
fnprint
match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Pishi is a code coverage tool like kcov for macOS.

Runtime Windows API interception library for hooking, monitoring, and instrumenting function calls. Supports binary rewriting and DLL injection,…

Documentation and reverse engineering of reCAPTCHA


Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

GNU IFUNC is the real culprit behind CVE-2024-3094

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Xyntia, the black-box deobfuscator

A script to detect stack-strings by using emulation (leveraging Unicorn)

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Static Binary Instrumentation tool for Windows x64 executables

Fermion, an electron wrapper for Frida & Monaco.

Code Coverage Exploration Plugin for Ghidra

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

x64 Dynamic Reverse Engineering Toolkit

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.