
pefile
pefile is a Python module to read and work with PE (Portable Executable) files

pefile is a Python module to read and work with PE (Portable Executable) files

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

Automatically exported from code.google.com/p/firmware-mod-kit

machofile is a module to parse Mach-O binary files

Security Analysis tool for WebAssembly module (wasm) and Blockchain Smart Contracts (BTC/ETH/NEO/EOS)

Parse BIOS/Intel ME/UEFI firmware related structures: Volumes, FileSystems, Files, etc

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

A PowerShell Module Dedicated to Reverse Engineering

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Ghidra module for disassembling, decompiling, and analyzing Ethereum smart contract bytecode. Detects insecure instructions, extracts hidden methods,…

An IDAPython module for enhancing c++ support on top of ida_kernelcache

PowerShell module for automatic detection of P/Invoke, Dynamic P/Invoke, and D/Invoke in .NET assemblies. Reveals unmanaged API calls, MDTokens, and…

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

nanoMIPS module for Ghidra

WinDbg plugin to trace module transitions from a debugged driver.

Magisk module that auto-packages renef_server (dynamic instrumentation for Android)

External read-only game overlay for Linux. Derived offsets, composed skeletons, optional kernel module for ptrace-independent memory reads and…

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…