
NtTrace
An strace-like program for the Windows 'native' API

An strace-like program for the Windows 'native' API

A DTrace on Windows Reimplementation

Time Travel Debugging IDA plugin

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

pyREtic is an extensible framework for in-memory Python 2.x bytecode reverse engineering

x64 Dynamic Reverse Engineering Toolkit

Code Coverage Exploration Plugin for Ghidra

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

Detours implementation (x64/x86) which used only ntdll import

Toy scripts for playing with WinDbg JS API

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

The ARTful library for dynamically modifying the Android Runtime


A tool for effective testing the binding layer of scripting languages

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

YARI is an interactive debugger for YARA Language.

Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.