
fnprint
match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

A script to detect stack-strings by using emulation (leveraging Unicorn)

x64 Dynamic Reverse Engineering Toolkit

Golang bindings for PE-sieve

DNSChef (NG) - DNS proxy for Penetration Testers and Malware Analysts

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

Remote access trojan created using WinRar with firefox installer and python Reverse Shell embedded.

An API hooking framework for intercepting and monitoring Windows applications

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

An strace-like program for the Windows 'native' API

MAPS cloud scanner and response parser for Microsoft Defender research.

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Defund the Police.

DNSChef - DNS proxy for Penetration Testers and Malware Analysts

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…