
GhidrAssist
An LLM extension for Ghidra to enable AI assistance in RE.

An LLM extension for Ghidra to enable AI assistance in RE.

Ghidra extension for PC firmware reverse engineering, providing loaders for PCI option ROMs, Intel Flash Descriptor, coreboot CBFS, and UEFI firmware…

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

Unofficial frida extension for VSCode

Incident Response & Digital Forensics Debugging Extension

Burp Suite extension for decoding Ethereum JSON-RPC calls and smart contract interactions, supporting multiple chains and automatic ABI retrieval.

CERT Kaiju is a binary analysis framework extension for the Ghidra software reverse engineering suite. This repository is a "mirror" -- please file…

crauEmu is an uEmu extension for developing and analyzing payloads for code-reuse attacks

Burp Suite extension for decoding Web3 JSON-RPC traffic, including smart contract function calls, responses, and ABI resolution with proxy-aware and…

Ghidra extension bridging static and dynamic analysis via Frida, enabling scriptable runtime instrumentation for reverse engineering binaries on…

WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

Proof-of-concept for CVE-2026-64788, a use-after-free in IOGPUFamily kernel extension on iOS 26.6, demonstrating exploitation via Metal texture…

Root-cause analysis and reachability PoC for CVE-2026-64747, a buffer overflow in the AppleAVE2 kernel extension. Includes reversed IOKit wire…

Denial-of-Service PoC | Writeup | Header with CLFS structures | Imhex pattern for .blf extension

Microsoft HEIF Extension (msheif_store.dll) OOB-read

A Chrome extension that demonstrates bypassing Widevine L3 DRM

The FLARE team's open-source extension to add Python 3 scripting to Ghidra.