
AtomicSyscall
Tools and PoCs for Windows syscall investigation.

Tools and PoCs for Windows syscall investigation.

idenLib - Library Function Identification [This project is not maintained anymore]

Hardware hacker’s flying probe automation stack for agent-driven target discovery, microscope mapping, safety-monitored CNC motion, probe review,…


Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.


Reverse engineering NVIDIA SASS instruction dictionary, kernel audits and pattern recognition across GPU architectures.

Extract AutoIt scripts embedded in PE binaries

Collection of extracted Microsoft Defender data for security research purposes

Reverse engineering the new Datadome VM 🔥

reverse engineering SynthID for text

sniff HDMI DDC (I2C) traffic

Emulate and Dissect MSF and *other* attacks

Define and match user-defined graph patterns against binary control flow graphs using a Capstone-based disassembler, with CLI, Python bindings, and…

Graphical interface for PortEx, a Portable Executable and Malware Analysis Library

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

Volatility Explorer Suit (volatility 3)