
dnSpy
.NET debugger and assembly editor

Fast and accurate AI powered file content types detection


Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

Source code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards…

More than a ReClass port to the .NET platform.


PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

SSMA - Simple Static Malware Analyzer [This project is not maintained anymore by me]

An open source script to perform malware static analysis on Portable Executable

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.

Automatically create YARA rules from malicious documents.

A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing, YARA scanning, and heuristic risk scoring.

A malware analysis and classification tool.

FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis
