


pefile is a Python module to read and work with PE (Portable Executable) files

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

A library for creating, reading and editing PE files and .NET modules.

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation

x64 PE bin2bin obfuscator which doesn't add a section to the binary

Technical analysis and reproduction of CVE-2023-21716, a critical heap-based buffer overflow in Microsoft Word's RTF parser, including root cause,…

A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.

MAPS cloud scanner and response parser for Microsoft Defender research.

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

machofile is a module to parse Mach-O binary files

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

Asclepius validates backup integrity by restoring files and actively testing their recoverability. Instead of trusting metadata, it attempts to parse…

A python library to parse OneNote (.one) files

Different methods to get current username without using whoami

Yet Another Golang binary parser for IDAPro