
droidbox
Dynamic analysis sandbox for Android apps that monitors network traffic, file operations, cryptographic API usage, permission circumvention, and…

Dynamic analysis sandbox for Android apps that monitors network traffic, file operations, cryptographic API usage, permission circumvention, and…

fireELF - Fileless Linux Malware Framework

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

A pattern based Dalvik deobfuscator which uses limited execution to improve semantic analysis

Automated pre-analysis tool for Android apps that disassembles samples, extracts properties via configurable pattern matching, and organizes output…

Disassemble ANY files including .so (NDK, JNI), Windows PE(EXE, DLL, SYS, etc), linux binaries, libraries, and any other files such as pictures,…

An strace-like program for the Windows 'native' API

Droidefense: Advance Android Malware Analysis Framework

Django application that performs SAST and Malware Analysis for Android APKs

Slide decks from my conference presentations

Windows XP 32-Bit Bootkit

A framework for automated extraction of static and dynamic features from Android applications

Linux Distro for Mobile Security, Malware Analysis, and Forensics



Exploit for the CVE-2023-23397

Malware detection using learning and information retrieval for Android

Fuzzy comparison tool for deobfuscating Android APKs by identifying renamed functions across versions, generating mapping files and interactive HTML…