
z80-sans
OpenType font that disassembles Z80 instructions

OpenType font that disassembles Z80 instructions

JIT-based userspace Linux kernel that runs containers natively on Apple Silicon macOS without a VM. Drop-in Docker Engine API replacement with…

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solutions that clash…

Vulnerability research assistant that locates calls to potentially insecure API functions in a binary file.

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

REmatch, a complete binary diffing framework that is free and strives to be open source and community driven.

All Security Resource Collections Repos That I Published.

FairPlay decryptor (dump iPA) for iOS Application that running on macOS with SIP-enabled, using CVE-2025-24204. Support macOS 15.0-15.2

Go package that aids in binary analysis and exploitation

Incarcero is a tool that creates Virtual Machines (VMs) preconfigured with malware analysis tools and security settings tailored for malware analysis…

Reverse engineering assistant that uses a locally running LLM to aid with pseudocode analysis.

Static binary instrumentation tool that dumps COFF object files from executables, enabling code/data insertion at any location for black-box fuzzing…

WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

I have documented all of the AMSI patches that I learned till now