
dnSpy
Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…


Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

Live hunting of code injection techniques

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

Linux 内核VMA-UAF 提权漏洞(CVE-2018-17182),0day

Golang bindings for PE-sieve

Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel…

Research project related to memory address analysis

Escalating privilege in the system from unsigned driver using throttlestop vulnerability

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…