
dotnetfile
Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

A library for creating, reading and editing PE files and .NET modules.

Documentation of a denial-of-service vulnerability in the Rizin reverse engineering framework's ELF parser, caused by a forged DT_VERNEEDNUM value…

Exploit for CVE-2016-2334: heap overflow in 7zip's HFS+ archive parser. Includes HFS+ file generator and WinDbg heap analysis scripts for debugging…

MAPS cloud scanner and response parser for Microsoft Defender research.

A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.


Parse BIOS/Intel ME/UEFI firmware related structures: Volumes, FileSystems, Files, etc

Yet Another Golang binary parser for IDAPro

Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)

Python parser for extracting CobaltStrike Beacon configurations from PE files, memory dumps, and C2 URLs using heuristic XOR decryption and…

Event Trace Log file parser in pure Python

Python utility for parsing Xamarin AssemblyStore blob files