
drakvuf-sandbox
Automated hypervisor-level malware analysis sandbox with agentless guest introspection, web-based result exploration, and guided installer for…

Automated hypervisor-level malware analysis sandbox with agentless guest introspection, web-based result exploration, and guided installer for…

A Full-Featured HexEditor compatible with Linux/Windows/MacOS

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

WinDbg plugin for automated malware dynamic analysis and IOC extraction. Executes within the debugger to collect predefined indicators and writes…

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

More than a ReClass port to the .NET platform.

Malware Configuration And Payload Extraction

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

My musings with PowerShell


Python Decoders for Common Remote Access Trojans

Free educational content on reverse engineering and malware analysis from the FLARE team

A PowerShell Module Dedicated to Reverse Engineering

Python-based malware analysis sandbox that integrates with Sysinternals Procmon to automatically collect, analyze, and report runtime indicators with…

A tool for studying JavaScript malware.

AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and…

Advanced macOS system monitor leveraging Apple Endpoint Security to collect, enrich, and display process, file, memory, and XPC events for malware…