
bindiff
Quickly find differences and similarities in disassembled code

Quickly find differences and similarities in disassembled code

Symbolic verification tool for security protocols using multiset rewriting and constraint solving to prove secrecy, authentication, and equivalence…

Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.

Some bugs found via binary instrumentation and fuzzing

Automated static analysis tools for binary programs

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

N-gram-based type recovery tool for binaries, recovering structures and function signatures from decompiled code with high throughput and actionable…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Generalized VMProtect devirtualizer supporting versions 1.x–3.x. Standalone CLI tool and Ghidra plugin for automated bytecode decoding, handler…

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

Deep Learning models for network traffic classification

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

An automatic obfuscation tool for Android apps that works in a black-box fashion, supports advanced obfuscation features and has a modular…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

The Redexer binary instrumentation framework for Dalvik bytecode

All Security Resource Collections Repos That I Published.

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research