
Brovan
User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Record and replay framework for deterministic debugging of multi-threaded applications, enabling reverse execution, hardware watchpoints, and…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Xyntia, the black-box deobfuscator

Pishi is a code coverage tool like kcov for macOS.

MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools.

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Reproduces the CVE-2026-70638 integer overflow in llama.cpp Android JNI with a safe arithmetic demo, malicious GGUF generator, and Frida hook for…

A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

Detours implementation (x64/x86) which used only ntdll import

Linux ptrace-based process tracing and debugging utility for inspecting system calls, memory, and program execution flow.

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…