Stars
ArgFuscator.net is an open-source, stand-alone web application that helps generate obfuscated command lines for common system-native executables.
A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl
Python tool to check rootkits in Windows kernel
Cross-platform multi-protocol VPN software. Pull requests are welcome. The stable version is available at https://github.com/SoftEtherVPN/SoftEtherVPN_Stable.
This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC, MIPS, RISC-V 64, a…
Binary distribution of https://github.com/xiaorouji/openwrt-passwall built with official OpenWRT SDK.
Poison Ivy Remote administrator tool Reload
Capture screenshots of onion services on an onion service.
《Hello 算法》:动画图解、一键运行的数据结构与算法教程。支持 Python, Java, C++, C, C#, JS, Go, Swift, Rust, Ruby, Kotlin, TS, Dart 代码。简体版和繁体版同步更新,English version in translation
msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.
vmware-archive / HexRaysDeob
Forked from RolfRolles/HexRaysDeobHex-Rays microcode API plugin for breaking an obfuscating compiler
Modified python version of Rolf Rolles' https://github.com/RolfRolles/HexRaysDeob to unflatten Emotet'S Control Flow Flattening
A lib that allows using mhyprot2 driver for enum process modules, r/w process memory and kill process.
WTF Solidity 极简入门教程,供小白们使用。Now supports English! 官网: https://wtf.academy
Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks
IDA Pro plugin which improves work with HexRays decompiler and helps in process of reconstruction structures and classes
Decrypted content of odd.tar.xz.gpg, swift.tar.xz.gpg and windows.tar.xz.gpg
Multipass orchestrates virtual Ubuntu instances
Diaphora, the most advanced Free and Open Source program diffing tool.
IDA Pro plugin for recognizing known hashes of API function names
An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general (sandboxing).