
shellen
:cherry_blossom: Interactive shellcoding environment to easily craft shellcodes

:cherry_blossom: Interactive shellcoding environment to easily craft shellcodes

Course materials for hackaday.io Ghidra training

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

Workshop on firmware reverse engineering

AST-level Python obfuscation engine with AES-256 encryption, runtime payload protection, and control-flow flattening for security research and…

OpenType font that disassembles Z80 instructions

A collection of useful links for Pentesters

Automated ROP chain generator for x86-64 binaries using symbolic execution. Supports register/memory writes, function calls, syscalls, badchar…

A verified map of reverse engineering and malware analysis. Disassemblers, unpacking, exploit dev, fuzzing, DFIR, and the deep-cut writeups other…

Go package that aids in binary analysis and exploitation

Parallel IDA Pro binary analysis with AI-powered function naming, Neo4j knowledge graph, and phantomrt emulation/hooking/fuzzing engine for automated…

Binary Exploitation and Reverse-Engineering (from assembly into C)

Static deobfuscation toolkit for compiled V8 JavaScript bytecode, focusing on JSCeal payloads. Provides pattern-driven filters, control-flow…

Slides and files for the Reversing Rust Binaries: One step beyond strings workshop at REcon 2024, presented on June 28, 2024.

Header-only C++2x compile-time assembler for x86/x86-64 instruction encoding

Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

CVE-2025-55177 + CVE-2025-43300: reverse-engineering the WhatsApp-ImageIO zero-click iOS chain, with interactive labs.