
fnprint
match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

An strace-like program for the Windows 'native' API

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

An API hooking framework for intercepting and monitoring Windows applications

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

MAPS cloud scanner and response parser for Microsoft Defender research.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Defund the Police.

DNSChef (NG) - DNS proxy for Penetration Testers and Malware Analysts

Golang bindings for PE-sieve

x64 Dynamic Reverse Engineering Toolkit

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

.NET deobfuscator and unpacker.

Remote access trojan created using WinRar with firefox installer and python Reverse Shell embedded.

DNSChef - DNS proxy for Penetration Testers and Malware Analysts