
CVE-2024-7344
Technical research on a UEFI Secure Boot bypass caused by an unsafe custom PE loader, including root-cause analysis, exploitation workflow, and an…

Technical research on a UEFI Secure Boot bypass caused by an unsafe custom PE loader, including root-cause analysis, exploitation workflow, and an…

Generates anti-copy malware launchers using Process Ghosting to bypass AV/EDR signature scanning and prevent automatic sample submission. Supports…

Proof-of-concept demonstrating a Windows Defender bypass technique for CVE-2026-5000, intended for controlled testing and defensive research.

Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload.

A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to evade…

Fuzzy comparison tool for deobfuscating Android APKs by identifying renamed functions across versions, generating mapping files and interactive HTML…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Ghidra is a software reverse engineering (SRE) framework

A collection of android security related resources

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Yet another static code analyzer for malicious Android applications

Tool for leaking and bypassing Android malware detection system

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.


Golang bindings for PE-sieve

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

An A/V evasion armoring experiment for CVE-2012-4681