverse execution, hardware watchpoints, and…

MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools.

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

Detours implementation (x64/x86) which used only ntdll import

Linux ptrace-based process tracing and debugging utility for inspecting system calls, memory, and program execution flow.

A DTrace on Windows Reimplementation

Tool for reverse engineering macOS/OS X

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

Sample extensions, scripts, and API uses for WinDbg.

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

YARI is an interactive debugger for YARA Language.

Detect, analyze and uniquely identify crashes in Windows applications

Inject code into running Python processes

An Interactive Binary Patching Plugin for IDA Pro