
NtDetours
Detours implementation (x64/x86) which used only ntdll import

Detours implementation (x64/x86) which used only ntdll import

The ARTful library for dynamically modifying the Android Runtime

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…


Windows NT ioctl bruteforcer and modular fuzzer

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

GUI Burp Plugin to ease discovering of security holes in web applications

Pishi is a code coverage tool like kcov for macOS.

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

A tool for effective testing the binding layer of scripting languages

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

A collection of useful resources for hacking WordPress and it's plugins and themes

YARI is an interactive debugger for YARA Language.

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

GNU IFUNC is the real culprit behind CVE-2024-3094