
DLLirant
DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Detours implementation (x64/x86) which used only ntdll import

Windows NT ioctl bruteforcer and modular fuzzer

The first analysis framework for CPU microcode

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Toy scripts for playing with WinDbg JS API

A PoC Java Stager which can download, compile, and execute a Java file in memory.

Pishi is a code coverage tool like kcov for macOS.

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

The ARTful library for dynamically modifying the Android Runtime

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…


Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

A tool for effective testing the binding layer of scripting languages

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.