
gftrace
A command line Windows API tracing tool for Golang binaries.

A command line Windows API tracing tool for Golang binaries.

Command line tool for scanning streams within office documents plus xor db attack

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

Lightweight RAT providing silent remote command-line access, hidden file download/execution, and persistence mechanisms for Windows systems.…

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Python Command-Line Ghidra MCP

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

machofile is a module to parse Mach-O binary files

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Tool that can be used to trim useless things from a PE file such as the things a file pumper would add.

Public OCI-Image (docker image) Security Checker

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

Proof-of-concept for CVE-2025-55891: heap corruption in TIFFCP.EXE via malformed TIFF file, triggering segmentation fault during LZW decompression in…

Command-line and Python debugger for instrumenting and modifying native software behavior on Windows and Linux.

Ghidra is a software reverse engineering (SRE) framework