
MaFrida
A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

pefile is a Python module to read and work with PE (Portable Executable) files

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

A PowerShell Module Dedicated to Reverse Engineering

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Ghidra module for disassembling, decompiling, and analyzing Ethereum smart contract bytecode. Detects insecure instructions, extracts hidden methods,…

An IDAPython module for enhancing c++ support on top of ida_kernelcache

machofile is a module to parse Mach-O binary files

PowerShell module for automatic detection of P/Invoke, Dynamic P/Invoke, and D/Invoke in .NET assemblies. Reveals unmanaged API calls, MDTokens, and…

nanoMIPS module for Ghidra

WinDbg plugin to trace module transitions from a debugged driver.

Magisk module that auto-packages renef_server (dynamic instrumentation for Android)

External read-only game overlay for Linux. Derived offsets, composed skeletons, optional kernel module for ptrace-independent memory reads and…

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

Ghidra processor description module for NEC/Renesas v810 and v830 families

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

Technical analysis and proof-of-concept bypass for CVE-2023-33668 in DigiExam proctoring software, demonstrating weak VM detection and native module…