
ARTful
The ARTful library for dynamically modifying the Android Runtime

The ARTful library for dynamically modifying the Android Runtime

Pishi is a code coverage tool like kcov for macOS.

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

A tool for effective testing the binding layer of scripting languages

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

YARI is an interactive debugger for YARA Language.

Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.


Golang bindings for PE-sieve

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Static Binary Instrumentation tool for Windows x64 executables

Time Travel Debugging IDA plugin

Detours implementation (x64/x86) which used only ntdll import


Detect, analyze and uniquely identify crashes in Windows applications

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.