
dnSpy
.NET debugger and assembly editor

UNIX-like reverse engineering framework and command-line toolset

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux


ret-sync is a set of plugins that helps to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with IDA/Ghidra/Binary Ninja…

Win32 and Kernel abusing techniques for pentesters

Parse BIOS/Intel ME/UEFI firmware related structures: Volumes, FileSystems, Files, etc

Blackbox Protobuf is a set of tools for working with encoded Protocol Buffers (protobuf) without the matching protobuf definition.


Lifetime AMSI bypass


B2R2 is a fully managed binary analysis framework written in F#. It provides a rich set of algorithms, functions, and tools for reverse engineering,…

A fully functional DanderSpritz lab in 2 commands

Incident Response & Digital Forensics Debugging Extension

Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names.

Automated ROP chain generator for x86-64 binaries using symbolic execution. Supports register/memory writes, function calls, syscalls, badchar…

Efficient Deobfuscation of Linear Mixed Boolean-Arithmetic Expressions

FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis