
ExportHider
ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

A script to detect stack-strings by using emulation (leveraging Unicorn)


Golang bindings for PE-sieve

A Android malware analysis tool that creates comprehensive runtime profiles by hooking into application behavior across cryptography, file systems,…

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

Extract the managed (.NET) assemblies out of a MAUI Android assembly store.

Linux ptrace-based process tracing and debugging utility for inspecting system calls, memory, and program execution flow.

frida-stalker based system call tracer on windows(x64).

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

.NET deobfuscator and unpacker.

DEX → Java decompiler in Rust — fast, progressive analysis, bilingual CLI

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Static Binary Instrumentation tool for Windows x64 executables

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…