
VMDragonSlayer
Multi-engine framework for unpacking and analyzing VM-protected binaries using dynamic taint tracking, symbolic execution, pattern classification,…

Multi-engine framework for unpacking and analyzing VM-protected binaries using dynamic taint tracking, symbolic execution, pattern classification,…

Raw binary firmware analysis software

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++

Themida Devirt Results

Decrypt TP-Link Firmware

a PE Loader and Windows API tracer. Useful in malware analysis.

The Manticore User Interface with plugins for Binary Ninja and Ghidra

Chase H.Q. for ZX Spectrum — reverse-engineered and reconstructed in portable C

FPGA based microcomputer sandbox for software and RTL experimentation

Windows named pipe hooking toolkit

A post-processing script for TinyTracer

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…


End-to-end exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow). Includes static analysis with IDA/Ghidra, binary fuzzing,…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…