
Detours
Runtime Windows API interception library for hooking, monitoring, and instrumenting function calls. Supports binary rewriting and DLL injection,…

Runtime Windows API interception library for hooking, monitoring, and instrumenting function calls. Supports binary rewriting and DLL injection,…

Plasma is an interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax.

Functional RISC-V ISA simulator supporting multiple extensions (RV32/64, V, cryptography) with interactive debug mode, GDB integration, and…

Structured reverse engineering course covering x64 Windows binaries, assembly, debugging, and malware analysis. Designed for beginners to…

PEDA - Python Exploit Development Assistance for GDB



Tiny cute emulator plugin for IDA based on unicorn.

Library for lifting machine code to LLVM bitcode

Hex-Rays Decompiler plugin for better code navigation

IDAPython tool for creating automatic C++ virtual tables in IDA Pro

Yet Another Golang binary parser for IDAPro

Guide to building a virtual iPhone using VPHONE600AP components from Apple's PCC firmware, with firmware patching, bootchain modification, and kernel…

Python decompiler for 3.7-3.8 Stripped down from uncompyle6 so we can refactor and start to fix up some long-standing problems

PoCs and tools for investigation of Windows process execution techniques

Malware Configuration And Payload Extraction

A Trace Explorer for Reverse Engineers

Frida-based tracer for easier reverse-engineering on Android, iOS, Linux, Windows and most related architectures.