
HexWalk
Hex Viewer/Editor/Analyzer compatible with Linux/Windows/MacOS

Hex Viewer/Editor/Analyzer compatible with Linux/Windows/MacOS

Virtual Machine Introspection, Tracing & Debugging

The Multiplatform Linux Sandbox

BPF-based Linux IPC tracer for pipes, signals, Unix sockets, loopback, and pseudoterminals with metadata and content capture, filtering, and JSON…

Live kernel signal observability tool using eBPF tracepoints to stream every signal raised on a Linux host, showing sender, target, disposition,…

An automatic unpacker and logger for DotNet Framework targeting files

Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no…

A modern syscall tracer built on eBPF. Think strace, but with a real TUI, smart filters, TLS decryption, and output that's actually readable.

Learning Linux Binary Analysis, published by Packt

Modular malware analysis artifact collection and correlation framework

Lightweight macOS malware analysis sandbox that monitors system activity via OpenBSM or Monitor.app, generating detailed reports and timelines of…

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

Lightweight Windows disassembler, PE inspection and patch-assistance tool for native EXE/DLL files.

Experimental Linux strace LLM agent

A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.

Hardware Sandbox Toolkit

This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.