
ExportHider
ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

A script to detect stack-strings by using emulation (leveraging Unicorn)

x64 Dynamic Reverse Engineering Toolkit

Golang bindings for PE-sieve

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

.NET deobfuscator and unpacker.

Remote access trojan created using WinRar with firefox installer and python Reverse Shell embedded.

An strace-like program for the Windows 'native' API

MAPS cloud scanner and response parser for Microsoft Defender research.

An API hooking framework for intercepting and monitoring Windows applications

DNSChef - DNS proxy for Penetration Testers and Malware Analysts

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

DNSChef (NG) - DNS proxy for Penetration Testers and Malware Analysts

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

Defund the Police.

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough