
windiff
Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI…

Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI…

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

Modlishka. Reverse Proxy.

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

Automagically reverse-engineer REST APIs via capturing traffic

Trusted localhost HTTPS — local CA, /etc/hosts, mDNS LAN sharing, reverse proxy. Maps https://name.local → localhost:port

Burp Suite extension for decoding Web3 JSON-RPC traffic, including smart contract function calls, responses, and ABI resolution with proxy-aware and…

Malware analysis from the domain goxlr.net

Robust Frida-based tool to dump decrypted iOS apps as .ipa from a jailbroken device supports App Store, sideloaded and system.

A comprehensive security toolkit with 1000+ penetration testing and security assessment tools.

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

Analysis of malware found on a server compromised via CVE-2025-55182, including obfuscated dropper, C2 communication, persistence mechanisms, and…

Gives you one-liners that aids in penetration testing operations, privilege escalation and more

Some results of my DGA reversing efforts

Reverse image search tool using Google Cloud Vision API to detect landmarks, web entities, and geolocation data from images for OSINT investigations.

Maps attack surface of GWT applications by extracting obfuscated RPC endpoints and generating serialized request payloads for security testing.