
DLLirant
DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.


Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

GNU IFUNC is the real culprit behind CVE-2024-3094

Xyntia, the black-box deobfuscator

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

A script to detect stack-strings by using emulation (leveraging Unicorn)

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

.NET deobfuscator and unpacker.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Differential testing framework for HTTP implementations

Sample extensions, scripts, and API uses for WinDbg.

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

An strace-like program for the Windows 'native' API

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

The first analysis framework for CPU microcode

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…