


Static-first research tool for unpacking Nuitka-compiled binaries: extracts constants, modules, recovers .pyc files, and generates analysis reports.

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

Binary template repository for 010 Editor, providing .bt scripts for parsing executables, filesystem images, registry hives, and forensic artifacts…

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Local privilege escalation exploit for CVE-2020-1066 targeting Windows 7 and Server 2008 R2. Leverages arbitrary file replacement via Windows…

Terminal-based note manager with hierarchical tagging and file linking

Intercepts and analyzes USB Mass Storage traffic at the block and file level, emulates USB devices, and supports custom Python stubs for security…

Total Commander FTP Password Recovery Tool for Python allows you to decrypt the FTP account password information for all Total Commander versions…

An strace-like program for the Windows 'native' API

MAPS cloud scanner and response parser for Microsoft Defender research.

Exploit helper for CVE-2019-11932 (WhatsApp GIF RCE) that calculates system() function and ROP gadget addresses for different devices to enable…

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

RP2040 firmware that bridges a Toshiba MK4001MTD 0.85" SDIO microdrive as a USB mass storage device, implementing the full SDIO-ATA protocol stack…

Tools for analyzing Canon Pixma printer firmware

Presented at Recon Montreal 2018

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…