
NtTrace
An strace-like program for the Windows 'native' API

An strace-like program for the Windows 'native' API

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

x64 Dynamic Reverse Engineering Toolkit

Documentation and reverse engineering of reCAPTCHA

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

Code Coverage Exploration Plugin for Ghidra

Windows NT ioctl bruteforcer and modular fuzzer

GNU IFUNC is the real culprit behind CVE-2024-3094

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

MAPS cloud scanner and response parser for Microsoft Defender research.

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

HTTP Proxy Analysis for reverse engineering protocol communication

A script to detect stack-strings by using emulation (leveraging Unicorn)

An API hooking framework for intercepting and monitoring Windows applications

High-performance HTTP/HTTPS/SOCKS5 MITM proxy in Rust with TLS interception, rule-based request rewriting, traffic capture, breakpoints, script…