
draytek-arsenal
Reverse Engineering and Observability toolkit for Draytek firewalls

Reverse Engineering and Observability toolkit for Draytek firewalls

An x64dbg plugin which marks XFG call signatures as data

indent guides plugin for hex-rays decompiler


PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

Exploit writeups I've authored


A small utility to deal with malware embedded hashes.

Standalone MCP server plugin for IDA Pro.

Provides a chat-based, LLM-assisted reverse engineering experience within Ghidra

Reconstructing a Dead USB Protocol: A Handheld's Secrets Unlocked by a Hot Knife, a multi-disciplinary journey to reviving a forgotten USB interface

A lightweight hex editor and decompiler to solve your binary file analysis problems.

Heap analysis tooling for dlmalloc

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Android Malware Tracker

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

Wireshark plugin for dissecting the Telegram protocol