
SentinelNav
SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

Process heap analysis framework - Windows/Linux - record type inference and forensics

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

my advisory, poc, slides and scripts related to IoT/protocol security

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

Reverse engineering toolkit for PerimeterX's bytecode VM, featuring a CFG-based disassembler, 5-layer decryption pipeline, opcode table…

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

Tool for solving BPF filters and crafting packets based on these.

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

ELF anti-reversing tool that overwrites section headers with nullbytes to prevent static analysis by disassemblers and debuggers, rendering functions…

A BOF designed to inspect processes memory and addresses

🛡️ Open-source binary protection toolkit for Windows PE. Nanomite, VM protection, anti-debug, and more.

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…