
rpef
Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

x64 Dynamic Reverse Engineering Toolkit

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Web-based tool for browsing mobile application sandboxes, previewing SQLite databases and binary files, and downloading app data via Frida…

PoCs and tools for investigation of Windows process execution techniques

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

Simple Process Dumper using DMA over a PCIe FPGA device

A lightweight dynamic instrumentation library

DrSemu - Sandboxed Malware Detection and Classification Tool Based on Dynamic Behavior

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

A dynamic VMP dumper and import fixer, powered by VTIL.

Drltrace is a library calls tracer for Windows and Linux applications.

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

Protect process by shellcode

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.