
flare-vm
A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Semantic analysis engine for detecting vulnerability fixes in Windows kernel driver patches — 58 YAML rules, Ghidra decompilation, reachability…

Detecting vulnerabilities like CVE-2024-0762, particularly in UEFI firmware, is quite challenging due to the low-level nature

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

Multi OS Support: Version for MacOS/Linux and Windows, Fully translated to English

baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Standalone assessment and servicing for the Secure Boot 2011 to 2023 certificate rollover (CVE-2023-24932 / KB5025885). Assess-only by default; no…

AI-powered skill router pack for reverse engineering, penetration testing, and security research. Routes AI agents to correct methodologies and…

Library for lifting machine code to LLVM bitcode

Open-source hardware and software toolkit for reverse-engineering and communicating with infrared-based electronic shelf labels. Includes custom…

Domain-specific language for writing fast functional device models for virtual platforms. Compiles DML to C with API calls tailored for the Intel…

Detection scripts and mitigation resources for the BootHole vulnerability (CVE-2020-10713), including PowerShell and Bash tools to audit EFI System…

WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.

Research tooling to boot Linux on iPad mini 1 via checkm8, patched iBSS/iBEC, and custom bare-metal payloads, including device tree port, kernel…

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

UNIX-like reverse engineering framework and command-line toolset

Raspberry Pi Pico Arduino core, for all RP2040 and RP2350 boards