
iMonitor
Endpoint behavior monitoring and analysis system for processes, files, registry, and networks. Supports scripting, extensions, and plugins for…

Endpoint behavior monitoring and analysis system for processes, files, registry, and networks. Supports scripting, extensions, and plugins for…

Ghidra plugin that enhances reverse engineering by fixing missed disassembly, detecting functions, labeling crypto constants, and renaming functions…

A Reverse Engineering Tool for py2exe applications.

CERT Kaiju is a binary analysis framework extension for the Ghidra software reverse engineering suite. This repository is a "mirror" -- please file…

Scripts for automating malware analysis and reverse engineering workflows in IDA Pro, covering binary inspection, static analysis, and code…

A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing, YARA scanning, and heuristic risk scoring.

Universal signature generation for any system function from all Windows Builds using Winbindex

Technical analysis of a multi-stage Adobe Acrobat PDF JavaScript sample, detailing environment triage, Acrobat API abuse, and in-memory payload…

RetDec is a retargetable machine-code decompiler based on LLVM.

Portable Executable reversing tool with a friendly GUI

pefile is a Python module to read and work with PE (Portable Executable) files

Static analyzer for PE executables with plugin-based detection of packers, compilers, suspicious imports, cryptographic constants, and ClamAV…

A library for creating, reading and editing PE files and .NET modules.

Xori is an automation-ready disassembly and static analysis library for PE32, 32+ and shellcode

Python parser for extracting CobaltStrike Beacon configurations from PE files, memory dumps, and C2 URLs using heuristic XOR decryption and…


XMachOViewer is a Mach-O viewer for Windows, Linux and MacOS

A machine learning tool that ranks strings based on their relevance for malware analysis.