
RPC-Triage
A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

C++ plugin demonstrating an improved anti-debugging concept inspired by VMProtect (formerly AmogusPlugin) for debugger detection and software…

Documenting the internals of Fingerprint Pro's commercial agent, not the open-source FingerprintJS library

C++ reverse-engineering IDE with PE/ELF parsing, x86/x64 disassembly, Pcode IR, decompilation, function detection, and a Qt GUI.

Obfuscates C/C++ through LLVM passes: string encryption, control-flow flattening, MBA rewriting, and anti-analysis to defeat reverse engineering.

Complete firmware vulnerability analysis for CVE-2020-9373 Netgear R6400 UPnP stack overflow, including unpacking, reverse engineering, static…

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Static reverse-engineering of a GIGABYTE H510M K V2 (`H510MKV2.F3`) BIOS image: full UEFI firmware-volume extraction analysis of the PI-spec SMM Core…

WslinkVMAnalyzer is a tool to facilitate analysis of code protected by a virtual machine featured in Wslink malware

Collection of some easy of use tools - in powershell.

XMachOViewer is a Mach-O viewer for Windows, Linux and MacOS

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Highly advanced Linux anti-exploitation and anti-tamper binary protector for ELF.

Exports disassembly from IDA Pro, Ghidra, and Binary Ninja into compact protobuf files for fast, standalone binary analysis and program manipulation…

A library for creating, reading and editing PE files and .NET modules.

A decompiler-agnostic plugin for interacting with AI in your decompiler. GPT-4, Claude, and local models supported!

Xyntia, the black-box deobfuscator

VBScript & VBA source-to-source deobfuscator with partial-evaluation