
iMonitor
Endpoint behavior monitoring and analysis system for processes, files, registry, and networks. Supports scripting, extensions, and plugins for…

Endpoint behavior monitoring and analysis system for processes, files, registry, and networks. Supports scripting, extensions, and plugins for…

A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing, YARA scanning, and heuristic risk scoring.

Universal signature generation for any system function from all Windows Builds using Winbindex

Portable Executable reversing tool with a friendly GUI

pefile is a Python module to read and work with PE (Portable Executable) files


PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.

A multi-platform GUI for bit-based analysis, processing, and visualization

Event Trace Log file parser in pure Python

Visually inspect and force decode YARA and regex matches found in both binary and text data with colors. Lots of colors.

A C# based tool for analysing malicious OneNote documents

Tool to help guess a files 256 byte XOR key by using frequency analysis

machofile is a module to parse Mach-O binary files

PowerShellProfiler

UNIX-like reverse engineering framework and command-line toolset

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more

Free educational content on reverse engineering and malware analysis from the FLARE team