
Fix-Apple-Mail-CVE-2020-9922
Patches the zero-click Apple Mail vulnerability (CVE-2020-9922) on macOS, preventing remote code execution without user interaction.

Patches the zero-click Apple Mail vulnerability (CVE-2020-9922) on macOS, preventing remote code execution without user interaction.

Android Reverse-Engineering Workbench for VS Code

Android virtual machine and deobfuscator

Yet another static code analyzer for malicious Android applications

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Expose USB activity on the fly

Collection of malware source code for a variety of platforms in an array of different programming languages.

Red Team C code repo

LetsDefend SOC336 case study on CVE-2025-21298

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Example InSpec profile to detect presence of a malicious rest-client gem (CVE-2019-15224)

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

Don't Just Search OSINT. Sweep It.

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

Ressources and papers related to my conferences and work on (un)RASPs. These work is in progress, please be patient :) Don't hesitate to contribute /…

Windows BYOVD research on DCRCVDrv.sys and Alinubx.sys, reverse engineering their kernel primitives, IOCTL surfaces, and detection opportunities.