
pyOneNote
A python library to parse OneNote (.one) files

A python library to parse OneNote (.one) files

Define and match user-defined graph patterns against binary control flow graphs using a Capstone-based disassembler, with CLI, Python bindings, and…

Python tool and library to help analyze files during malware triage and analysis.

Object-oriented Python API to simplify interaction with IDA for reverse engineering, enabling plugin development and automation of disassembly…

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

HardeningMeter is an open-source Python tool carefully designed to comprehensively assess the security hardening of binaries and systems.

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation

machofile is a module to parse Mach-O binary files

Python framework for building LLM workflows as state machines with formal verification via Z3 theorem proving, CTL model checking, and conformal…

Multi-session IDALib MCP router for coding agents. Analyze multiple binaries in parallel with IDA-compatible reverse engineering tools.

A Qt Widgets desktop UI for exploring Python bytecode with pycdc/pycdas, inspecting native decompilation, and using AI fallback for unsupported code…

Exploit and firmware analysis toolkit for Canon MF644 printer vulnerabilities, including Python exploits, ARM shellcode, and IDA Pro loader scripts…

Open-source entropy harvesting from unconventional hardware sources. Rust + Python SDK.

Take first steps in CodeQL for Python by writing a query to find CVE-2024-32022

The Python Version of our Not Go-ing Anywhere Vulnerable Application

Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.