
datadome-vm
Reverse engineering the new Datadome VM 🔥

Reverse engineering the new Datadome VM 🔥

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Windows malware emulation framework that executes binaries, drivers, and shellcode in a modeled runtime, emulating APIs, process/thread behavior,…

B2R2 is a fully managed binary analysis framework written in F#. It provides a rich set of algorithms, functions, and tools for reverse engineering,…

A tool that is used to hunt vulnerabilities in x64 WDM drivers

An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general…

🦆 Malduck is your ducky companion in malware analysis journeys

Start WebRTC in the browser—run it somewhere else

In this workshop session, we will extract firmware from an EV charger, dig into the firmware, and eventually emulate it so we can interact with the…

Technical exploit for CVE-2025-43529, a WebKit DFG JIT compiler vulnerability enabling use-after-free via missing store barrier in concurrent GC,…

Proof-of-concept exploit for CVE-2024-54507, an integer type confusion vulnerability in XNU kernel, with technical writeup and exploitation details.

Manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in Lenovo's LnvMSRIO.sys to perform a BYOVD attack, mapping PE64 drivers into…

Integer overflow in Apple ImageIO WebP parsing (macOS/iOS)

Proof-of-concept exploit for CVE-2018-12798, a heap overflow in Adobe Acrobat Reader that enables remote code execution via malicious PDF files.

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware…

Collection of malware source code for a variety of platforms in an array of different programming languages.

Reverse engineering framework in Python

Decompiler from Java bytecode to Java, used in IntelliJ IDEA.