
FlowName
Next-generation JavaScript identifier recovery with LLMs.

Next-generation JavaScript identifier recovery with LLMs.

0-day malware detection for binaries, source & scripts (that doesn't suck)

Multi-format malware analysis platform combining a stealth Ring-3 Windows sandbox, static PE/PDF analyzers, ransomware key recovery, and an AI…

A machine learning tool that ranks strings based on their relevance for malware analysis.

Reconstructs legacy Windows binaries into C source by pairing Ghidra decompiler exports with local LLMs, producing compile-checked candidates and…

Android Antivirus which doesn't require root, adb, ca install and cloud with many features and ways to detect more zero-day malware

A Binary Genetic Traits Lexer Framework

A Ghidra plugin for locating object file boundaries.

LLM powered fuzzing via OSS-Fuzz.

Plugin for Binary Ninja that integrates local Ollama models to rename functions and variables in decompiled HLIL code, preserving privacy by keeping…

For our CCS24 paper 🏆 "ReSym: Harnessing LLMs to Recover Variable and Data Structure Symbols from Stripped Binaries" by Danning Xie, Zhuo Zhang, Nan…

Reverse Engineering: Decompiling Binary Code with Large Language Models

IDA plugin which queries language models to speed up reverse-engineering

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Image-based Android malware detection framework tackling obfuscation and concept drift. Includes curated datasets and Python code for training…

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…


Python library for local LLM-powered security analysis with Ghidra binary analysis, C/C++ vulnerability scanning, and MCP tool integration for…