
DECAF
DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

makin - reveal anti-debugging and anti-VM tricks [This project is not maintained anymore]

idenLib - Library Function Identification [This project is not maintained anymore]

InfectPE - Inject custom code into PE file [This project is not maintained anymore]

This is the main repository for metasm, a free assembler / disassembler / compiler written in ruby

This repository houses the work that ive put into reversing the various encoders and protocols used for customer service buttons in retail shops such…

This tool is used for encrypt backdoor,shellcode,socks5 proxy generation,Information retrieval and POC arrangement for various architecture devices

CERT Kaiju is a binary analysis framework extension for the Ghidra software reverse engineering suite. This repository is a "mirror" -- please file…

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

In this workshop session, we will extract firmware from an EV charger, dig into the firmware, and eventually emulate it so we can interact with the…

This framework enables user to discover JOP gagdets and can automate building a complete JOP chain to bypass DEP. JOP ROCKET is the ultimate solution…

proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls loaded. x86/x64/wow64 supported.

This repository contains an IDA processor for loading and disassembling compiled yara rules.

This tool calculates tricky canonical huffman histogram for CVE-2023-4863.

This is a little plugin to copy disassembly in a way that is usable in YARA rules!

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

This is a collection of Unisoc BootROMs dumped from various Unisoc chipsets via CVE-2022-38694

Reverse engineered android malware, and this is a C&C server for it