
pe-sieve
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Static analyzer for PE executables with plugin-based detection of packers, compilers, suspicious imports, cryptographic constants, and ClamAV…

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

Mediatek Flash and Repair Utility

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Intel Pin-based tracer for API calls, syscalls, and instructions with anti-debug evasion, used for malware analysis and reverse engineering of packed…

A reversing plugin for cross-decompiler collaboration, built on git.

Automates setup of binary exploitation challenges by patching ELF binaries, fetching matching linkers, unstripping libc, and generating pwntools…

Sickle - Payload Development Kit

Deobfuscation via optimization with usage of LLVM IR and parsing assembly.

Obfuscate specific windows apis with different apis

Obfuscate a python code 2.x and 3.x

:cherry_blossom: Interactive shellcoding environment to easily craft shellcodes

PE-bear (builds only)

Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks

A hypervisor for fuzzing built with WHVP and Bochs

Decompiles serialized V8 bytecode (JSC files) into high-level readable JavaScript-like code, with support for multiple V8 versions, tree output, and…

A multi-platform GUI for bit-based analysis, processing, and visualization