
radare2
UNIX-like reverse engineering framework and command-line toolset

UNIX-like reverse engineering framework and command-line toolset

Ghidra is a software reverse engineering (SRE) framework

Reverse engineering framework with disassembly, decompilation, taint analysis, version diffing and semantic search, plus LLM-driven autonomous binary…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

An API hooking framework for intercepting and monitoring Windows applications

Image-based Android malware detection framework tackling obfuscation and concept drift. Includes curated datasets and Python code for training…

Framework for hashing declared permissions in Chromium extensions and APKs, enabling clustering, hunting, and pivoting across potentially malicious…

Static and dynamic Android application security analysis

A machine learning malware analysis framework for Android apps.

Android Malware Tracker

Cisco ASA Software and ASDM Security Research

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

A simple and scalable Android bot emulation framework, as presented at Black Hat Europe 2021's Arsenal, as well as atHack 2021's Arsenal

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis