

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Fuzzing Framework for Modules in Apache HTTPD Server

A script to detect stack-strings by using emulation (leveraging Unicorn)

Golang bindings for PE-sieve

通过 jvm 启动参数 以及 jps pid进行拦截非法参数




Laravel debug mode - Remote Code Execution (RCE)

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Runtime Windows API interception library for hooking, monitoring, and instrumenting function calls. Supports binary rewriting and DLL injection,…

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

.NET deobfuscator and unpacker.

Static Binary Instrumentation tool for Windows x64 executables