
MappedImagesDetector
Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

MAPS cloud scanner and response parser for Microsoft Defender research.

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

Program for determining types of files for Windows, Linux and MacOS.

Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

Static Binary Instrumentation tool for Windows x64 executables

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

XMachOViewer is a Mach-O viewer for Windows, Linux and MacOS

🛡️ Open-source binary protection toolkit for Windows PE. Nanomite, VM protection, anti-debug, and more.

Kernel-mode syscall wrapper with Zydis-based dynamic pattern finding for Windows 10/11

PE file viewer/editor for Windows, Linux and MacOS.

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

An strace-like program for the Windows 'native' API

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

An API hooking framework for intercepting and monitoring Windows applications