
javascript-deobfuscator
Deobfuscator for javascript-obfuscator 5.x output (string arrays, control-flow flattening, self-defending, RC4/base64)

Deobfuscator for javascript-obfuscator 5.x output (string arrays, control-flow flattening, self-defending, RC4/base64)

Reverse bytenode .jsc (V8 code cache) to JavaScript — static, pure Rust, no patched V8/Node. Node 8→26 / V8 5.8–14.6; 25k .jsc tested, 0 fail.

0-day malware detection for binaries, source & scripts (that doesn't suck)

Agent-native CLI wrapping IDA Pro IDALib for stateless, JSON-output binary analysis: disassembly, Hex-Rays decompilation, CFG, xrefs, strings, and…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Xyntia, the black-box deobfuscator

x64 Dynamic Reverse Engineering Toolkit

Pishi is a code coverage tool like kcov for macOS.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

Code Coverage Exploration Plugin for Ghidra

Windows NT ioctl bruteforcer and modular fuzzer

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

Documentation and reverse engineering of reCAPTCHA

GNU IFUNC is the real culprit behind CVE-2024-3094

CAWODOG is a proof-of-concept project demonstrating how to protect Python-based AI models deployed on offline industrial machines. Across three…