
linux-kernel-debugger
Kernel hardware debugger module for dumping rootkit operations and inspecting kernel-level activity for malware analysis and reverse engineering.

Kernel hardware debugger module for dumping rootkit operations and inspecting kernel-level activity for malware analysis and reverse engineering.

GhostLock One-Tap Execution App (CVE-2026-43499)

Exploit for redirecting control flow of a legit kernel module to your own illegitimate kernel module to evade anti-cheats stack walking

External read-only game overlay for Linux. Derived offsets, composed skeletons, optional kernel module for ptrace-independent memory reads and…

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

machofile is a module to parse Mach-O binary files

An IDAPython module for enhancing c++ support on top of ida_kernelcache

nanoMIPS module for Ghidra

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

Android Malware Tracker

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

Technical analysis and proof-of-concept bypass for CVE-2023-33668 in DigiExam proctoring software, demonstrating weak VM detection and native module…

WinDbg plugin to trace module transitions from a debugged driver.

Ghidra processor description module for NEC/Renesas v810 and v830 families

pefile is a Python module to read and work with PE (Portable Executable) files

GNU Radio out-of-tree (OOT) module for QRadioLink blocks.

Magisk module that auto-packages renef_server (dynamic instrumentation for Android)