
pefile
pefile is a Python module to read and work with PE (Portable Executable) files

pefile is a Python module to read and work with PE (Portable Executable) files

External read-only game overlay for Linux. Derived offsets, composed skeletons, optional kernel module for ptrace-independent memory reads and…

GhostLock One-Tap Execution App (CVE-2026-43499)

An IDAPython module for enhancing c++ support on top of ida_kernelcache

GNU Radio out-of-tree (OOT) module for QRadioLink blocks.

Parse BIOS/Intel ME/UEFI firmware related structures: Volumes, FileSystems, Files, etc

Magisk module that auto-packages renef_server (dynamic instrumentation for Android)

Ghidra processor description module for NEC/Renesas v810 and v830 families

Automatically exported from code.google.com/p/firmware-mod-kit

machofile is a module to parse Mach-O binary files

WinDbg plugin to trace module transitions from a debugged driver.

nanoMIPS module for Ghidra

Proof-of-concept exploit for CVE-2023-50564 targeting Pluck CMS, delivering a reverse shell via malicious module installation.

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Android Malware Tracker

Exploit for redirecting control flow of a legit kernel module to your own illegitimate kernel module to evade anti-cheats stack walking

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…