This is your work, valued
xx. The xx file format. Turn your hex dumps into art, then into binary data.
★ 343scare. A multi-arch assembly REPL and emulator for your command line.
★ 311golfclub. Binary Golf Examples and Resources
★ 262protocols. Python
★ 228inhale. A malware analysis and classification tool.
★ 191gtfoplus. Linux Local Privesc Helper and Agent
★ 165pdiff. Binary Protocol Differ
★ 117BGGP. Binary Golf Grand Prix
★ 115yxd. yxd - Yuu's heX Dumper
★ 92reversi. Generate very tiny reverse shell binaries for Linux~
★ 76jLoot. JIRA Secure Attachment Looter
★ 69dissectors. random dissectors
★ 68kimagure. Assembly
★ 44hardcode. 64KB and smaller demoscene intros. Sorted by size. hardcode.untergrund.net
★ 40i2ao. Intro to Assembly Optimization stream repo
★ 30notes. Shell
★ 27uJunk. An unsorted collection of little tools and scripts I've made that don't fit anywhere else
★ 19importsort. Group imports from Windows binaries
★ 17pdiff2. Python
★ 15b64mute. Base64 Mutator
★ 13bgws. HTML
★ 12hexcalc. A simple hex calculator in the browser
★ 11ai_dev. Python
★ 8enumgen. Enumeration Notes and Cheatsheet Generator
★ 6Simple-Virtual-CPU. A very simple example of a virtual CPU written in C and an "assembler" in python 3.7.
★ 5pockettoolz. Python
★ 5easylkb. easylkb - Easy Linux Kernel Builder
★ 4netspooky.
★ 4ParrotSec_Alternate_Install. Fixes for Parrot Sec Install Scripts
★ 3writeups.
★ 3MalwareSourceCode. Collection of malware source code for a variety of platforms in an array of different programming languages.
★ 2sublime-notes. A syntax designed to bring syntax highlighting to every day note taking.
★ 13DSTests. Some WIP Scripts for the 3DS using ctrulib
★ 1dnb. one of the first projects i made with python
★ 1Responder3. Responder for Python3
★ 1liltools. Shell
★ 1osed-scripts. bespoke tooling for offensive security's Windows Usermode Exploit Dev course (OSED)
★ 1mquickjs. Public repository of the Micro QuickJS Javascript Engine
★ 6.1kmt7622-qemu-vm. QEMU emulation of MediaTek MT7622 PCI driver
★ 21tinyelfscarf. Source code to build a 76 byte ELF file that prints out the word "scarf"
★ 9grammars-v4. Grammars written for ANTLR v4; expectation that the grammars are free of actions.
★ 11kusb-course-materials. index of all course materials; suitable for offline use
★ 45goodasm. A portable assembler for Z80, 8080, Gameboy, 6805, 8051 and others.
★ 53TonyHawksProStrcpy. Code execution exploit for Tony Hawk's video game series
★ 354yaxgbc. at least 75% of a gbc emulator
★ 6DVUEFI. Damn Vulnerable UEFI
★ 305slothy. Assembly super-optimization via constraint solving
★ 336SummerCart64. SummerCart64 - a fully open source N64 flashcart
★ 1.1kAssemblage. The repo holds Assemblage
★ 10efi-memory. PoC EFI runtime driver for memory r/w & kdmapper fork
★ 585certmitm. A tool for testing for certificate validation vulnerabilities of TLS connections made by a client device or an application.
★ 734UEFI-Lessons. Lessons to get to know UEFI programming in Linux with the help of EDKII
★ 364kernel-inline-hook-framework. hook or replace arbitary linux/FreeBSD kernel functions in runtime, supporting arm32, arm64, x86, x86_64, riscv, loongarch
★ 225midgetpack. midgetpack is a multiplatform secure ELF packer
★ 210Silent_Packer. An ELF / PE binary packer written in pure C, made for fun
★ 118elixir. The Elixir Cross Referencer
★ 1.2kpendulum. Linux Sleep Obfuscation
★ 130ida-openrisc. OpenRISC 1000 processor module for IDA 7.x
★ 13easylkb. easylkb - Easy Linux Kernel Builder
★ 402serio. Python
★ 43hypermedia-blog. a static blog using bun, tailwindcss, htmx, sqlite, and typescript
★ 18hw-hacking-lab. VSS Hardware Hacking Wiki and Blog Entries
★ 264FwHunt. The Binarly Firmware Hunt (FwHunt) rule format was designed to scan for known vulnerabilities in UEFI firmware.
★ 247tsffs. A snapshotting, coverage-guided fuzzer for software (UEFI, Kernel, firmware, BIOS) built on SIMICS
★ 331scandump. A command-line utility that scans for Wi-Fi networks using the 802.11 netlink API.
★ 36wavacity. C
★ 477object-introspection. Object Introspection (OI) enables on-demand, hierarchical profiling of objects in arbitrary C/C++ programs with no recompilation.
★ 183bitlocker-attacks. A list of public attacks on BitLocker
★ 462libsigrokdecoder_spi-tpm. libsigrok stacked Protocol Decoder for TPM 2.0 & TPM 1.2 transactions from an SPI bus. BitLocker Volume Master Key (VMK) are automatically extracted.
★ 25Big-Ass-Data-Broker-Opt-Out-List.
★ 6.7kShrine. A TempleOS distro for heretics
★ 1.6kshiva. A custom ELF linker/loader for installing ET_REL binary patches at runtime
★ 218adder. Adder python runtime instrumentation
★ 1Cartographer. Code Coverage Exploration Plugin for Ghidra
★ 382finley. finley makes it easy to quickly decompile several .NET binaries concurrently without involving a GUI.
★ 7python-ftfy. Fixes mojibake and other glitches in Unicode text, after the fact.
★ 4.1kROPemporium. All ROPemporium binaries categorized by architecture, with solving scripts and custom flags
★ 25FPGADesignElements. A self-contained online book containing a library of FPGA design modules and related coding/design guides.
★ 468stelf-loader. A stealthy ELF loader - no files, no execve, no RWX
★ 175michelangelo-reanimator. Michelangelo REanimator bootkit and REcon 2023 talk slides/materials
★ 30PRE-Resources. Protocol Reverse Engineering Resources
★ 22hvICE. hypervisor enforced patch protection for the linux kernel with xen + libvmi, libvmi KASLR offset spoofer
★ 33awful-ai. 😈Awful AI is a curated list to track current scary usages of AI - hoping to raise awareness
★ 7.5kumap. UEFI bootkit for driver manual mapping
★ 599SupplyChainAttacks.
★ 280Heap-Resources. Heap Exploitation Resources
★ 22pastis. PASTIS: Collaborative Fuzzing Framework
★ 165asm2cfg. Python command-line tool and GDB extension to view and save x86, ARM and objdump assembly files as control-flow graph (CFG) pdf files
★ 88eresi. The ERESI Reverse Engineering Software Interface
★ 575ddisasm. A fast and accurate disassembler
★ 753linux-kernel-enriched-corpus. Linux Kernel Fuzzer Corpus
★ 161macstealer. MacStealer: Wi-Fi Client Isolation Bypass
★ 552jellyfin. The Free Software Media System - Server Backend & API
★ 55kblenny. A payload delivery system which embeds payloads in an executable's icon file!
★ 74fpicker. fpicker is a Frida-based fuzzing suite supporting various modes (including AFL++ in-process fuzzing)
★ 296Grammar-Mutator. A grammar-based custom mutator for AFL++
★ 273RVVM. The RISC-V Virtual Machine
★ 1.3kpacker-tutorial. A tutorial on how to write a packer for Windows!
★ 318hoard-of-bitfonts. turns out I like bitmap fonts
★ 1.5kfragattacks. C
★ 1.3kdebugoff. Linux anti-debugging and anti-analysis rust library
★ 337wavedrom. :ocean: Digital timing diagram rendering engine
★ 3.5kitlb_poc. iTLB multihit PoC
★ 43binary-parsing. A list of generic tools for parsing binary data structures, such as file formats, network protocols or bitstreams
★ 1.1ksecret_handshake. A prototype malware C2 channel using x509 certificates over mTLS
★ 153p65a. Pythonic 6502 Assembler: An experimental alternative to traditional assemblers.
★ 21Book-on-MOS-stages. Book repository "Analysis and Design of Elementary MOS Amplifier Stages"
★ 392vmlinux-to-elf. A tool to recover a fully analyzable .ELF from a raw kernel, through extracting the kernel symbol table (kallsyms)
★ 1.8kTEE-reversing. A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices
★ 1kMacDirtyCowDemo. Get root on macOS 13.0.1 with CVE-2022-46689 (macOS equivalent of the Dirty Cow bug), using the testcase extracted from Apple's XNU source.
★ 410usercorn. dynamic binary analysis via platform emulation
★ 906unicorn-engine-notes. Notes on using the Python bindings for the Unicorn Engine
★ 88unicorn. Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86)
★ 9.2ktest. A collection of boilerplate code and projects for testing ideas
★ 14qiling. A True Instrumentable Binary Emulation Framework
★ 6klkmpg. The Linux Kernel Module Programming Guide (updated for 5.0+ kernels)
★ 8.5kGhidraBoy. Sharp SM83 / Game Boy extension for Ghidra
★ 283fq. jq for binary formats - tool, language and decoders for working with binary and text formats
★ 11klearn-fpga. Learning FPGA, yosys, nextpnr, and RISC-V
★ 3.6kusb_c_cable_tester.
★ 795hyperpom. AArch64 fuzzer based on the Apple Silicon hypervisor
★ 202twitter-archive-parser. Python code to parse a Twitter archive and output in various ways
★ 2.4ktdfiglet. A figlet for TheDraw's TDF ANSI fonts
★ 67dotfiles. rice 🍚 custom linux config files. as seen on r/unixporn #noricenolife neovim cultist. dotfiles are perpetual wip
★ 2.3kCommunity-Papers. RIXED LABS is open for contributions for it's community papers . If you want to publish a blog or a paper , it will be added to the site with proper credits.
★ 80PS5SDK. An SDK to build payloads/ELF files compatible with the loader in the PS5 WebKit+Kernel Exploit chain.
★ 203exploit_me. Very vulnerable ARM/AARCH64 application (CTF style exploitation tutorial with 29 vulnerability techniques)
★ 1.1khashprogs. A collection of small programs which compute cryptographic hashs.
★ 5taskverse. A tool like /bin/ps but uses /proc/kcore for walking the tasklist; this finds hidden processes
★ 60lipgloss. Style definitions for nice terminal layouts 👄
★ 12kawesome-firmware-security. Awesome Firmware Security & Other Helpful Documents
★ 618linux-wifi-ota-crash. This is a small POC running on an ESP32, exploiting CVE-2022-42722 to crash Linux devices over the air.
★ 80tigard. An FTDI FT2232H-based multi-protocol tool for hardware hacking
★ 850xx-files.
★ 1portscraper. Rust
★ 4monomorph. MD5-Monomorphic Shellcode Packer - all payloads have the same MD5 hash
★ 791awesome-youtubers. An awesome list of awesome YouTubers that teach about technology. Tutorials about web development, computer science, machine learning, game development, cybersecurity, and more.
★ 7.6kkmemd. Explore a live Linux kernel's memory using GDB
★ 118heap_find_and_poke. uses process_vm_readv and process_vm_writev to patch heap memory of another process
★ 4rtpmidid. RTP MIDI (AppleMIDI) daemon for Linux
★ 247Ghidrathon. The FLARE team's open-source extension to add Python 3 scripting to Ghidra.
★ 787hello-asm. Hello World examples in assembly, for use as templates.
★ 13LIEF. LIEF - Library to Instrument Executable Formats (C++, Python, Rust)
★ 5.5kgrc. generic colouriser
★ 2.2kbitmap-font-css. Trying to make bitmap web fonts look better.
★ 40Terminus. Bring a real terminal to Sublime Text
★ 1.5kReC98. The Touhou PC-98 Restoration Project
★ 845garble. Obfuscate Go builds
★ 5.6klike-dbg. Fully dockerized Linux kernel debugging environment
★ 770Pokemon-Shellcode-Loader. Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.
★ 128PVT. PCAP visualization tool
★ 105utils. Useful scripts, Docker images, docker-compose apps, and Terraform modules.
★ 148tproxy. A cli tool to proxy and analyze TCP connections.
★ 3.7kSurvivalManual. Libre Survival Manual for Android with offline in mind
★ 1.3kdecompiler-explorer. Decompiler Explorer! Compare tools on the forefront of static analysis, now in your web browser!
★ 2.6kpiloslib. Multi-platform open-source set of audio and modulation tools that focus on synthesis, live electronic music, interconnection, probability, unique sounds, and intuitive interfacing built by Akunull in Pure Data starting in 2014
★ 146nprint. nPrint provides a generalizable data representation for network packets that works directly with machine learning techniques
★ 125eagle-rs. Rusty Rootkit - Windows Kernel Rookit in Rust (Codename: Eagle)
★ 580gorss. Go Terminal Feed Reader
★ 462Arm-firmware-emulation. Script for emulating Arm firmware in QEMU, including a binary for hooking functions for certain Tenda firmware versions that are not straight-forward to emulate.
★ 31Cronos-Rootkit. Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.
★ 943asciiflow. ASCIIFlow
★ 5.8kemba. EMBA - The firmware security analyzer
★ 3.6kpwnkernel. Kernel development & exploitation practice environment.
★ 256Cybersecurity-Tradecraft. A repo to support the book
★ 112heaptrace. helps visualize heap operations for pwn and debugging
★ 329ImHex. 🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
★ 54kWeylus. Use your tablet as graphic tablet/touch screen on your computer.
★ 9.4kgoo-gone. degoogle for your browser
★ 18nfqueue-go. Go bindings for NFQueue
★ 52gdb-dashboard. Modular visual interface for GDB in Python
★ 12kspritegtk. render sprites into your desktop environment as shaped windows using GTK
★ 22uCodeDisasm. Python
★ 374exclave. C++
★ 16WindowsInternals. Yet another windows internals repo
★ 221ScareCrow. ScareCrow - Payload creation framework designed around EDR bypass.
★ 2.9ksimple-languages-js. A small Javascript snippet for smooth bi/multilingual websites.
★ 3js-vuln-db. A collection of JavaScript engine CVEs with PoCs
★ 2.3khow2heap. A repository for learning various heap exploitation techniques.
★ 8.8krappel. A linux-based assembly REPL for x86, amd64, armv7, and armv8
★ 1.3kPPLdump. Dump the memory of a PPL with a userland exploit
★ 893termshark. A terminal UI for tshark, inspired by Wireshark
★ 9.9kICS-Security-Tools. Tools, tips, tricks, and more for exploring ICS Security.
★ 2kropc. A Turing complete ROP compiler
★ 327ropr. A blazing fast™ multithreaded ROP Gadget finder. ropper / ropgadget alternative (currently x86 only)
★ 554Reverse-Engineering. A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.
★ 14kal-khaser. Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
★ 7.1kmalware_training_vol1. Materials for Windows Malware Analysis training (volume 1)
★ 2.1kwsb-detect. wsb-detect enables you to detect if you are running in Windows Sandbox ("WSB")
★ 373libgolf. Binary Golf Library
★ 64sublime. 320+ color themes for Sublime Text and Textmate.
★ 362AFLplusplus. The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!
★ 6.7kwinafl. A fork of AFL for fuzzing Windows binaries
★ 2.6kActive-Directory-Exploitation-Cheat-Sheet. A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
★ 6.7kcores. Teensy Core Libraries for Arduino
★ 575rich. Rich is a Python library for rich text and beautiful formatting in the terminal.
★ 57kwtfpython. What the f*ck Python? 😱
★ 37kansilove. ANSI and ASCII art to PNG converter in C
★ 422edex-ui. A cross-platform, customizable science fiction terminal emulator with advanced monitoring & touchscreen support.
★ 45kuboot-mdb-dump. Python
★ 108funky_malware_formats. Parsers for custom malware formats ("Funky malware formats")
★ 97algo. Set up a personal VPN in the cloud
★ 30kmitra. A generator of weird files (binary polyglots, near polyglots, polymocks...)
★ 1.3kPSKernel-Primitives. Exploit primitives for PowerShell
★ 435EfiGuard. Disable PatchGuard and Driver Signature Enforcement at boot time
★ 2.5kret-sync. ret-sync is a set of plugins that helps to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with IDA/Ghidra/Binary Ninja disassemblers.
★ 2.4kDIRT. Driver Initial Reconnaissance Tool
★ 127endlessh. SSH tarpit that slowly sends an endless banner
★ 8.5ktools-for-hack-a-sat-2020. QEMU setup for emulating satellite firmware for Hack-A-Sat final event
★ 97pcodedmp. A VBA p-code disassembler
★ 488oletools. oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.
★ 3.4kDNSExfiltrator. Data exfiltration over DNS request covert channel
★ 885cb-multios. DARPA Challenges Sets for Linux, Windows, and macOS
★ 540bip. Python
★ 204idascope. An IDA Pro extension for easier (malware) reverse engineering
★ 115cosa-nostra. Cosa Nostra, a FOSS graph based malware clusterization toolkit.
★ 231FavFreak. Making Favicon.ico based Recon Great again !
★ 1.3kawesome-embedded-and-iot-security. A curated list of awesome embedded and IoT security resources.
★ 2.4kpe_tree. Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump in-memory PE files and reconstruct imports.
★ 1.3kmalwaremustdie. repository of tools & resources of the MMD team
★ 144htp-zines. A collection of Hack The Planet's zines.
★ 72capa. The FLARE team's open-source tool to identify capabilities in executable files.
★ 6.1kExploits. Real world and CTFs exploiting web/binary POCs.
★ 79threadx. Eclipse ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applications.
★ 3.5kcLEMENCy. cLEMENCy is the LEgitbs Middle ENdian Computer architecture developed by Lightning for DEF CON CTF 2017
★ 125syphon. ⚗️ a privacy centric matrix client
★ 1.1khaxon. Tooling to retrieve data from Axon2 Body Cams
★ 49element-themes. A place to share themes for Element. PRs with new themes are welcome!
★ 289pypykatz. Mimikatz implementation in pure Python
★ 3.3kyara-rules-re. [Moved to Codeberg] Tools for inspecting YARA bytecode
★ 22degoogle. search Google and extract results directly. skip all the click-through links and other sketchiness
★ 505ipftrace2. A packet oriented Linux kernel function call tracer
★ 410binary-samples. Samples of binary with different formats and architectures. A test suite for your binary analysis tools.
★ 281python-curses-scroll-example. :tv: How to implement the scroll and paging in Python curses
★ 50exrex. Irregular methods on regular expressions
★ 957ICS_PCAPS. ICS Cybersecurity PCAP respository
★ 66Z0FCourse_ReverseEngineering. Reverse engineering focusing on x64 Windows.
★ 5.9k