
ReflectivePluginLoader
A minimal PE mapper that loads DLLs straight from memory and calls into a clean plugin interface, no LoadLibrary needed.

A minimal PE mapper that loads DLLs straight from memory and calls into a clean plugin interface, no LoadLibrary needed.

A high-fidelity x86_64 polymorphic mutation engine focused on instruction-level fragmentation and context preservation.

Zyrox: LLVM based, compile-time obfuscator plugin.

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

DEFCON 30 Mainframe buffer overlow workshop container

Automated ELF binary analysis tool for CTF/PWN challenges. Extracts security mitigations, ROP gadgets, PLT/GOT tables, and decompiles ASM to C using…

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

Driver Reverse & Exploitation


Documentation of Microsoft's Warbird obfuscation

Challenge handouts, source code, and solutions for UofTCTF 2025

A collection of vulnerabilities & exploits against modern GCS

A OSINT project that explores how to dump data from React

All-in-one macOS binary analysis: Mach-O parsing, ARM64 disassembly, code signatures, and debugging.

Analysis of VBS exploit CVE-2018-8174

ELF anti-reversing tool that overwrites section headers with nullbytes to prevent static analysis by disassemblers and debuggers, rendering functions…