
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

A Chrome extension that demonstrates bypassing Widevine L3 DRM

Command-line and GUI tool for decompiling Android Dex and APK files into readable Java source code, with resource decoding, deobfuscation, and Smali…

Android virtual machine and deobfuscator

Automated hypervisor-level malware analysis sandbox with agentless guest introspection, web-based result exploration, and guided installer for…

A tool that helps you easy trace classes, functions, and modify the return values of methods on iOS platform

Static analysis framework that identifies fuzzable function targets in source code and binaries, generates harness templates, and integrates with…

POC for frustrating/defeating Malware Analysts

Reverse engineering assistant that uses a locally running LLM to aid with pseudocode analysis.

UPX - the Ultimate Packer for eXecutables

Modular GDB interface providing a visual dashboard with customizable panels for inspecting registers, source code, assembly, and program state during…

AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Android APK unpacker that dumps DEX files from running or installed apps on Android 5.0–12 without root, Xposed, or Frida, supporting deep unpacking…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…
