
CAPEv2
Malware Configuration And Payload Extraction

Malware Configuration And Payload Extraction

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Automated hypervisor-level malware analysis sandbox with agentless guest introspection, web-based result exploration, and guided installer for…

Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no…

Live kernel signal observability tool using eBPF tracepoints to stream every signal raised on a Linux host, showing sender, target, disposition,…

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…


A tool for studying JavaScript malware.

Lightweight Windows disassembler, PE inspection and patch-assistance tool for native EXE/DLL files.

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Hex Viewer/Editor/Analyzer compatible with Linux/Windows/MacOS

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

Experimental Linux strace LLM agent

A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.

A modern syscall tracer built on eBPF. Think strace, but with a real TUI, smart filters, TLS decryption, and output that's actually readable.

Free educational content on reverse engineering and malware analysis from the FLARE team

Python-based malware analysis sandbox that integrates with Sysinternals Procmon to automatically collect, analyze, and report runtime indicators with…

Advanced macOS system monitor leveraging Apple Endpoint Security to collect, enrich, and display process, file, memory, and XPC events for malware…