This is your work, valued
msdocsviewer. msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.
★ 161idapython6to7. Python
★ 89unicorn-engine-notes. Notes on using the Python bindings for the Unicorn Engine
★ 88gopep. Go Lang Portable Executable Parser
★ 39hansel. Hansel - a simple but flexible search for IDA
★ 25ida_yara. A python script that can be used to scan data within in an IDB using Yara.
★ 23capstool. Python
★ 20asm-examples. Compiled executables of common crypto and encoding algorithms
★ 16RenameLocalVars. RenameLocalVars is an IDA plugin that renames local variables to something easier to read.
★ 15IDAGolangHelper. Set of IDA Pro scripts for parsing GoLang types information stored in compiled binary
★ 15FunctionTrapperKeeper. Function Trapper Keeper is an IDA plugin for writing and storing notes related to functions.
★ 13asmdec. Python
★ 7coffcoff. A python script for exploring COFF string tables.
★ 3func-renamer. Python
★ 2pwinfected. 7zip Password Protect File in Memory
★ 2BeginnersGuideToIDAPython. A repo for tracking updates, requests and bug fixes for the Beginner's Guide to IDAPython.
★ 2xxxswf. Python
★ 1pin-tools. Collection of tools for the Pin dynamic instrumentation framework
★ 1xrefs_strings. Displays cross-references to strings.
★ 1StressingLLMs. Python
★ 1oh-my-pi. ⌥ AI Coding agent for the terminal — hash-anchored edits, optimized tool harness, LSP, Python, browser, subagents, and more
★ 21kmagic-context. Unbounded context. Memory that manages itself. One session, for life. The hippocampus for coding agents, part of CortexKit.
★ 1.6kpyghidra-PAL. A defensive decompilation layer: Ghidra facts, lifted into runnable Python & artifacts aiding analysis.
★ 5genai-security-training. Jupyter Notebook
★ 458nono. Sandbox any AI agent in seconds - zero setup, zero latency.
★ 3.3kLLMVault. An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RAG Security, Agent Security, and GenAI penetration testing.
★ 259marker. Convert PDF to markdown + JSON quickly with high accuracy
★ 38kcrackmes-re-dataset. Labeled reverse-engineering dataset over 4,598 crackmes: flags, verifier scripts, and normalized obfuscation tags.
★ 109AI-For-Beginners. 12 Weeks, 24 Lessons, AI for All!
★ 54kasftriage. LLM Agent Session Forensics Tool
★ 22perfetto. Production-grade client-side tracing, profiling, and analysis for complex software systems.
★ 6.3kLiveBench. LiveBench: A Challenging, Contamination-Free LLM Benchmark
★ 1.3kds4. DeepSeek 4 Flash and PRO local inference engine for Metal, CUDA and ROCm
★ 19kghidra-rpc. A Ghidra agentic reverse engineering skill.
★ 298assignment1-basics. Student version of Assignment 1 for Stanford CS336 - Language Modeling From Scratch
★ 2.5kargus. Windows network traffic interception tool for malware analysis. Intercepts HTTP/S, DNS, SMTP, POP3 with fake responses, HTTPS MITM, and per-transaction capture.
★ 5ghidra-cli. Automate Ghidra reverse engineering from the command line — headless analysis, decompilation, and structured JSON output for AI agents like Claude Code
★ 175ghidrasql-skills. Claude Code skills for ghidrasql — live SQL interface for Ghidra analysis and annotation workflows
★ 11Glass. Glass - a fast and free IDA Pro alternative
★ 192cerberus-re-skill. cerberus-re is a local Apple-focused reverse-engineering workbench for building a repeatable three-headed static/dynamic/instrumentation loop around Ghidra, LLDB, and Frida.
★ 173llvm-jutsu. Anti-LLM obfuscation via finger counting
★ 236plannotator. Annotate and review coding agent plans and code diffs visually, share with your team, send feedback to agents with one click.
★ 7.4kgemma_crackme_tutorial. HTML
★ 35tiny-dec. A tiny educational decompiler that helps people understand how decompilation works.
★ 233windbg-decompile-ext. WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.
★ 111sogen. 🪅 Windows & Linux userspace emulator
★ 3.4kpyghidra-mcp. Python Command-Line Ghidra MCP
★ 392gamehacking-cheatsheet. Comprehensive Game Hacking Cheat Sheet for security researchers, reverse engineers, and CTF participants. Covers memory analysis, anti-cheat evasion, exploit development, and game engine reverse engineering for authorized security testing and educational purposes
★ 78agent. Language Model Agent Instructions for Binary Refinery
★ 13CORUNA_TECHNICAL_ANALYSIS. A Complete Technical Teardown of a State-Grade iOS/macOS Watering-Hole Exploit Chain
★ 57Assemblage. Python
★ 47YesterPlayOS. YesterPlayOS is a tribute to the golden era of personal computing. Minimalistic, fast, and nostalgic.
★ 2claude-code-hooks-mastery. Master Claude Code Hooks
★ 3.9kmaths-cs-ai-compendium. Become a cracked AI/ML researcher/engineer with this unconventional textbook covering maths, computing, and ML with intuition.
★ 7.2kHypervisors-for-Hackers. The materials of the "Hypervisors for Hackers: Security from the Hardware Up" class held at Global Cybersecurity Camp 2026 Vietnam.
★ 68swirly. Learn a python package interactively (similar to R's Swirl)
★ 11bof-wsl. bof for interacting with WSL
★ 14rust-malware-gallery. A collection of malware families and malware samples which use the Rust programming language.
★ 225letsbuildacompiler. Re-implementation of the Let's Build a Compiler tutorial in Python, emitting WASM
★ 159shellcode. Shellcodes for Windows/Linux/BSD running on x86, AMD64, ARM, ARM64
★ 1warbird-research. Find out how to bypass HVCI (or not). My own research on Microsoft Warbird (specifically in clipsp.sys)
★ 98ida-cyberchef. A Qt-based CyberChef interface designed for malware analysis workflows, particularly in IDA Pro
★ 179rendergit. Render any git repo into a single static HTML page for humans or LLMs
★ 2.4kz3_tutorial. Jupyter notebooks for tutorial on the Z3 SMT solver
★ 169drakvuf. DRAKVUF Black-box Binary Analysis
★ 1.3kcpu_rec. Recognize cpu instructions in an arbitrary binary file
★ 752LinuxInExcel. C
★ 462libro. A terminal based book tracking tool
★ 211StealthAPCDispatcher. Function scheduling stealth method using APC with encrypted shellcode
★ 15hacktical-c. A practical hacker's guide to the C programming language.
★ 1.1kollvm-unflattener. Obfuscator-llvm Control Flow Flattening Deobfuscator
★ 268x86-64-playground. An online assembly editor, emulator and debugger for the x86-64 architecture
★ 709blink. tiniest x86-64-linux emulator
★ 7.6kzydis. Fast and lightweight x86/x86-64 disassembler and code generation library
★ 4.3klearning-ai. Notes and exploration code for learning about AI/ML
★ 221reconstructing-rust-types-talk-re-verse-2025. Slides and materials for the talk Reconstructing Rust Types: A Practical Guide for Reverse Engineers at RE//verse 2025, presented on February 28, 2025.
★ 27agents-course. This repository contains the Hugging Face Agents Course.
★ 31kucutils. Convenience routines for working with the Unicorn emulator in Python
★ 34blueskyfeedbot. A bot that posts RSS feeds to Bluesky via GitHub Actions
★ 99asm-lessons. FFmpeg Assembly Language Lessons
★ 12kwindows_kernel_resources. Papers, blogposts, tutorials etc for learning about Windows kernel exploitation, internals and (r|b)ootkits
★ 421dewolf. A research decompiler implemented as a Binary Ninja plugin.
★ 230markitdown. Python tool for converting files and office documents to Markdown.
★ 170kaws-dev-associate. Repo for https://learn.cantrill.io/p/aws-certified-developer-associate
★ 425HackSysExtremeVulnerableDriver. HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux
★ 3kudmp-parser. A Cross-Platform C++ parser library for Windows user minidumps with Python 3 bindings.
★ 233vac-bypass-kernel. Fully working kernel-mode VAC bypass
★ 102falcon-operator. Go
★ 76PyhidraNotebook. Learn Ghidra through pyhidra
★ 4drawmeatree. Tool to visualize the output of the WinDbg "wt" command as customizable graphic trees, to facilitate reverse engineering.
★ 11function-graph-overview. Control-Flow Graph (CFG) Visualizer for VSCode
★ 69kotaemon. An open-source RAG-based tool for chatting with your documents.
★ 26kworkshops. Malware analysis and Reverse Engineering Workshops from Invoke RE
★ 15nyxstone. Nyxstone: assembly / disassembly library based on LLVM, implemented in C++ with Rust and Python bindings, maintained by emproof.com
★ 410aidapal. aiDAPal is an IDA Pro plugin that uses a locally running LLM that has been fine-tuned for Hex-Rays pseudocode to assist with code analysis.
★ 391business-ctf-2024. Official writeups for Business CTF 2024: The Vault Of Hope
★ 163rust-reversing-workshop-northsec-2024. Rust
★ 24SourceSync. Set of plugins and library for dynamic pdb generation and synchronisation
★ 41ml-basics. Exercise notebooks for Machine Learning modules on Microsoft Learn
★ 1.9kSAFACon-Vienna.
★ 24operating-system-design-review. Operating System Design Review: A systematic analysis of modern systems architecture
★ 344coderex. A tool that automates regex generation for the x86 and x86-64 instruction sets
★ 75opentelemetry-ebpf-profiler. The production-scale datacenter profiler (C/C++, Go, Rust, Python, Java, NodeJS, .NET, PHP, Ruby, Perl, ...)
★ 3.2kdds. Dr. Disassembler
★ 38zydis-go. Pure Go bindings for Zydis.
★ 17ipex-llm. Accelerate local LLM inference and finetuning (LLaMA, Mistral, ChatGLM, Qwen, DeepSeek, Mixtral, Gemma, Phi, MiniCPM, Qwen-VL, MiniCPM-V, etc.) on Intel XPU (e.g., local PC with iGPU and NPU, discrete GPU such as Arc, Flex and Max); seamlessly integrate with llama.cpp, Ollama, HuggingFace, LangChain, LlamaIndex, vLLM, DeepSpeed, Axolotl, etc.
★ 8.9kptrtut13. A TUTORIAL ON POINTERS AND ARRAYS IN C
★ 1.4kgftrace. A command line Windows API tracing tool for Golang binaries.
★ 159xfg_analyzer. A Binary Ninja plugin that uses bruteforced XFG hashes to recover precise function prototypes
★ 16lend. Tiny x86 Length Disassembler
★ 73mydumbedr. C
★ 123QuickAsm. Simple x86/x64 Assembler/Disassembler/Emulator
★ 198presentation. Presentation slides, blogs, and videos of my conference presentations.
★ 26ghidriff. Python Command-Line Ghidra Binary Diffing Engine
★ 796morris-worm. The decompiled Morris Worm source code
★ 670declib. A library for writing plugins in any decompiler: includes API lifting, common data formatting, and GUI abstraction!
★ 182concealed_code_execution. Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows
★ 225InsightEngineering. Hardcore Debugging
★ 945varbert_api. A Python API to VarBERT, a BERT based model for suggesting variable names in decompiled code.
★ 53YARA_Detection_Engineering. Detection Engineering with YARA
★ 88VectorKernel. PoCs for Kernelmode rootkit techniques research.
★ 442protobuf-magic. Java
★ 83ML-For-Beginners. 12 weeks, 26 lessons, 52 quizzes, classic Machine Learning for all
★ 89kAlternativeShellcodeExec. Alternative Shellcode Execution Via Callbacks
★ 1.7kbinja-win-docs. Python
★ 14windows-driver-docs-ddi. The official Windows Driver Kit DDI reference documentation sources
★ 311IdaClu. IdaClu is a version agnostic IDA Pro plugin for grouping similar functions. Pick an existing grouping algorithm or create your own.
★ 186Microsoft-365-Defender-Hunting-Queries. Sample queries for Advanced hunting in Microsoft 365 Defender
★ 2.1kJonMon. C++
★ 267bindiff. Quickly find differences and similarities in disassembled code
★ 3.1kcloudynight. Code and example data repository for Mommert (2020): Cloud Identification from All-sky Camera Data with Machine Learning, Astronomical Journal, 159
★ 40Learning-EDR-and-EDR_Evasion. I will be uploading all the codes which I created with the help either opensource projects or blogs. This is a step by step EDR learning path for me.
★ 291PIC-Get-Privileges. Building and Executing Position Independent Shellcode from Object Files in Memory
★ 174discrete-math-python-scripts. Python code snippets from Discrete Mathematics for Computer Science specialization at Coursera
★ 455cff_playground. Control flow flattening toy apps
★ 3ida-rust-untangler. An IDA plugin which demangles Rust function names
★ 37awesome-WinDbg. collect Windows WinDbg notes
★ 10python-mastery. Advanced Python Mastery (course by @dabeaz)
★ 13kcomp128. C
★ 8revng. revng: the core repository of the rev.ng project
★ 1.7kUnpacMe-IDA-Byte-Search. UnpacMe IDA Byte Search
★ 29MalwareMorphology. C++
★ 84THE_HIVE. My public notes about offensive security
★ 168A5.1. A5/1 GSM stream cipher
★ 1comprehensive-rust. This is the Rust course used by the Android team at Google. It provides you the material to quickly teach Rust.
★ 33kwinipt. The Windows Library for Intel Process Trace (WinIPT) is a project that leverages the new Intel Processor Trace functionality exposed by Windows 10 Redstone 5 (1809), through a set of libraries and a command-line tool.
★ 410Stealthy-Kernelmode-Injector. Manual mapper that uses PTE manipulation, Virtual Address Descriptor (VAD) manipulation, and forceful memory allocation to hide executable pages. (VAD hide / NX bit swapping)
★ 416awesome-llvm-security. awesome llvm security [Welcome to PR]
★ 859RebirthGuard. Anti-cheat library for Windows C++
★ 507DVRT. How Meltdown and Spectre haunt Anti-Cheat: DVRT details
★ 21ebpf-beginners. The beginner's guide to eBPF
★ 1.7kopenai-cookbook. Examples and guides for using the OpenAI API
★ 75krust_type_layout_helper_bn. An extremely experimental Binary Ninja importer for the type layout information emitted by the -Zprint-type-sizes flag of the Rust compiler.
★ 37gadget_synthesis. Esorics 2021 - Towards Automating Code-Reuse Attacks Using Synthesized Gadget Chains
★ 59docker-mcrit. Dockerized Setup for the MinHash-based Code Recognition & Investigation Toolkit (MCRIT)
★ 16mac-monitor. "The missing ProcMon for macOS": Mac Monitor records Endpoint Security events and displays them for analysis.
★ 1.4kallthingsida. Repository for the code snippets from the AllThingsIDA video channel
★ 192iced. Blazing fast and correct x86/x64 disassembler, assembler, decoder, encoder for Rust, .NET, Java, Python, Lua
★ 3.5kDotNextSP2019. DotNext 2019 St. Petersburg Talk Demos
★ 39libyara.NET. .NET wrapper for libyara built in C++ CLI used to easily incorporate yara into .NET projects
★ 60LOLDrivers. Living Off The Land Drivers
★ 1.7kVulnCases. Vulnerability examples.
★ 412clr-profiler. A CLR (.NET Runtime) profiler written purely in Rust.
★ 37DotNetHooking. Sample use cases of the .NET native code hooking technique
★ 221maldev-for-dummies. A workshop about Malware Development
★ 1.8kEssentials-of-Compilation. A book about compiling Racket and Python to x86-64 assembly
★ 1.6kminhook. The Minimalistic x86/x64 API Hooking Library for Windows
★ 5.9kobfuscation_detection. Binary Ninja plugin to identify obfuscated code and other interesting code constructs
★ 669UnityHacking. The materials to accompany Unity hacking blogs found on mayer.cool
★ 7ClrAnalyzer. .NET library for hooking and dumping Clr
★ 44SharpCollection. Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.
★ 2.9kSharpAllTheThings. The idea is to collect all the C# projects that are Sharp{Word} that can be used in Cobalt Strike as execute assembly command.
★ 484Hypervisor-101-in-Rust. The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application for high-performance fuzzing on Intel/AMD processors.
★ 1.2kSealighter. Sysmon-Like research tool for ETW
★ 394Presentations. Presentation material presented by Outflank team members at public events.
★ 191mattifestation.
★ 7EWS. Emulation Wrapper Solution is a IDA Pro plugin that brings emulator capacities to provide features such as debugging an mocking.
★ 23CLRInstrumentationEngine. The CLR Instrumentation Engine is a cooperation profiler that allows running multiple profiling extensions in the same process.
★ 101DotDumper. An automatic unpacker and logger for DotNet Framework targeting files
★ 266etw-event-dumper. C#
★ 33clrmd. Microsoft.Diagnostics.Runtime is a set of APIs for introspecting processes and dumps.
★ 4SilkETW. C#
★ 852OffensiveDLR. Toolbox containing research notes & PoC code for weaponizing .NET's DLR
★ 526defcon_27_windbg_workshop. DEFCON 27 workshop - Modern Debugging with WinDbg Preview
★ 748BugChecker. SoftICE-like kernel debugger for Windows 11
★ 1.1kAnti-Debug-DB. Anti-Debug encyclopedia contains methods used by malware to verify if they are executed under debugging. It includes the description of various anti-debug tricks, their implementation, and recommendations of how to mitigate the each trick.
★ 71Evasions. Evasions encyclopedia gathers methods used by malware to evade detection when run in virtualized environment. Methods are grouped into categories for ease of searching and understanding. Also provided are code samples, signature recommendations and countermeasures within each category for the described techniques.
★ 449ipyida. IPython console integration for IDA Pro
★ 851sliver. Adversary Emulation Framework
★ 12kgargoyle. Historical Windows temporal memory-state research artifact for studying time-bound memory observations, validation limits, and defensive visibility.
★ 908Lesson-3-Control-Flow. C
★ 1dumb-obfuscator. Tutorial on how to write the dumbest obfuscator I could think of.
★ 177nampa. Nampa - FLIRT for (binary) ninjas
★ 101CSCD70. CSCD70 Compiler Optimization
★ 264llvm-deobfuscator. Python
★ 431opaque-predicates-detective. An approach to detect opaque predicates by identifying the damage caused by the obfuscation.
★ 32lancelot. intel x86(-64) code analysis library that reconstructs control flow
★ 113goat. GO Approximation of Typer
★ 5Artfuscator. A C compiler targeting an artistically pleasing nightmare for reverse engineers
★ 1.1klibscemu. SCEMU The crates.io lib, x86 cpu and systems emulator focused mainly for anti-malware
★ 46mcrit. The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework created to simplify the application of the MinHash algorithm in the context of code similarity.
★ 102mux-mongo-api. Go
★ 6fgtrace. fgtrace is an experimental profiler/tracer that is capturing wallclock timelines for each goroutine. It's very similar to the Chrome profiler.
★ 909.NET-Deobfuscator. Lists of .NET Deobfuscator and Unpacker (Open Source)
★ 1.5kripr. Package Binary Code as a Python class using Binary Ninja and Unicorn Engine
★ 412f-ing-around-with-binaryninja. Repository of code I've written during my twitch stream, "F'ing Around with Binary Ninja"
★ 108pypcode. Python bindings to Ghidra's SLEIGH library for disassembly and lifting to P-Code IR
★ 213golang-internals-resources. A collection of articles and videos to understand Golang internals.
★ 1.3kbinjascripts. Scripts for Binary Ninja
★ 259lensm. Go assembly and source viewer
★ 3.7kpanda_class. Classes for teaching about PANDA, the Platform for Architecture-Neutral Dynamic Analysis
★ 6MBA-Solver. Python
★ 46tfg. A copy of my Mathematics and Computer Engineering B.Sc. thesis
★ 18file-upload. Go
★ 42WinDbg_Scripts. Useful scripts for WinDbg using the debugger data model
★ 436rusty-memory-loadlibrary. Load DLLs from memory with rust
★ 141SiT. Simple Instruction Tracer
★ 2blog-posts. Contain code referred in https://www.securityinbits.com/
★ 13manticore. Symbolic execution tool
★ 3.9kmaat. Open-source symbolic execution framework: https://maat.re
★ 650