
AsmResolver
A library for creating, reading and editing PE files and .NET modules.

A library for creating, reading and editing PE files and .NET modules.


Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.

MAPS cloud scanner and response parser for Microsoft Defender research.

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

A python library to parse OneNote (.one) files

Yet Another Golang binary parser for IDAPro

CVE-2023-20052 information leak vulnerability in the DMG file parser of ClamAV

CVE-2023-20052, information leak vulnerability in the DMG file parser of ClamAV

Python parser for extracting CobaltStrike Beacon configurations from PE files, memory dumps, and C2 URLs using heuristic XOR decryption and…

Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)