
VMUnprotect.Dumper
VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

A DTrace on Windows Reimplementation

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

pyREtic is an extensible framework for in-memory Python 2.x bytecode reverse engineering

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis

A verified map of reverse engineering and malware analysis. Disassemblers, unpacking, exploit dev, fuzzing, DFIR, and the deep-cut writeups other…

ioc2rpz is a place where threat intelligence meets DNS.

Detours implementation (x64/x86) which used only ntdll import

Verdict-as-a-Service SDKs: Analyze files for malicious content

Parallel IDA Pro binary analysis with AI-powered function naming, Neo4j knowledge graph, and phantomrt emulation/hooking/fuzzing engine for automated…


match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

YARI is an interactive debugger for YARA Language.

MAPS cloud scanner and response parser for Microsoft Defender research.

Tool for solving BPF filters and crafting packets based on these.