
Xiaomi-C200-Firmware-Analysis
From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

Reverse engineering analysis of DarkTortilla RAT, a sophisticated malware that steals credit card data, decrypts browser passwords, and exfiltrates…

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

A frida script implement XposedBridge & load xposed modules, without installing xposed framwork.

Reverse engineering analysis of AcrStealer, a sophisticated info-stealer that uses custom protocols, browser credential theft, and payload…

A plugin to introduce interactive symbols into your debugger from your decompiler

An extensible, end-to-end encrypted reverse shell that works across networks without port forwarding.

C++ library to load DLLs directly from memory without touching disk, with exception handling support, enabling stealthy code execution and evasion of…

Binary-only firmware historian that learns to locate functions in raw binaries by extracting known functions from similar binaries, enabling fast…

🕵️ Tool to reverse-engineer Protocol Buffers with unknown definition

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Kernel-mode syscall wrapper with Zydis-based dynamic pattern finding for Windows 10/11

Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.

Run iOS apps without actually installing them!

Visualizes repeated byte sequences in binary files to reveal hidden structure, supporting reverse engineering and pattern discovery without…

GhostLock One-Tap Execution App (CVE-2026-43499)

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…