
radare2
UNIX-like reverse engineering framework and command-line toolset

UNIX-like reverse engineering framework and command-line toolset

Windows tool for dumping malware PE files from memory back to disk for analysis.

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

GhostLock (CVE-2026-43499) exploit fork for RootMyVivo Neo — iQOO Neo 11 (PD2520, SM8750, 6.6.89). For authorized research on own devices only.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Ghidra is a software reverse engineering (SRE) framework

CVE-2026-43805 IOKit IODMACommand race analysis and proof of concept

External read-only game overlay for Linux. Derived offsets, composed skeletons, optional kernel module for ptrace-independent memory reads and…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Research repository documenting exploitation attempts of CVE-2026-43499 futex UAF on Honor YLP-W00 kernel 6.12.38, including PoC sources, kernel…

Kernel LPE exploit for CVE-2023-6931 on Xiaomi Pad 6 (pipa), chaining a perf read_size overflow to root and disabling SELinux via data-only…

Redacted notes on CVE-2026-28618 / StreamBox APV lab — heap write into a session object via FRAME height mismatch

Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in Android's MatroskaExtractor reachable via a…

memory search and patch tool on debuggable apk without root & ndk

GhostLock (CVE-2026-43499) for OPPO Find X5 Pro (PFEM10) — OPlus watchdog & heap-spray detector reverse engineering

Linux kernel local privilege escalation PoC for CVE-2026-68121, chaining PPPoE, FUSE, and IP6GRE to corrupt kernel memory and gain root.

Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.