
sharem
SHAREM is a shellcode analysis framework, capable of emulating more than 45,000 WinAPIs and virutally all Windows syscalls. It also contains its own…

SHAREM is a shellcode analysis framework, capable of emulating more than 45,000 WinAPIs and virutally all Windows syscalls. It also contains its own…

Complete analysis of CVE-2025-21298, a double free vulnerability related to ole32 library in windows.

A technique of hiding malicious shellcode via Shannon encoding.

Ghidra is a software reverse engineering (SRE) framework

ParanoiDF - PDF Analysis Suite based on PeePDF by Jose Miguel Esparza (http://peepdf.eternal-todo.com/). Tools added: Password cracking, redaction…

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix…

A workshop about Malware Development

Some of my publicly available Malware analysis and Reverse engineering.

Tools for the Computer Incident Response Team :computer:

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…


IDA 2016 plugin contest winner! Symbolic Execution just one-click away!

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

Visually inspect and force decode YARA and regex matches found in both binary and text data with colors. Lots of colors.

C++ tool for detecting AnyRun sandbox environments, enabling malware to evade dynamic analysis and automated sandboxing systems.

Binary and Directory tree comparison tool using Fuzzy Hashing