> cat /dev/github | grep security-tools

Reverse-Engineering

ida-headless-mcp

2026-08-31 Rust ★ 10
ida-headless-mcp is a Rust-based, multi-session headless server implementation for IDA Pro, designed to facilitate concurrent analysis of multiple databases while ensuring session isolation. Notable features include an explicit supervisor/worker architecture for process management, session lifecycle control, and a comprehensive suite of analysis tools categorized into 12 groups. This tool operates without GUI support, making it ideal for automated and headless environments requiring IDA Pro integration.

mole

2026-08-31 Python ★ 84
Mole is a Binary Ninja plugin that facilitates the identification of significant execution paths within binaries through backward slicing of variables, leveraging the Medium Level Intermediate Language (MLIL) in Static Single Assignment (SSA) form for static taint analysis. Its primary use case lies in vulnerability detection, where it allows users to define source and sink functions, visualize paths, and analyze them using AI integration for classifying potential vulnerabilities. Notable features include operational flexibility, extensive path exploration options, customizable path grouping strategies, persistence of analysis progress, and inter-procedural variable slicing.

rsleigh

2026-08-31 Rust ★ 10
rsleigh is a pure-Rust reverse-engineering workbench designed to convert various binary formats, including PE, ELF, and Mach-O, into C-like pseudocode and other structured outputs like disassembly and call graphs. This tool excels in static analysis workflows by enabling users to navigate binaries efficiently, uncover function calls, analyze packed code, and integrate findings with LLMs for automated analysis, without dependence on JVM or C++ bindings. Notably, it supports a multi-architecture API, allowing for flexible integration and insights into binary behavior.

wrappem

2026-08-31 C++ ★ 19
WrappEm is a Windows tool designed for adversarial payload execution by utilizing three distinct methods of subverting the Windows Image Loader through byte-based manipulation of a binary file’s Import Directory and Import Section. Its primary use case involves inserting an additional executable binary into a host process's virtual address space, serving as an alternative to traditional export forwarding techniques. Notable features include support for multiple methods of import manipulation and compatibility with various build systems, all implemented without external dependencies.

GTA5-DMA-CHEAT

2026-08-31 C++ ★ 30
The GTA5 DMA Control Console provides an external interface for Direct Memory Access (DMA) manipulation in Grand Theft Auto V, supporting both the original and Enhanced versions of the game. It features dynamic offset resolution for seamless updates, real-time player and vehicle monitoring, and comprehensive control options such as teleportation, vehicle editing, and weapon functionality. Built with C++23 and utilizing Dear ImGui for its UI, it allows users to modify game states efficiently while ensuring automatic detection of critical game parameters.

th095

2026-08-31 C++ ★ 16
The TH095 project aims to reconstruct the original Japanese version 1.02a of the game "Shoot the Bullet" by providing a framework for precise byte-level comparison against an authenticated executable. Notable features include the support for exact function restoration, semantic analysis using IDA Pro, and tracking of source presence and validation for various game components, with an aspirational reconstruction target of 99.5% accuracy. Users can import their legal copy of the game executable to verify against established criteria, facilitating a comprehensive understanding of the game's architecture.

TinySecrets

2026-08-31 ★ 227
TinySecrets is a comprehensive repository focused on the technical specifications and modding potential of small PCs from Lenovo, Dell, HP, and Acer. It details comparisons of system boards, configurations, and available PCIe riser types across various models, complemented by high-resolution images. This tool serves as a valuable resource for hardware enthusiasts looking to explore unutilized capabilities and modifications of compact computer systems.

CTFlearn-Writeups

2026-08-31 Python ★ 171
CTFlearn-Writeups is a compilation of detailed solutions for various Capture The Flag challenges across multiple domains such as Cryptography, Forensics, and Web security. The tool serves as a reference for practitioners and enthusiasts looking to enhance their skills in cybersecurity challenge-solving. Notable features include categorized writeups that cover a range of problem types, providing structured insights into methodologies and techniques used in each challenge.

hitman-vr-foveation-fix

2026-08-30 PowerShell ★ 10
HitmanVRFoveationFix enhances the visual experience of HITMAN World of Assassination in PC VR by replacing the game's fixed foveation renderer with dual full-resolution eye layers across the entire field of view, addressing the peripheral blurriness typical in pancake-lens headsets. Notable features include improved startup speeds for unverified game builds, reduced CPU usage while idle, and maintained safety protocols to ensure accurate gameplay integrity. The tool is compatible with Windows and SteamVR platforms, with experimental support for Linux.

simtower-native-windows-port

2026-08-30 C++ ★ 16
SimTower native Windows port is a function-by-function x86-64 implementation of the original Windows 3.1 version of *SimTower*, aimed at preserving and facilitating interoperability of the game. Notable features include comprehensive code analysis, exact native mapping of game routines, and a thorough validation process that ensures fidelity to the original gameplay experience. The tool requires specific resources from a legally owned copy of the game for successful local builds and emphasizes strict adherence to the original game's architecture and resource management.

pyfunda

2026-08-30 Python ★ 190
pyfunda is a Python API wrapper specifically designed for interacting with Funda.nl, the leading Dutch real estate platform, utilizing its reverse-engineered mobile JSON API to fetch property listings without the need for HTML scraping or browser automation. This library provides clean, typed objects for listings, prices, media, and brokers, allowing users to perform detailed searches, retrieve listing information, view price history, and monitor new listings. Notably, pyfunda is an open-source solution that acts as the only functioning Python client for accessing Funda’s endpoints, making it a valuable tool for developers seeking a reliable alternative to proprietary scraping services.

tmhc

2026-08-30 C ★ 16
Twisted Metal: Harbor City is a project aimed at creating a matching decompilation of the unreleased PlayStation 2 game. It is primarily used for analyzing and understanding the game's code structure and assets in a POSIX environment. Notable features include detailed documentation on classes, assets, and networking, as well as integration with various development tools such as GNU GCC and Ninja for building.

Zeravynex

2026-08-30 TypeScript ★ 14
Zeravynex is a robust static malware analysis platform designed for Windows Portable Executable files, utilizing a combination of deterministic heuristics, YARA signatures, and machine learning techniques to provide explainable security decisions. Notable features include deep PE parsing, a built-in YARA rule engine for malware family detection, automatic indicator of compromise extraction, and a modern web dashboard for real-time analysis visualization, all while ensuring safety by performing static analysis only. The platform facilitates binary inspection through both command-line interface and FastAPI REST API, supporting comprehensive threat triage processes.

Atlas-Override

2026-08-30 HTML ★ 55
The Stellar Cartographer's Atlas is a sophisticated C++ tool designed to enhance the experience of players in procedurally generated space exploration simulations by providing an external memory system for tracking exploration journeys. Its notable features include advanced data interpretation across three layers: spatial analysis for path reconstruction and resource identification, linguistic assistance for understanding alien languages, and narrative generation that composes a personalized log of discoveries and interactions. This tool aims to enrich players' exploration narratives and prevent the loss of valuable data amid vast digital environments.

deadspace3-resource-surge

2026-08-30 HTML ★ 55
DeadSpace3ResourceManager is a cross-platform tool designed for the Steam version of Dead Space 3 that facilitates efficient in-game resource management. By allowing users to inject 500 units of various resources directly into their inventory with a keystroke, it enhances the gameplay experience through instantaneous resource access while maintaining balance with features like customizable bindings and a cooldown timer. Notably, it operates non-intrusively and supports multilingual configurations, making it an ideal solution for players seeking to optimize their resource utilization ethically.

grok-bot-0.18-original

2026-08-30 JavaScript ★ 13
The grok-bot-0.18-original repository provides an archival version of the Grok Bot 0.18.0 runtime code, mechanically split into a modular file structure for ease of access and analysis. It contains the original runtime bundles and tools for lossless reassembly, alongside precise documentation of module paths and offsets, which are crucial for understanding the binary's internal architecture. This setup facilitates the study and reconstruction of the software without any source mapping, preserving its structural fidelity for educational purposes.

hades-render-overlay

2026-08-30 HTML ★ 55
Kekropis is a cross-platform tactical overlay designed for competitive FPS games, focusing on enhancing situational awareness without altering the game’s core. It utilizes a micro-kernel visualization engine to passively observe game telemetry and displays intuitive glyphs, emphasizing minimal cognitive load and visual clarity. Notable features include a responsive user interface, support for multiple operating systems, and reliance on a read-only spatial telemetry network to maintain the integrity of the gaming experience.

HexPatch

2026-08-30 Rust ★ 333
HexPatch: a binary patcher and editor written in Rust with terminal user interface (TUI).

nvidia-playgroud-go

2026-08-30 Go ★ 16
nvidia-playgroud-go is a reverse-engineered Go client and multi-format proxy for accessing NVIDIA Build Playground's anonymous models. It supports dynamic model fetching and routing to prediction endpoints, utilizing a pure-Go hCaptcha solver for verification, and includes features such as Docker deployment and integration with the CLIProxyAPI for OpenAI completions and responses. This tool is designed for developers seeking to interface with multiple NVIDIA AI models programmatically without browser dependencies.

packet-warden

2026-08-30 HTML ★ 55
AQW-Sequence Weaver is a bioinformatics-inspired toolkit designed to visualize and extract patterns from network telemetry specifically for AQW private server research. It enables users to map packet transactions, identify variable fields through heuristic analysis, and interactively explore session flows, while also supporting export to standard formats and multilingual interfaces. Notably, it offers a protocol diff engine for comparing captures across versions and a community research log for collaborative annotation of packet sequences.

Rebirth-Pub-Save-Forge

2026-08-30 HTML ★ 55
ChronoVault is a sophisticated game profile management tool designed to enhance single-player narratives by allowing users to architect alternate realities within their gaming experiences. Unlike traditional save editors, it provides comprehensive features such as relationship mapping, inventory weaving, and resource flow balancing to ensure narrative coherence and immersion. Its responsive interface and multilingual support further elevate the user experience, making it accessible and intuitive for gamers at all levels.

reversing-labs-sandbox

2026-08-30 HTML ★ 55
MindForge is an educational sandbox designed for aspiring reverse engineers and memory manipulators, allowing users to explore the interactions between software and hardware within a controlled environment. It features a fictional binary target for practice, comprehensive in-app tutorials, a snapshot recovery system for experimentation, and tools like memory heatmaps and scriptable learning modules that foster understanding of memory manipulation concepts. The platform also supports multiple languages, making it accessible to a global audience of learners.

shadow-of-mordor-wraith-arsenal

2026-08-30 HTML ★ 55
The Forge of the Wraith is an internal trainer specifically designed for the Steam GOTY edition of Middle-earth: Shadow of Mordor, enabling extensive manipulation of game mechanics through memory editing. It offers a robust suite of features such as invulnerability, infinite focus in combat, stealth enhancements, and currency maximization, allowing users to dominate gameplay and explore freely without the constraints of the original mechanics. Its internal architecture ensures stability and minimizes the risk of detection, providing a seamless and powerful gaming experience.

Tinyriser

2026-08-30 ★ 156
TinyRiser is an advanced riser solution for Lenovo's 8th and 9th generation Tiny5 PCs that enables simultaneous use of independent x8 and x4 PCIe links through a PCIe x16 slot and an m.2 slot. This tool allows users to install both low-profile PCIe cards and an extra M.2 NVMe SSD without requiring motherboard modifications, ensuring plug-and-play functionality. Notable features include support for various PCIe card configurations, compatibility with specific Lenovo models, and a fan header with multiple power modes for enhanced cooling options.

ue3-reliquary-runtime

2026-08-30 HTML ★ 55
EchoForge is a runtime reflection framework and asset studio tailored for Unreal Engine 3 (UE3), enabling users to explore and manipulate the engine's internal object graph without altering its core. Its notable features include a comprehensive runtime reflection API, support for polyglot modding through C, C++, and Rust, and a cross-platform asset studio that allows live viewing and editing of game assets. This tool serves as a vital resource for modders and researchers aiming to enhance or reimagine existing UE3 games, providing flexibility through dynamic property discovery and event notification systems.

0sec

2026-08-30 TypeScript ★ 47
0sec is an open and extensible AI-driven cybersecurity tool that automates vulnerability discovery, exploitation, and remediation across various layers, including web applications, APIs, source code, and network infrastructure. It supports multi-model and multi-agent capabilities to address complex security challenges, emphasizes continuous security over point-in-time assessments, and includes a command-line interface for streamlined interactions and automation of pentesting workflows. Notable features include the ability to find a wide range of vulnerabilities, integration with various environments and systems, and a focus on supply chain security and other emerging threat vectors.

BerryProtocol

2026-08-29 TypeScript ★ 11
BerryProtocol is a TypeScript-based SDK designed for creating interactive messaging experiences on WhatsApp, enabling developers to build rich, client-facing applications with features like native lists, buttons, and real-time events. Its multi-session architecture allows for scalable connections, supporting independent authentication states and session recovery, making it suitable for SaaS platforms and chatbot integrations. The SDK emphasizes a developer-friendly experience with a clean API, robust typings, and seamless npm integration.

ghidra-lx-loader

2026-08-29 Java ★ 81
The Ghidra LX Loader is an extension for Ghidra that facilitates the analysis of LX/LE executable formats, including OS/2 and various DOS styles, by providing comprehensive support for relocation, typed headers, and detailed fixup statistics. Notable features include the ability to manually override base addresses for debugging purposes, label management for fixups and memory pages, and customizable mapping options for image data. This tool is particularly useful for reverse engineers working with legacy executable formats needing robust analysis capabilities.

system-programming-roadmap

2026-08-29 ★ 590
The System Programming Roadmap is an educational framework designed to guide users through the fundamentals of compiler development, malware reverse engineering, and kernel development. It emphasizes a structured approach to mastering system programming languages such as C, Rust, and C++, while also covering essential concepts in computer architecture and assembly language. Notable features include a curated list of resources and prerequisites to enhance the learning experience and ensure a comprehensive understanding of low-level programming.

berbel-remote

2026-08-29 C++ ★ 14
The Berbel Remote is an ESP32-based emulator for the Berbel BFB 6bT remote control, designed to integrate seamlessly with Home Assistant through MQTT. It enables full emulation of the original remote features, including real-time status updates and supports over-the-air firmware updates, making it compatible with various Berbel kitchen hoods manufactured after November 2020. Key features include automatic entity creation via MQTT auto-discovery, efficient memory usage with the NimBLE stack, and flexible configuration options for different hood models.

keras

2026-08-29 TypeScript ★ 20
KeRaS is an open-source automation and scheduling tool that assists university students in managing their course planning (KRS) by acting as an integration layer between the student and the university's existing KRS systems. Developed through reverse engineering, it enables the retrieval of course data, maintains session contexts, and automates submission attempts, all without requiring a dedicated public API from the university's KRS system. Notable features include a unified scheduling interface and the ability to generate schedules based on user-defined constraints.

spyglass

2026-08-29 C++ ★ 15
Spyglass is a packet capture tool designed to run within the Minecraft: Bedrock client, providing visibility into every packet sent and received by the client, along with details on decoding failures. It facilitates debugging for server software and proxies by presenting a structured overlay that displays packet details, error information, and hex data, allowing users to filter, search, and analyze communication with ease. Notable features include an interactive packet list, detailed breakdowns of failed packets, various data export options, and customizable filtering capabilities.

pulsar-mouse-linux

2026-08-28 Python ★ 10
The pulsar-mouse-linux tool enables Linux users to configure various Pulsar gaming mice through a user-friendly interface, supporting models with distinct protocols. Key features include plugin architecture for different mouse drivers, customization options for performance and lighting, button remapping, and a system tray icon for easy access. This tool is reverse-engineered from USB HID captures and provides comprehensive support for both wired and wireless models.

web-reconstruction

2026-08-28 JavaScript ★ 10
The `web-reconstruction` tool is an evidence-driven solution for accurately reconstructing static websites, responsive pages, and complex UI elements utilizing WebGL/WebGPU/Canvas effects. It distinguishes between faithful replicas, visual approximations, and design transfers by using a structured approach to gather evidence, lock down routes, and verify outputs, ultimately facilitating multi-state verification and editable project creation. Key features include modular reconstruction paths for various target types, a progressive workflow that ensures accuracy, and no dependencies on third-party packages.

dsp-w215-b1-openwrt-hacks

2026-08-28 Shell ★ 11
The D-Link DSP-W215 B1 OpenWrt Hacks repository provides comprehensive reverse engineering and control scripts specifically for the D-Link DSP-W215 B1 smart plug running OpenWrt. It offers detailed guidance on flashing OpenWrt, troubleshooting connectivity issues, and controlling the device's relay and power metering features via GPIO and serial communication with the PL8331 chip. Notable features include a step-by-step flashing procedure, solutions to common post-flash problems, and the ability to integrate with services like Home Assistant and MQTT for real-time monitoring.

Nds4j

2026-08-28 Java ★ 10
Nds4j is a Java library designed for reading, modifying, and creating various file types utilized in Nintendo DS games, initially catering to the Pokémon DS hacking community. Currently, it supports several formats such as NDS ROM, NARC, and others with full editing capabilities for certain file types, while additional formats are planned for future support. Notable features include cross-platform compatibility, a focus on byte-for-byte round-tripping, and being written in pure Java, making it accessible for JVM-based applications.

patternsleuth

2026-08-28 Rust ★ 89
Patternsleuth is a testing suite designed to identify robust patterns for locating common functions and global variables within Unreal Engine games, specifically tailored for use with the UE4SS framework. Users can easily integrate game executables into the designated directory and run tests to analyze function recognition and isolation. Notable features include support for multiple game titles and a collection of established patterns that enhance the accuracy of symbol resolution.

DelphiReSym

2026-08-28 Python ★ 35
DelphiReSym is a reverse engineering tool that recovers fully qualified Delphi symbol names from the metadata in Delphi executables, facilitating the analysis of Delphi malware and legacy applications. Integrated with Ghidra, it not only restores human-readable context for functions and types but also automatically populates virtual table structures in Ghidra's Data Type Manager. This tool supports multiple Delphi versions, enabling detailed reconstruction of metadata for effective reverse engineering.

FF-16-TUI

2026-08-28 Go ★ 31
FF-16-TUI is an interactive static analysis tool designed to identify frequently occurring local 16-bit patterns within files, aiding in the analysis of file structures and layouts. It features a text user interface that allows users to navigate through patterns efficiently while providing customizable filtering options for detailed pattern analysis. Notable functionalities include command-line usage with support for dictionary files, along with keyboard shortcuts for seamless interaction throughout various analysis panels.

grate

2026-08-28 C ★ 90
Grate is an open source reverse-engineering toolset specifically designed for analyzing NVIDIA Tegra 2/34 2D and 3D graphics engines. Its primary use case is to facilitate understanding and documentation of the Tegra architecture through various resources, including command streams and shader instructions. Notable features include comprehensive wiki documentation that details MMIO registers, shader ISAs, and geometry submission methods.

hcaptcha-hsj-reverse

2026-08-28 Python ★ 21
The hcaptcha-hsj-reverse tool is designed to reverse engineer hCaptcha's hsj.js to extract encryption keys used in its operations. It provides functionality to hook into the AES key schedule of hsj.js and dump encryption keys from memory, utilizing various cryptographic algorithms such as AES-GCM. Notable features include a KeyFetcher class for retrieving these keys and a comprehensive set of helper classes for encryption, hashing, and encoding processes.

Multiline-Ultimate-Assembler

2026-08-28 C ★ 177
Multiline Ultimate Assembler is a plugin for x64dbg and OllyDbg that serves as a multiline assembler and disassembler. Its primary use case involves modifying and extending the functionality of compiled executables and creating code caves. Notable features include support for multiline assembly input, enhancing the reverse engineering process.

n64-decomp-workbench

2026-08-28 Python ★ 13
N64 Decomp Workbench is a diagnostic tool designed to identify and analyze discrepancies in late-stage MIPS decompilation, particularly for near-matched functions. Its primary use case is for developers working with MIPS assembly code, allowing them to efficiently isolate functions, understand the reasons behind mismatches, and generate hypotheses for resolution without requiring extensive setup or external tools. Notable features include a guided workflow, exhaustive documentation, and commands like `diagnose-dumps` and `compare-dumps` that enable users to comprehensively compare and troubleshoot decompiled outputs.

rvt-rs

2026-08-28 Rust ★ 13
rvt-rs is a Rust/Python toolkit designed for inspecting Autodesk Revit files without requiring a Revit installation. It allows users to open OLE/CFB containers, decode truncated-gzip streams, extract metadata, and classify schema field encodings, with notable features including a zero-upload browser viewer that enables real-time 3D rendering and element analysis. The toolkit offers a variety of command-line interfaces and Python bindings, enhancing accessibility for both technical and non-technical users.

skyroads-sdl

2026-08-28 C ★ 28
SkyRoads SDL is a cross-platform port of the classic DOS space racing game SkyRoads, rewritten in C using SDL2, enabling native execution on macOS and Linux without the need for emulation. Notable features include a self-contained app bundle with integrated game data, customizable controls, and advanced graphical options such as CRT effects. The tool allows users to build from source easily while providing comprehensive compatibility with various hardware architectures.

xoreos-tools

2026-08-28 C++ ★ 80
xoreos-tools is a collection of utilities designed for the reverse-engineering of BioWare's Aurora engine games. Its primary use case includes converting various proprietary game file formats to XML and back, extracting and creating archives, and decompiling scripts, offering extensive support for BioWare and Nintendo file types. Notable features include support for multiple file conversions and the ability to repair or extract data from damaged or proprietary archives.

amv_decoder

2026-08-27 Rust ★ 10
`amv_decoder` is a Rust-based tool designed for parsing and partially decoding the AJPM (Alpha Movie) video format, predominantly utilized in KiriKiri engine titles. Its notable features include stability for reverse engineering tasks, the ability to read file headers, load quantization tables, and decode frame packets into RGBA frames, while also supporting the export of raw packet data and quick inspection PPM images.

awesome-hex-editors

2026-08-27 ★ 46
The "awesome-hex-editors" repository provides a comprehensive curated list of hexadecimal editors available for Windows, macOS, and Linux, catering to various needs such as file viewing, editing, and searching. Each listed tool has been enriched with specific highlight tags to denote unique features like multi-file support, scripting capabilities, and disassembly, assisting users in selecting the appropriate hex editor for their requirements. The repository aims to facilitate discovery within the hex editing space by presenting a diverse range of interfaces and licenses.

datadome-rs

2026-08-27 Rust ★ 73
High-end Rust DataDome deobfuscator & solver with VM disassembly — all 3 challenge types (tags, interstitial, slider).

PPS-MH8A-Transmitter

2026-08-27 Visual Basic .NET ★ 24
The PPS MH8A Transmitter is an Arduino-based tool designed to decode and transmit data packets from wireless air integration systems used in scuba diving. Its primary use case is to allow divers to monitor air pressure and related metrics by creating custom data packets that can be displayed on a computer or device. Notable features include a Windows standalone encoder for packet creation and forthcoming support for a receiver and additional encoding and decoding functionalities.

rz-libdemangle

2026-08-27 C ★ 11
Rizin libdemangle is a static library that provides demangling support for various programming languages within the Rizin framework. It can also be utilized independently as a command-line interface (CLI) tool, allowing users to demangle symbols from mangled identifiers, with features that support custom outputs and comprehensive testing options for development. The library is built using the Meson build system, facilitating easy installation and configuration for further development efforts.

sleepwalker

2026-08-27 C ★ 48
SLEEPWALKER is a passive backdoor tool designed for offensive security tasks, featuring a 64-bit Windows DLL that impersonates `dpapi.dll` and loads into ESET's Management Agent. It utilizes a proprietary command language interpreted through a 23-opcode bytecode system, allowing for various operations including data transmission and remote execution of shellcode upon receiving a specific trigger packet. Notably, the tool includes a Python controller for compiling and encrypting commands, alongside a configurable architecture enabling advanced covert command execution and behavior customization.

SR-Server

2026-08-27 C ★ 11
SR CoD4x is a modified server for Call of Duty 4: Modern Warfare that enhances gameplay by fixing original binary bugs and providing developers with a plugin system for extended server functionality. Key features include administration commands, anti-hacker measures, support for legacy clients, and advanced player movement mechanics, along with enhanced netcode and customizable server settings. This tool aims to improve the multiplayer experience and server reliability while introducing additional gameplay features.

atria

2026-08-27 Swift ★ 146
Atria is an open-source iOS application designed for local data collection and analysis using a WHOOP strap, eliminating the need for official cloud services or subscriptions. It offers features such as live heart rate monitoring, sleep and workout tracking, HealthKit export, and customizable metrics, allowing users to leverage their straps for honest local metrics while maintaining data privacy. The app communicates directly with the strap over Bluetooth LE, ensuring all data remains on the device.

flarevm-mcp

2026-08-27 Python ★ 11
FlareVM MCP is a Model Context Protocol server that facilitates remote access to a suite of over 48 Windows malware analysis tools within an isolated FlareVM environment, allowing seamless integration for AI agents and security analysts. Its notable features include remote file operations, comprehensive static and dynamic analysis capabilities, debugger integration, and a standardized interface for automatized workflows. This architecture enables enhanced malware examination while maintaining the security of the analysis environment.

krypton-devirtualizer

2026-08-27 C# ★ 16
Krypton is a .NET Reactor devirtualizer designed to transform virtualized or protected assemblies into executable, standalone Common Intermediate Language (CIL) code. Its primary use case involves reconstructing VM-protected methods, recovering hidden calls, and decrypting strings/resources, all while ensuring the output maintains original runtime behavior and functionality without reliance on the .NET Reactor runtime. Notable features include automated semantic validation, a generic reconstruction engine adaptable to various inputs, and a range of post-deobfuscation capabilities to enhance code readability and execution efficiency.

LHDC-V5-Decoder

2026-08-27 C ★ 12
The LHDC V5 Decoder is a real-time software decoder for the proprietary LHDC V5 Bluetooth audio codec, designed for use on the ESP32 platform within a Bluedroid A2DP sink. It supports a range of sample rates and bit depths, and features an optimized pipeline for efficient decoding with no dependencies on the ESP-IDF framework, making it versatile for both embedded and host applications. Notable features include support for various bitrates, interleaved stereo PCM reconstruction, and performance tuning specifically for the Xtensa LX6 architecture.

navimow_pro

2026-08-27 Python ★ 20
Navimow is an unofficial integration for Home Assistant that facilitates control and monitoring of Segway Navimow robot mowers using the vendor's private cloud protocol. Key features include customizable mowing schedules, real-time status updates through various sensors, a visual mapping interface, and a set of Lovelace cards for an enhanced user experience. This integration allows users to execute mowing commands and manage mower settings while maintaining oversight of the mower's operational status and performance.

Ryuumonbuchi

2026-08-27 Python ★ 45
Ryuumonbuchi is a headless Model Context Protocol (MCP) server that integrates with Ghidra to facilitate reverse engineering through direct interaction with its APIs via typed tool calls, eliminating the need for GUI automation and manual scripts. This tool supports a persistent PyGhidra and JVM backend, allowing multiple program session analyses including decompilation, disassembly, and patching, while maintaining efficient use of resources by reusing the backend across requests. With 216 distinct functions available to users, Ryuumonbuchi streamlines reverse engineering tasks within a robust and flexible architecture.

awesome-security-agent-harnesses

2026-08-27 ★ 16
Awesome Security Agent Harnesses provides a collection of AI-driven tools designed for penetration testing, code auditing, fuzzing, vulnerability discovery, and reverse engineering. The primary use case is to enhance security assessments through a variety of harnesses, sandboxes, and evaluation frameworks that streamline the detection and validation of vulnerabilities while minimizing false positives. Notable features include multi-agent collaboration, independent validation of findings, and integration with various coding agent methodologies to automate and enhance security processes.

ARSCLib

2026-08-26 Java ★ 401
ARSCLib is a Java library designed for the manipulation of Android binary resources, enabling users to read, write, modify, and create resource tables and binary XML files. Its primary use case is to replace aapt/aapt2 with enhanced decoding capabilities, allowing conversion to/from JSON and XML formats for both obfuscated and un-obfuscated resources, making resource management more accessible to developers. Notable features include seamless integration across platforms and the ability to handle unvalidated XML input, which provides flexibility in resource encoding without strict checks.

ghidra-emotionengine-reloaded

2026-08-26 Java ★ 231
Ghidra Emotion Engine: Reloaded is an extension for the Ghidra reverse engineering framework specifically designed to support the PlayStation 2 architecture. It enables users to disassemble and decompile Emotion Engine-specific instruction sets, recover data types and functions from ELF files, and import PCSX2 save states. Notable features include the STABS Analyzer for enhanced debugging capabilities and the MIPS-R5900 Constant Reference Analyzer for improved variable reference handling.

gtirb-pprinter

2026-08-26 C++ ★ 54
The GTIRB Pretty Printer is a tool designed to convert the GTIRB intermediate representation of binary files into gas-syntax assembly code, primarily for the purposes of binary analysis and reverse engineering. Notable features include the ability to generate reassembleable assembly files, create new binaries directly, and generate dummy shared object files to facilitate linking without actual libraries. The tool requires a C++17 compliant compiler and dependencies such as GTIRB and Capstone for its functionality.

IFDA

2026-08-26 Go ★ 43
IFDA is a tool designed for automated reverse engineering and vulnerability discovery in IoT firmware binaries, supporting the analysis of ELF files and extracted firmware trees. It features a bilingual web UI, integrates with existing tools like Capstone and PyELFTools for disassembly and ELF parsing, and offers a structured output for findings, including severity and vulnerability classifications. The architecture includes a Python analysis core and a Go service layer for orchestration, ensuring efficient task management and live progress tracking.

sdocx

2026-08-26 Rust ★ 19
sdocx is a reverse-engineered tool and SDK designed for parsing and converting Samsung Notes (.sdocx) files, primarily used to extract and manipulate handwritten notes stored in these formats. Key features include a command-line interface for easy access, library support for Rust and JavaScript environments, and a best-effort parsing approach that provides insights into document structure, stroke data, and metadata while acknowledging potential limitations and fidelity concerns.

skyroads-mac

2026-08-26 C ★ 15
SkyRoads for macOS is a native port of the classic 1993 DOS space-racing game, allowing it to run seamlessly on both Apple Silicon and Intel Macs without the need for emulation. It features a self-contained application that incorporates game data, customizable controls, and visual enhancements such as CRT effects, while supporting easy installation and building from source. Notable features include a fully rewritten engine in portable C with SDL2, support for AdLib music synthesis, and plans for future enhancements like online leaderboards and improved visual effects.

Free-RASP-Community

2026-08-26 ★ 511
freeRASP is a mobile in-app threat detection and security monitoring SDK designed to protect applications from runtime threats such as reverse engineering, repackaging, and unsafe operating environments. It offers a suite of precise security checks, is lightweight with minimal performance impact, and integrates easily with various platforms including iOS, Android, Flutter, and Unity. Notable features include real-time threat response via API, weekly security reports, and adherence to OWASP MASVS standards for resilience against reverse engineering.

RPC-Triage

2026-08-26 Python ★ 12
RPC-Triage is a static analysis tool designed to assess the Windows RPC attack surface by analyzing compiled PE binaries to identify registered RPC servers and their corresponding method signatures, security flags, and transport bindings. It uniquely ranks interfaces based on a composite score of reachability and danger, providing detailed receipts for transparency in scoring. Notably, the tool operates without the need for symbol files, making it effective on stripped binaries found in production environments.

WinSecRuntime

2026-08-26 C++ ★ 44
WinSecRuntime is a Windows runtime security library implemented in C++20, designed to enhance application integrity by providing defensive mechanisms against tampering, debugging, and injection attacks. It features a modular architecture that supports header-only usage, static libraries, and hardened DLLs, allowing developers to configure anti-debugging, anti-hooking, and memory safety checks tailored to their security needs. The library emphasizes redundancy and safe detection methods rather than deceptive techniques, making it suitable for production environments focused on security hardening.

androidReverse

2026-08-25 ★ 108
Android Reverse is a comprehensive reverse engineering toolkit designed to operate entirely on Android devices, eliminating the need for PC-based tools or ADB. Key features include multi-engine Java decompilation, native binary analysis facilitated by an embedded Radare2 engine, and advanced APK manipulation abilities such as resource editing, AXML editing, and APK rebuilding. The tool also supports a Model Context Protocol server for AI-assisted editing, making it suitable for both manual and automated reverse engineering tasks.

ESP_RTK_ROVER

2026-08-25 HTML ★ 10
ESP_RTK_ROVER is a DIY GNSS rover that repurposes a ComNav K803 Lite board with a Seeed Studio XIAO ESP32C6 to provide centimetre-accurate positioning via Bluetooth for mobile GIS applications. Noteworthy features include automatic configuration as a rover at boot, bi-directional data transmission, Bluetooth Low Energy communication compatibility, and a web-based dashboard for real-time diagnostics. It serves hobbyist applications such as autonomous robotics, DIY auto-steering, and educational purposes in GNSS and RTK technologies, although it is not designed for professional surveying or critical applications.

Ghidra-Switch-Loader

2026-08-25 Java ★ 366
Ghidra Switch Loader is a Ghidra extension designed to support various Nintendo Switch file formats, enhancing reverse engineering capabilities for these files. Its primary use case involves facilitating the analysis and debugging of Nintendo Switch games and applications within the Ghidra development environment. Notable features include compatibility with multiple file formats and straightforward installation via Ghidra's extension management system.

logitech-ipc-protocol

2026-08-25 Python ★ 17
logitech-ipc-protocol is a tool that provides reverse-engineered documentation and programmatic control of Logitech multi-host devices through the Logi Options+ agent IPC protocol, addressing limitations in macOS regarding raw HID access. This tool enables seamless device switching and input monitoring on both macOS and Windows platforms, featuring scripts for automated switching, hotkey configurations, and enhanced integration for multi-device setups. Notably, it includes a monitor-follow daemon that automatically switches monitor inputs based on keyboard activity, thereby enhancing user experience in multi-host environments.

tiktok-msddk-info-fully-reversed

2026-08-25 Python ★ 11
The TikTok X-Mssdk-Info Reverse Engineering & Decrypter is a comprehensive Python tool designed to analyze and decrypt the X-Mssdk-Info telemetry header used by TikTok for device fingerprinting and security measures. It operates without external dependencies, enabling users to generate and decrypt the header payloads for API verification and device registration processes. Notable features include a complete implementation of the XXTEA encryption algorithm used by TikTok, alongside detailed instructions for payload generation and decryption.

Flux

2026-08-25 C ★ 21
Flux is a compiled, statically typed systems programming language designed to optimize performance while providing an advanced type system that exceeds C's capabilities. Its primary use case is in systems programming where high efficiency and fine-grained control over data types and memory layout are essential, featuring notable attributes such as arbitrary-width integers, compile-time code generation, and a unique approach to zero-copy packet parsing. The language aims to empower developers with powerful tools and flexibility, expecting them to manage complexity effectively.

MafiaToolkit

2026-08-25 C# ★ 153
Mafia Toolkit is a Windows modding toolkit designed for the Mafia series, featuring comprehensive file format parsers, editors, and a 3D map editor to facilitate game modification. It supports several games including Mafia II and Mafia III, providing tools for editing materials, managing SDS archives, and configuring AI integration via the Model Context Protocol server. Notable features include a robust map editor with DirectX 11 rendering capabilities, extensive data editing options for game files and tables, and support for FBX model import/export.

vo_patch

2026-08-25 Python ★ 44
vo_patch is a tool designed to optimize and facilitate the installation of *Cyber Troopers Virtual-On* on modern systems, primarily by addressing compatibility issues such as crashes and frame rate problems. Notable features include XInput gamepad support for two players, internet play functionality without the need for port forwarding, and the ability to run the soundtrack from files instead of the disc, thereby enhancing the overall gaming experience.

BTG-packer

2026-08-24 Rust ★ 27
BTG Packer is a Rust-based research framework for the analysis, transformation, and virtualization of Windows x86-64 PE32+ executables. It features comprehensive functionality including PE reconstruction, control-flow transformation, RISC lifting, and runtime protection, making it suitable for security research and code modification tasks. Notable capabilities include its ability to generate polymorphic virtual machines, conduct advanced code analysis, and ensure build determinism and structural validation.

libd2

2026-08-24 Zig ★ 12
libd2 is a clean-room reimplementation of the Diablo II 1.14d engine core, written in Zig, designed primarily for game development and reverse engineering. It features a seed-driven map generator that replicates the game's world, along with comprehensive systems for item generation, network protocols, and world routing, all accessible across multiple programming languages and platforms, including WASM support. The library allows for on-the-fly act generation and provides rich functionalities through various APIs, ensuring seamless integration for developers.

vanmoof-bms

2026-08-24 Go ★ 14
The VanMoof BMS Toolkit is a diagnostic and control utility designed for managing VanMoof DynaPack BMS batteries across various bike models. It enables users to interact with the battery management system via Modbus/UART or CAN interfaces, offering functionalities such as real-time data display, calibration, and log management. Notable features include support for multiple hardware configurations, a range of commands for battery operations, and the ability to export logs for analysis.

Ghidrust

2026-08-24 Rust ★ 12
Ghidrust is a Rust-based reverse-engineering toolkit designed for analyzing PE and ELF binaries, offering multi-architecture support through Capstone-class listings and pseudo-C decompilation. Its key features include a headless CLI, a GUI interface, an experimental GPU decompilation capability for enhanced performance, and integrated network analysis via Ghidnet for process attribution and IDS records. Ghidrust aims to improve upon Ghidra's analysis speed and output quality while maintaining a small, auditable core.

rilua

2026-08-24 Rust ★ 42
rilua is a Rust-based implementation of Lua 5.1.1 designed primarily for the World of Warcraft emulation ecosystem, enabling addon development, server-side scripting, and client Lua environment emulation without external dependencies. Notable features include a safe memory model with no unsafe blocks, structured error handling that preserves the call stack, and native WASM support, making it suitable for embedding in Rust applications while facilitating accurate behavioral equivalence with the reference Lua interpreter.

x64dbg-mcp-server

2026-08-23 Zig ★ 1796
x64dbg-MCP Server is a native plugin for x64dbg that enables programmatic control of the debugger over HTTP, utilizing the Model Context Protocol (MCP). Its primary use case is for enhanced reverse engineering, allowing users to manage breakpoints, step through code, and access memory and registers via any MCP-compatible AI assistant. Notable features include zero dependencies, dual transport methods (streamable HTTP and SSE), and comprehensive debugger control with 71 available tools and 22 event callbacks.

desvendando-elifoot-98

2026-08-23 C ★ 16
Desvendando o Elifoot 98 é uma ferramenta de engenharia reversa que analisa o motor do jogo clássico Elifoot 98, utilizando Ghidra e Cheat Engine para explorar algoritmos, fórmulas, e mitos relacionados ao jogo. O repositório documenta as mecânicas internas do código, como a influência das nacionalidades dos jogadores e a estrutura de dados, desmistificando crenças populares que circularam por anos. Notáveis recursos incluem a verificação de mecânicas de jogo e a demonstração de como são calculadas as forças dos times, com uma abordagem técnica para dissecação de um jogo de 16 bits.

VanBus

2026-08-23 C++ ★ 75
VanBus is an Arduino library designed for reading and writing packets on the VAN bus of Peugeot and Citroën vehicles, which communicates using a protocol similar to CAN bus. It supports ESP8266 and ESP32 platforms, facilitating interactions with comfort-related equipment in vehicles manufactured by PSA up until around 2009. Notable features include compatibility with various hardware setups and comprehensive schematics for implementation, ensuring ease of use for developers working on automotive applications.

antigravity-patch-proxy-remote

2026-08-23 Dart ★ 13
The Google Antigravity Custom Model Proxy is a tool designed to enable seamless integration of various large language models (LLMs) into the Google Antigravity IDE. It supports multiple providers such as Anthropic, OpenAI, and DeepSeek, and features real-time bi-directional SSE streaming, native UI integration, and robust AES-256-GCM encryption for secure communications. This proxy acts as a bridge, translating requests between the IDE and LLMs while maintaining high interoperability and performance.

bosectl

2026-08-23 Python ★ 41
bosectl is a command-line tool designed for controlling Bose headphones on Linux and macOS without the need for an app or cloud services. It utilizes the Bose BMAP protocol over Bluetooth RFCOMM, providing users direct access to manage features such as noise cancellation, equalization, spatial audio, button mapping, and device profiles. The tool supports various Bose devices, ensuring comprehensive customization options and functionalities.

DanyAPI

2026-08-23 Python ★ 22
DanyAPI is an OpenAI-compatible HTTP API implemented using Python and FastAPI, designed to interact with the internal APIs of free web clients, enabling users to bypass the need for paid API keys. It utilizes server-side accounts created from user-supplied tokens for chat services, allowing seamless API consumption without requiring additional authentication from end users. Notable features include ease of integration with existing fast API setups and support for multiple Python versions.

openrecet

2026-08-23 C ★ 11
OpenRecet is an open-source C reimplementation of the Win32 engine for Recettear: An Item Shop's Tale, designed as a drop-in replacement for the original executable for users with a legitimate copy. This educational reverse-engineering project focuses on game preservation, ensuring no copyrighted content is included, and implements rigorous verification methods to achieve behavioral parity with the original game engine. While the project is in early stages and not yet playable, it has made significant progress in rendering key components of the game.

Chaos-Zero-Nightmare-ASSet-Ripper

2026-08-22 C++ ★ 51
Chaos Zero Nightmare ASSet Ripper is a specialized asset extraction tool designed to retrieve encrypted game assets from the Yuna engine and specific anime games. It features support for exporting various formats, including SCT images as PNG, encrypted databases as JSON, and SCSP Spine format, with an integrated viewer for the latter. The tool allows users to navigate a file tree for asset management and enables batch exports of selected files and folders, enhancing usability for game modding and asset repurposing.

LegoDimensions

2026-08-22 C# ★ 42
The LegoDimensions tool provides a .NET implementation for interacting with the Lego Dimensions portal and NFC tags, enabling users to automate and manipulate these elements beyond their original gaming context. Its primary use case includes reading tags and controlling portal LEDs, with support for various platforms including Windows, Linux, and MacOS, facilitating integration with devices like Raspberry Pi. Notable features include event-driven handling of tag presence and dynamic LED color adjustments for the portal pads.

new-reddit-com

2026-08-22 TypeScript ★ 10
The tool is a userscript designed to migrate the deprecated Reddit API endpoints `gateway.reddit.com` and `gql.reddit.com` to functional alternatives, ensuring continued access to Reddit content. Its primary use case is for users requiring legacy API functionality to interact with Reddit while leveraging a modular architecture for network requests. Notable features include the ability to inspect network traffic through a script manager and independent operations from Reddit Inc.

plugin-ghidra

2026-08-22 Java ★ 188
The RevEng.AI Ghidra Plugin integrates with Ghidra to facilitate AI-assisted binary analysis, enabling users to upload binaries for analysis and perform Binary Code Similarity operations. Its notable features include automatic function renaming based on confidence thresholds and the ability to display similar function names, which assist in reverse engineering stripped binaries. This tool is particularly useful for security researchers and software developers involved in binary analysis and reverse engineering tasks.

caterpillar

2026-08-22 Python ★ 39
Caterpillar is a Python library designed for the efficient packing and unpacking of structured binary data, building upon Python's native `struct` capabilities. Its primary use case is facilitating the declaration of custom data structures through Python class definitions, enabling features like dynamic endian configuration, inheritance-based struct adaptation, and the implementation of bitfields and unions. Notable functionalities include memory optimization via `__slots__`, type compliance for static checking, and extensibility for custom parsing logic written in C or C++.

Creation-Kit-Platform-Extended

2026-08-22 C++ ★ 136
Creation Kit Platform Extended (CKPE) is an enhanced editing platform for Bethesda's Creation Kit, providing a collection of modifications and reverse-engineered resources aimed at improving the user experience for titles like Skyrim Special Edition, Fallout 4, and Starfield. Notable features include various fixes, editor enhancements, and additional support for Unicode, aimed at streamlining game modding workflows. This platform serves as a comprehensive successor to previous projects focused on improving the Creation Kit's functionality.

CSS-MultiHack-Internal

2026-08-22 C++ ★ 18
The CSS-MultiHack-Internal is an internal multihack designed for Counter-Strike: Source, featuring functionalities such as aimbot, triggerbot, bunnyhop hack, and anti-flash capabilities. It requires a DLL injector for installation and operation, allowing the user to toggle features via an in-game menu. Notable features include precise aimbot functionality, automatic jumping through the bunnyhop hack, and the capability to negate flashbang effects.

HSR-OWNER

2026-08-22 Rust ★ 43
HSR-OWNER is a comprehensive reverse-engineering and modding toolkit specifically designed for Honkai: Star Rail on Windows, stripped of any illicit cheat features to maintain legitimacy. It provides functionalities to analyze game data, modify client behavior, and aid in updating through minimal manual intervention, with full support for integration with AI tools for automation. Key features include a runtime layer that adapts to game updates, in-depth client analysis capabilities, and a straightforward build process using the MSVC toolchain.

Persona3-FES-Decompilation

2026-08-22 C ★ 48
Persona 3 FES Decompilation is a work-in-progress project aimed at decompiling the USA version of Shin Megami Tensei: Persona 3 FES. Its primary use case is to provide a complete source code version of the game, facilitating modifications and research into its architecture. Notable features include ongoing efforts towards achieving a fully comprehensive decompilation to enhance accessibility for developers and modders.

wc2-re

2026-08-22 C ★ 17
Wing Commander II source reconstruction and SDL2 port serves to restore and port the classic space combat game "Wing Commander II" as found in "Wing Commander: The Kilrathi Saga." This project enables cross-platform gameplay through the SDL2 framework, supporting both Kilrathi Saga and partial original DOS game data, while offering significant fidelity in function mapping with 98.06% machine-code similarity to the original executable. Notable features include enhanced graphical rendering options, full mouse and joystick support, and various fixes to improve user experience, such as window resizing and aspect ratio correction.

IDA-Skill

2026-08-21 Python ★ 222
IDA Skill is an AI-powered tool that enables automated malware analysis using IDA Pro, mimicking the capabilities of human security analysts. It features automatic identification of malicious behavior, code functionality understanding, key information extraction, and threat indicator localization, enhancing malware investigation efficiency. Notable components include REAI for AI function analysis and FindCrypt for detecting encryption algorithms, facilitating comprehensive and advanced threat assessment.

fitface-studio

2026-08-21 Kotlin ★ 17
FitFace Studio is an Android application designed for customizing Fit3 (SM-R390) watch faces by allowing users to browse, edit, and install them directly to their watches via Bluetooth. The tool features a catalogue for searching and sorting watch faces, a layout editor for altering backgrounds and widgets, and does not redistribute watch face packages; instead, it edits the original binary directly. With functionalities such as widget movement, color adjustments, and real-time validation before installation, it facilitates a user-friendly interface for personalizing watch faces without the need for app re-signing or installation on the device.

NotDec

2026-08-21 C++ ★ 93
NotDec is a WebAssembly decompiler and static analysis framework that focuses on enhancing decompiler techniques through variable recovery and structural analysis. Its primary use case is to facilitate detailed type recovery experiments, allowing developers to gain insights into the inner workings of decompilation processes while improving their algorithms iteratively. Notable features include customizable environment variables for debugging type recovery and a robust setup for experimenting with LLVM and C code generation.

metaforce

2026-08-21 C++ ★ 733
Metaforce is a reverse-engineered reimplementation of the video game Metroid Prime, currently in alpha state and focused on providing a native, cross-platform gaming experience on Windows, macOS, and Linux. Its notable features include support for multiple graphics APIs (D3D12, Vulkan, OpenGL, Metal), a console logging option, and developer functionalities such as world/area warping, enabling users to explore and debug the game more effectively. The project is supported by ongoing contributions from its decompilation counterpart, enhancing bug fixes and new implementations.

Onyx-External-ESP

2026-08-21 C++ ★ 11
Onyx External ESP is a tool designed for emulation on Android x86_64 architecture, specifically for the MuMu Player, providing users with external ESP (Extra Sensory Perception) features such as skeletons, snaplines, bounding boxes, health indicators, and off-screen markers. Primarily aimed at educational purposes, it serves as a foundational codebase for understanding and modifying ESP implementations in games, though it currently lacks support for physical ARM devices and certain advanced features due to game obfuscation. The tool includes automated batch scripts for straightforward building and deployment, enhancing the user experience for developers and researchers.

Arkana

2026-08-21 Python ★ 208
Arkana is a comprehensive malware analysis tool that streamlines the investigation process by integrating 308 specialized analysis tools through a single AI-driven interface. It allows users to submit natural language prompts to conduct extensive malware evaluations, including decompilation, vulnerability detection, and real-time data enrichment without switching between multiple applications. Notable features include automated risk scoring, MITRE ATT&CK mapping, and interactive debugging capabilities, all designed to enhance efficiency in analyzing PE, ELF, and other binary formats.

crossroads-2-disassembly

2026-08-21 Assembly ★ 13
crossroads-2-disassembly is a reverse engineering tool designed to disassemble and analyze the C64 game Crossroads 2, originally published in 1988. It allows users to generate ASM files that replicate the original game, with optional variations to enhance gameplay, such as always displaying credits and modifying escalation levels. Notable features include handling complex assembly language constructs, such as the "BIT NOP trick" and self-modifying code challenges, enabling a clearer understanding of the game's underlying mechanics.

dmg-schematics

2026-08-21 KiCad Schematic ★ 46
The dmg-schematics repository provides comprehensive reverse-engineered schematics of the Game Boy DMG-CPU B chip and the SM83 CPU core using KiCad. It includes detailed layouts, parsable netlists, and exportable formats such as PDF. Notable features consist of an Electric VLSI cell library for standard cells, modified overlay SVGs that sync with the schematics, and a netlist formatting tool that generates readable outputs and simulation code.

JavaShroud

2026-08-21 Kotlin ★ 87
JavaShroud is a comprehensive obfuscation and hardening toolchain for Java applications, utilizing bytecode transformation through a Kotlin engine and enabling the execution of lowered methods within a Native bytecode VM (NBVM). It offers various features, including class and method renaming, string encryption, control flow obfuscation, method virtualization, and integrated runtime protections, designed to enhance security by increasing the costs associated with reverse engineering and code analysis. The tool emphasizes the generation of unique keys and layouts for each output, adhering to the Kerckhoffs principle, ensuring that the strength of the protection does not rely on implementation secrecy.

MikuSB

2026-08-21 C# ★ 671
MikuSB is an open-source server emulator for a specific dungeon anime game, designed to enable local gameplay and testing by mimicking server functionalities. It features distinct components including `SdkServer` for HTTP API responses, `GameServer` for TCP connections, and an optional local proxy for domain redirection. Key capabilities include account management, player data handling, inventory, and weapon functionalities, while supporting research and educational purposes within a safe environment.

openevv

2026-08-21 C ★ 24
openevv is a portable implementation of IBM's Embedded ViaVoice text-to-speech engine, reengineered in C for compilation on non-Windows platforms, enabling text-to-speech functionality with byte-for-byte fidelity to IBM's original audio outputs. Its primary use case includes generating audio from text and serving as an add-on for screen readers, with features like multiple voice presets and the ability to produce wave files for playback on Linux systems. The tool is built entirely from scratch without reliance on IBM's SDK, and includes both command-line and graphical interfaces for user interaction.

oswatcher

2026-08-21 ★ 67
OSWatcher is a tool designed for the preservation and analysis of historical operating system releases, allowing users to query a comprehensive graph of changes across OS versions from Windows 95 through 11 and Ubuntu 6.10 to 25.04. Using a Merkle graph model stored in Neo4j, it enables users to explore file evolutions, provenance of artifacts, and commonalities across releases, akin to a version control system for OS images. Notably, OSWatcher emphasizes offline image analysis rather than real-time monitoring, differentiating itself from similar tools like Oracle's OSWatcher Black Box.

rockchip-npu-notes

2026-08-21 Shell ★ 13
The `rockchip-npu-notes` repository provides comprehensive reverse-engineering documentation for the Rockchip RK3588 Neural Processing Unit (NPU), focusing on the hardware's register-command interface and its integration with the mainline `rocket` DRM-accel driver. It includes subsystem-organized notes detailing machine parameters, register offset maps, precision encodings, and operational quirks, aiming to assist users constructing custom compute solutions using the RK3588. Notable features include empirical observations tagged with their verification methods, alongside in-depth explanations of NPU architecture and operational capabilities.

smali

2026-08-21 Java ★ 117
smali/baksmali is an assembler and disassembler for the dex format utilized by Android's Dalvik Virtual Machine, enabling users to manipulate Android bytecode effectively. It supports comprehensive features of the dex format, including annotations and debugging information, while providing a command line interface for building and testing. The tool is a maintained fork of the original smali project, ensuring ongoing updates and support through Google Maven distribution.

somtoday-api-docs

2026-08-21 ★ 85
The SOMtoday REST API provides comprehensive documentation for integrating with the SOMtoday educational management platform. Its primary use case is to facilitate access to various educational data endpoints, including student information, grades, schedules, and homework assignments via RESTful API calls. Notable features include authentication mechanisms, support for fetching specific student and school data, and options for accessing data in iCalendar format.

swift-dwarf

2026-08-21 Swift ★ 21
swift-dwarf is a Swift library designed for parsing binary files to extract DWARF debugging information from Mach-O and ELF binary formats. It utilizes MachOKit for Mach-O files and ELFKit for ELF files, supporting various DWARF sections such as `.debug_info`, `.debug_str`, and `.debug_line`. The tool provides interfaces to easily access string tables, abbreviation sets, and compilation units, facilitating a streamlined debugging process for developers working with low-level binaries.

hacksguard

2026-08-20 Rust ★ 204
Hacksguard is a high-performance, multi-threaded Terminal UI (TUI) static analysis tool designed for SOC analysts, threat hunters, and reverse engineers to analyze Portable Executable (PE) files. Key features include automatic risk scoring based on multiple heuristic axes, integrated YARA scanning capabilities for threat detection, deep inspection of PE format details, and an interactive dashboard for efficient analysis within the terminal. Additionally, it offers functionality for auto-decoding strings, built-in disassembly of opcodes, and can operate in CLI mode for automation in CI/CD environments.

Recaptcha-VM

2026-08-20 JavaScript ★ 10
reCAPTCHA VM is a tool that emulates Google's reCAPTCHA validation mechanism by running its BotGuard engine in a jsdom sandbox environment, enabling the generation of legitimate reCAPTCHA tokens without a browser. It fully supports reCAPTCHA v3 token minting and provides a scoring mechanism to evaluate token legitimacy, while also offering a proof-of-concept for reCAPTCHA v2 that demonstrates the anchor flow and audio challenge URL capture. Key features include real network calls to Google's API and an in-depth implementation of the VM's bytecode interpretation.

ecd

2026-08-20 Java ★ 18
ECD++ is a fork of the Enhanced Class Decompiler (ECD) designed for decompiling Java class files into readable source code. Its primary use case is to assist developers in analyzing and understanding compiled Java applications by providing improved decompilation capabilities. Notable features include support for integration with Eclipse, multiple download sources (GitHub, Jitpack, SourceForge), and regular updates to enhance functionality and performance.

fnprint

2026-08-20 Rust ★ 34
fnprint is a binary analysis tool that uniquely identifies functions in stripped executables by analyzing their behavioral side effects rather than relying on byte signatures or control-flow graphs. It emulates function execution with fabricated inputs to generate behavior-based fingerprints, allowing for more resilient matches across different compiler optimizations and versions. Key features include indexing known binaries for function identification, differential analysis to detect behavioral changes between builds, and a triage capability to assess potential vulnerabilities based on function behavior comparison.

js-reverse-mcp

2026-08-20 TypeScript ★ 2619
JS Reverse MCP is an AI-native JavaScript reverse engineering server designed to enhance AI coding assistants with continuous debugging and analysis capabilities for web JavaScript behavior. It features advanced tools for breakpoint management, network and WebSocket analysis, and browser state replay, while also incorporating anti-detection mechanisms to navigate strongly protected sites seamlessly. The tool organizes script execution and data handling specifically for AI agents, enabling them to perform sophisticated tasks like locating scripts, saving sources, and reproducing complex web interactions.

listary-keygen

2026-08-20 TypeScript ★ 27
Listary Keygen is a Windows GUI tool designed for activating the Listary Pro license using a single-click process. It employs reverse engineering techniques to bypass the official license verification system, allowing users to generate and write a valid license key directly into the application's configuration file. Notable features include automatic key generation, backup of existing settings, and a straightforward user interface for seamless activation.

yuri

2026-08-20 Python ★ 19
Yuri is a decompiler and compiler specifically designed for the Yu-Ris engine, featuring support for parallel processing. Its primary use case is facilitating the decompilation and compilation of game files from various versions of the engine, including both public and commercial releases. Notable features include tools for text extraction and translation, such as `patch_text.py` for editing dialogue in .yuri files and `gbk.py` for modifying text encoding to support Chinese translations.

helm-d

2026-08-19 Python ★ 32
helmd is a comprehensive security analysis plugin designed for the DeepSeek Harness, integrating capabilities across six domains: Android, Web, Native, Protocol, Malware, and AI-Security. This tool facilitates a streamlined installation with ten independently released bundles, enabling users to access all essential functionalities with minimal configuration while maintaining a modular architecture for on-demand knowledge and tool utilization. Notable features include first-round tool anchoring for user queries, specialized routing for domain-related tasks, and a focused referencing system that supports autonomous model decision-making.

open-web-bridge

2026-08-19 JavaScript ★ 13
Open Web Bridge is a tool designed to facilitate the interaction of AI agents with a user's personal web browser, leveraging authenticated sessions and user-specific data. The tool features a command-line interface that integrates seamlessly with AI agents, offering capabilities such as semantic snapshots for web elements, waiting primitives for improved asynchronous interactions, and options for both local and remote operation modes. Notably, it allows AI agents to perform tasks in real-time using the currently active browser session, enhancing their ability to access and manipulate content beyond publicly available information.

ReHitman

2026-08-19 C++ ★ 70
ReHitman is a reverse engineering project aimed at modifying the game "Hitman: Blood Money" to create a multiplayer experience similar to Mafia 2's multiplayer. The tool focuses on developing an open-source SDK for the Glacier 1 Engine, reversing its rendering and input APIs, and building an associated toolset for game enhancements. Notable features include the integration of an ImGUI backend and current work on the game's scene format and GUI API.

ane-guide

2026-08-19 Shell ★ 11
The Apple Neural Engine (ANE) guide provides an in-depth examination of the architecture, programming, and performance characteristics of Apple's proprietary neural hardware present in its A11 and M1 silicon. It details the internal mechanisms, data pathways, and performance metrics of the ANE, with sections dedicated to model deployment and tuning as well as comprehensive documentation on the engine's programming interface, memory hierarchy, and private runtime features. This guide serves as a resource for research and development purposes, emphasizing that the methods described are not officially supported by Apple and are subject to change with operating system updates.

Grok-Api

2026-08-19 Python ★ 314
Grok-Api is a deprecated Python API wrapper for Grok AI that enables users to interact with the conversational AI without needing official API credentials or accounts. This tool features a FastAPI server for RESTful access, supports HTTP proxies, and allows for high-performance, concurrent requests with streaming response capabilities. Notably, it provides both automatic and expert processing modes, though it is rendered obsolete due to changes in Grok's access policy.

cordial

2026-08-19 Rust ★ 22
Cordial is a tool that enables the native execution of Roblox's Android x86-64 engine on Linux, employing a custom runtime that bypasses traditional emulation methods. It uniquely supports user-extensible functionality through plugins, allowing developers to write custom code that integrates directly into the client without modifying the core Roblox experience. Notable features include direct GPU access through Vulkan or GLES2 and a robust API designed for plugin development, emphasizing a commitment to maintainability and community contribution.

cross-channel_chinese-localization_project

2026-08-19 Ren'Py ★ 279
The CROSS†CHANNEL Chinese Localization Project is a collaborative effort aimed at translating the visual novel "CROSS†CHANNEL" and its remake into Chinese, utilizing a patch system for language integration. Notable features of this project include an extensive staff contributing to translation and quality assurance, as well as a suite of tools developed for packaging and deploying the localization, which eliminates dependencies on the Windows registry. The project is open-source under GPLv2, ensuring that any derivative works must remain open-source as well.

DeNuitkanizator

2026-08-19 Python ★ 18
DeNuitkanizator is a utility designed for analyzing .exe files compiled with Nuitka and other packagers such as PyInstaller. Its primary use case is for reverse engineers and malware analysts, providing detailed extraction of metadata, strings, modules, and PE structure information, while also disassembling machine code and identifying potential suspicious patterns. Notably, it distinguishes between different packagers, retrieves network-related data, and analyzes the executable's PE structure, although it does not function as a decompiler.

ELFKit

2026-08-19 Swift ★ 37
ELFKit is a library designed for parsing ELF (Executable and Linkable Format) files, enabling users to extract detailed information about segments, sections, dynamics, and symbols. Its notable features include the ability to retrieve all C strings and rebase information, making it particularly useful for developers involved in reverse engineering and binary analysis. The tool is implemented in Swift and provides a straightforward interface for loading ELF files from the filesystem.

kx-trainer-free

2026-08-19 C++ ★ 38
KX Trainer Free is an open-source utility for Guild Wars 2 that injects itself as a DLL to provide an in-game overlay menu, enhancing gameplay functionality. Its primary use case is to assist players with various game tools while ensuring compatibility with updates through community contributions. Notable features include modular maintainability, user-configurable hotkeys, and a commitment to transparency and educational use.

lucasartsifier

2026-08-19 Python ★ 47
The Sierra softlock analyzer is a static analysis tool designed for decompiling and enhancing Sierra SCI adventure games by identifying and mitigating softlocks—game states where players can input commands but cannot win. It effectively derives, verifies, and installs protective guards against these non-winnable scenarios without requiring any game-specific code, allowing for seamless integration and the preservation of original game content. Notable features include automated trap detection, comprehensive scripting alterations, and customizable guard behaviors, ensuring gameplay remains normal while safeguarding against progression-blocking states.

MBBSDASM

2026-08-19 C# ★ 56
MBBSDASM is a C#-based disassembler designed for analyzing 16-bit segmented executable files, specifically targeting MajorBBS and Worldgroup modules, as well as any NE format DLLs and executables. It features a command-line interface to support varied disassembly modes, including minimal, normal, and enhanced analysis that provides extensive information on code segments, external references, and string resolutions. Additionally, MBBSDASM offers a cross-platform text-based user interface for ease of use.

sonar-bypass

2026-08-19 Java ★ 11
Sonar Bypass is a Node.js script designed to circumvent the Sonar 2.1.x anti-bot verification mechanism for Minecraft servers by mimicking legitimate client behavior through raw socket communication. The tool operates without the need for captcha solving or manual interaction, handling various verification stages by copying the exact interactions of a real player, documented in its accompanying research files. Key features include automated packet responses and support for multiple server environments, making it effective for bypassing bot protections in targeted servers.

omp-re

2026-08-18 TypeScript ★ 10
`omp-re` is a reverse-engineering plugin for the Oh My Pi framework that utilizes Radare2 and offers a suite of 22 tools for in-depth binary analysis. Its primary use case is to facilitate the examination of binary files, featuring an interactive function navigator, decompilation capabilities, and a robust evidence storage system that ensures claims in reports are substantiated by gathered facts. Notable features include an HMAC-signable audit log and an evidence citation system, enhancing the reliability and traceability of the analysis process.

xrefer

2026-08-18 Python ★ 321
XRefer is a Python plugin for the IDA Pro disassembler that enhances binary analysis through a custom navigation interface. It clusters related functions, highlights execution paths, and integrates external data sources to provide context-rich path graphs, significantly speeding up manual static analysis. Notable features include LLM integration for generating natural language descriptions of code relationships and the ability to incorporate API traces and custom xrefs for improved insights.

DarkDex

2026-08-18 C++ ★ 12
DarkDex is a powerful tool designed to extract and reconstruct the real dex file from packed Android applications, including those protected by advanced packers like ijiami 4th generation. It operates in two modes: a host script that leverages memory reading from outside the Android sandbox, and an APK that runs directly on the device, facilitating full memory dumps in root mode or disk dex pulls without root. Notable features include an event-driven capture system that captures decrypted dex in real-time, as well as utilities for validating, deduplicating, and testing the output disassemblies.

robinhood-cli-mcp-api

2026-08-18 TypeScript ★ 10
Robinhood CLI (MCP + API) is an unofficial command-line interface and server designed for managing Robinhood accounts directly from the terminal. It offers comprehensive access to brokerage features, including options trading, recurring investments, dividends, and more, allowing users to execute trades while ensuring control over their investment strategies with real-time updates and dry-run capabilities. Notably, it leverages Robinhood's private web API for account interactions, providing a streamlined management experience not dependent on the official platform.

discord-badge-spoofer

2026-08-18 Python ★ 46
The Discord Badge Spoofer is a tool designed to artificially inflate the "hours played" and "games played" badges on Discord profiles by sending spoofed game events to Discord's analytics endpoint. This experimental Python application requires user authentication, including an account token and a cookie, to simulate playtime through commands for claiming hours and marking games as played. Notably, while the tool can track playtime without additional setup, the games-played count necessitates a legitimate executable fingerprint obtained from the user's own client, emphasizing its experimental nature and potential violation of Discord's terms of service.

hp-laser-1008a-macos

2026-08-18 C ★ 155
The HP Laser 1008a on macOS project provides a solution for printing with specific HP Laser printers that lack native macOS support by utilizing a Linux container to run HP's rastertospl driver. This tool enables users to print directly from any application via the standard Cmd-P method without reliance on terminal commands or external scripts, making it user-friendly for Apple Silicon macOS environments. Key features include automatic installation via a single command and seamless integration with the CUPS printing system, circumventing multiple compatibility limitations.

ida-headless-mcp

2026-08-18 Rust ★ 12
ida-headless-mcp is a Rust-native server designed for headless interactions with IDA Pro, allowing for multi-session handling of databases through a supervisor-worker model. It provides public tools for database management and analysis, supports both stdio and Streamable HTTP modes, and is optimized for a headless environment with no GUI components involved. Notable features include individual worker processes for each database session and a limit on the number of simultaneous worker processes for efficient resource management.

rr-decomp

2026-08-18 C ★ 20
rr-decomp is a decompilation tool for the PlayStation 1 game Ridge Racer, enabling users to reconstruct the game's source code from their legally-owned copy of the original disc. This tool generates assembly listings and a native runtime, facilitating a static recompilation approach that allows for incremental function replacement without breaking the gameplay experience. Notable features include the ability to verify progress in decompilation, ensuring no copyrighted assets are included, and the provision to create a playable version of the game using user-supplied data.

beosound5c

2026-08-18 Python ★ 25
BeoSound 5c is a software tool that modernizes the Bang & Olufsen BeoSound 5 experience by utilizing web technologies on a Raspberry Pi 5. It features a circular arc-based touch UI and integrates with various music services and devices, offering seamless remote control, configuration options, and support for legacy hardware like the original BS5 rotary encoder and display. Additionally, it incorporates a security model that ensures a trusted home network environment and protects sensitive configuration data.

KeyDot

2026-08-18 C++ ★ 122
KeyDot is a high-performance command-line tool that extracts encryption keys and detects engine versions from compiled Godot Engine games, specifically targeting Windows x64 executables and WebAssembly (`.wasm`) files. Its primary use case is static analysis of game files without requiring runtime execution, which enhances safety and efficiency. Notable features include optimized C++ code for rapid extraction, memory-mapped file usage for low memory consumption, and unique support for WASM files, making it an essential tool for developers working with Godot Engine games.

lm-decomp

2026-08-18 C ★ 28
The lm-decomp repository provides a work-in-progress decompilation of the game Luigi's Mansion, enabling users to analyze and understand the game's code without including any proprietary assets. It supports multiple versions of the game across various regions, including USA, Japan, and multiple PAL revisions, allowing for robust examination and potential modification of the code. Notably, the project strictly prohibits AI contributions to maintain code integrity and legal compliance.

newserv

2026-08-18 C++ ★ 265
newserv is a comprehensive game server and proxy tool specifically designed for the Phantasy Star Online (PSO) community, facilitating reverse-engineering and custom gameplay experiences. It supports features such as user accounts, server-side saves, cross-version play, and a REST API, while also allowing users to connect through a proxy to mitigate command vulnerabilities that could disrupt gameplay. Additionally, newserv incorporates community-driven reverse-engineering efforts, making it a stable and dynamic platform for both players and developers.

TikTok-SSL-Pinning-Bypass

2026-08-18 ★ 10
TikTok-SSL-Pinning-Bypass is a tool designed to intercept network traffic from the TikTok application on Android devices without the need for rooting. It supports Android versions 6.0 and above, and has been successfully tested using Mitmproxy in a non-root environment, specifically for the arm64-v8a architecture. Notable features include the ability to bypass SSL pinning, compatibility with real Android devices and AVD emulators, and the provision of a free patched APK that resolves specific login errors.

tcpk

2026-08-18 PowerShell ★ 19
TCPK (Thick Client Pentest Kit) is a Windows-based security audit tool designed for comprehensive testing of thick-client applications, including MSIX, .NET, and Electron binaries. Noteworthy features include a PowerShell engine, live auditing with real-time findings, CVSS scoring, AI triage capabilities, and automated report generation in multiple formats, providing an exhaustive analysis for authorized testing environments. This tool emphasizes evidence-based findings and offers extensive checks, making it suitable for security professionals conducting in-depth application audits.

dexcalibur

2026-08-17 TypeScript ★ 1168
Reversense (Dexcalibur 2) is a comprehensive binary intelligence platform tailored for reverse engineering of mobile and embedded applications. It automates the analysis process through integrated static and dynamic methodologies within a unified framework, facilitating collaboration among multiple analysts. Notable features include automated scanning capabilities, device-farm compatibility, and LLM integration, enhancing user experience and operational efficiency in assessing application behavior and vulnerabilities.

Frida-libcurlUnpinning

2026-08-17 JavaScript ★ 37
Frida-libcurlUnpinning is a tool designed to bypass SSL-Pinning protections in Android applications that utilize the libcurl library. Utilizing Frida, it allows users to spawn or attach to an application, enabling the dynamic hooking of `curl_easy_setopt` to disable SSL-Pinning mechanisms. Notable features include support for both spawn and attach modes for adaptability in various use cases.

KotOR.js

2026-08-17 TypeScript ★ 141
KotOR.js is a TypeScript-based reimplementation of the Odyssey Game Engine, originally used in Star Wars: Knights of the Old Republic I & II. This project aims to fully support and replicate the original engine's features, while also offering an early modding suite called KotOR Forge. It utilizes technologies like THREE.js for rendering, Electron for desktop application packaging, and provides web compatibility for enhanced accessibility in modern browsers.

web-re-toolkit

2026-08-17 Rust ★ 38
web-re-toolkit is a reverse engineering toolkit designed to solve Akamai Bot Manager and Kasada Bot Defence protections without using a browser, leveraging a V8 sandbox. It features the capability to handle V2 and V3 sensors, along with various interrogation processes, while maintaining compatibility with real device profiles and allowing for cross-language integration across Node, Python, Go, and Rust. Notably, it utilizes the vendor's original scripts for payload calculation, ensuring robust operation against evolving web security measures.

-SKYNET-Steam-Emulator

2026-08-17 C# ★ 134
SKYNET Steam Emulator is a compatibility layer designed to replicate Steamworks functionality through a meticulous emulation of the Steam API, coupled with a robust server backend for handling various game states and user interactions. Primarily aimed at developers and testers, it offers features like local service emulation, diagnostics, and a TypeScript-based Game Coordinator for Dota 2, all while maintaining fidelity to the native Steamworks ABI. Key capabilities include a modular architecture allowing for flexible session management, achievement tracking, and peer-to-peer relay functionalities, making it suitable for controlled development and testing scenarios rather than a complete Steam replacement.

apple-continuity-tools

2026-08-17 JavaScript ★ 87
The Apple Continuity Reverse Engineering Toolkit is designed for analyzing Apple’s wireless ecosystem services, including AirDrop and Handoff, primarily for security research and vulnerability assessment. It includes various tools for monitoring processes and accessing keychain items, requiring potential modifications to macOS' System Integrity Protection for full functionality. Notable features include `process_recon` for system log scanning and `keychain_access` for monitoring keychain interactions.

codex-plus-plus

2026-08-17 JavaScript ★ 14
Codex++ is a desktop application that allows users to manage multiple ChatGPT subscriptions seamlessly within a single interface on macOS and Windows. Notable features include a user-friendly profile menu for easy account switching, shared project and skill history, and separate user data management, ensuring the original ChatGPT application remains unaltered. The tool is built on Electron and enables a streamlined integration of additional subscriptions while preserving functionality across accounts.

Galaxy-Book4-Edge-linux

2026-08-17 Python ★ 72
The Galaxy-Book4-Edge-linux repository focuses on reverse-engineering and providing Linux support for the Samsung Galaxy Book4 Edge, particularly enhancing features such as battery reporting and thermal management through the ENE KB9058 embedded controller. Notable features include the development of a custom battery driver and tools for fan control, alongside pre-built ISOs for easier setup and manual driver installations for existing Linux users. The project offers comprehensive documentation on the reverse-engineering process, making it a valuable resource for developers working with this ARM64 platform.

hik-qr-export

2026-08-17 Python ★ 27
HikVision QR Export is a tool designed to decode and renew QR code data associated with Hik-Connect applications, specifically for extracting metadata and stored device information from QR codes generated for HikVision cameras. Its notable features include the ability to read QR code images directly from the macOS clipboard and the option to recover forgotten export passwords without the need for a static encryption key. This utility is valuable for users seeking access to their camera configurations after password loss.

recurse

2026-08-17 Rust ★ 26
Recurse is a reverse engineering desktop application leveraging radare2 for binary analysis, disassembly, and optional decompilation through r2ghidra integration. Notable features include a Cursor-style workspace for efficient navigation, a live analysis session capability, and an LLM agent that enhances the reverse engineering process via interactive queries driven by an OpenAI-compatible backend. Accessible through a dark-first UI, it aims to streamline the reverse engineering experience for security professionals and researchers.

wifi-password-sharing

2026-08-17 Swift ★ 18
The "Apple Wi-Fi Password Sharing" tool provides a reverse-engineered implementation of Apple's Wi-Fi Password Sharing protocol for macOS, enabling cross-device sharing of Wi-Fi passwords via Bluetooth Low Energy (BLE). It includes functionalities for both grantor and requestor roles, allowing a device to share or request a Wi-Fi password, although it requires specific security settings and additional setups for the requestor role due to macOS restrictions. Notably, the project serves primarily educational purposes and remains experimental, with an emphasis on its untested nature and the need for additional configuration when operating on macOS.

tiktok-signature

2026-08-16 Python ★ 11
The TikTok Signature Generator is a Python tool designed to create valid signatures for TikTok Web API requests, specifically **X-Gnarly**, **X-Bogus**, and **X-Dynosaur** signatures. It features support for SDK version 5.1.2 and employs advanced encryption and hashing algorithms, including ChaCha20 and RC4, to ensure secure and dynamic signature generation. This lightweight and production-ready implementation is tailored for developers seeking to interact with the TikTok API effectively.

Blackbird

2026-08-16 C# ★ 79
Blackbird is a comprehensive real-time malware analysis platform designed for software reverse engineering and intrusion detection. Its primary use case involves performing detailed local analysis of malware through advanced features such as kernel capture, in-process telemetry, and flexible target execution workflows. Notable functionalities include memory behavior tracking, offline capture analysis, and a user-friendly interface that facilitates malware detonation and threat triage within a controlled virtual environment.

dearxan

2026-08-16 Rust ★ 55
`dearxan` is a library designed for static and runtime analysis/patching of the Arxan protection checks embedded in binaries, specifically targeting various FromSoftware games. Its primary use case is to fully neutralize Arxan's anti-debug and integrity checks, thereby allowing for unhindered gameplay and modding experiences. Notable features include a straightforward API for integration with Rust, C, and C++ applications, as well as best-effort support for DLL injectors that do not suspend processes upon creation.

fallguys-frida-modmenu

2026-08-16 TypeScript ★ 48
The Fall Guys Mod Menu is an Android tool that utilizes Frida and frida-il2cpp-bridge to provide a suite of modifications for the game Fall Guys, enhancing gameplay with features such as teleportation, speed adjustments, and visual aids in rounds. Notable functionalities include the ability to bypass character physics checks, anti-AFK measures, and various movement enhancements like air jumps and 360 dives. This tool is intended solely for educational and research purposes, carrying risks of bans or game instability.

MassAcre

2026-08-16 Python ★ 10
MassAcre is a tool designed to exploit a zero-day vulnerability in the masscan banner scanning utility, causing it to enter an infinite loop and consume 100% CPU by sending a specially crafted TLS handshake record. Its primary use case is to demonstrate a remote, unauthenticated Denial of Service (DoS) attack that stalls the banner processing of masscan, leading to lost scan results. Notably, the attack is executed with a minimal payload and targets a specific flaw in masscan's certificate handling logic.

MikuCffHelper

2026-08-16 Python ★ 42
MikuCffHelper is a Binary Ninja plugin designed to deobfuscate binaries that utilize OLLVM-style control flow flattening (CFF). It employs static analysis techniques to identify dispatcher subgraphs and simulates state variables, offering two primary deobfuscation paths: a recommendation for the 'synthesize_switch' approach that preserves the dispatcher as a switch-case structure and an alternative 'deflate_hard' method that bypasses the dispatcher entirely. The tool significantly reduces High-Level Intermediate Language (HLIL) line counts, with half of the tested functions showing a decrease of 20-59% without losing any side effects.

retrore

2026-08-16 ★ 73
RetroRE 6502 is a comprehensive repository of reverse-engineered and original source code for vintage games developed for platforms utilizing the 6502 CPU, such as the Acorn Electron, Apple II, and various arcade systems. Its primary use case is to serve as a resource for retro game developers and enthusiasts interested in game design and programming on historical systems. Notable features include the organization of games by platform and year, along with links to source code for both original and reverse-engineered projects, highlighting the state of their completeness.

altium-designer-mcp

2026-08-16 Rust ★ 36
The Altium Designer MCP is a server tool that enables AI assistants to efficiently create and manage Altium Designer component libraries, specifically `.PcbLib` and `.SchLib` files, by handling file input/output and primitive placement. This tool addresses the challenges of manually building libraries by allowing AIs to perform engineering tasks while it manages the complexities of the undocumented binary formats, supporting the creation of any component rather than just predefined packages. Notable features include compatibility with multiple AI assistants and the ability to automate footprint generation based on datasheet interpretation and design specifications.

AobscanFast

2026-08-16 C# ★ 108
AobscanFast is a high-performance, cross-platform memory pattern scanner designed for locating Array-of-Bytes (AOB) signatures in live process memory, primarily used in game modding and reverse engineering. It features SIMD acceleration for efficient scanning, parallel processing capabilities, and zero-allocation paths to optimize performance, making it suitable for both Windows and Linux environments. Additionally, it offers configurable options for chunk size and parallelism, along with a dependency injection-ready architecture for flexible integration.

Benthic

2026-08-16 C ★ 77
Benthic is a comprehensive Windows kernel rootkit designed for educational exploration and practical insights into rootkit development. It features advanced capabilities including process and network stealth, keylogging, and file hiding, all integrated into a modular framework for demonstrating real-world stealth and persistence from kernel mode. While leveraging techniques such as DKOM for process hiding and using the Windows Filtering Platform for network obfuscation, Benthic serves as a foundational resource for those venturing into the complexities of rootkit creation.

BitMono

2026-08-16 C# ★ 552
BitMono is a versatile open-source obfuscator designed for .NET and Mono applications, offering robust protections against reverse engineering. Key features include advanced string encryption, various anti-debugging techniques, and the ability to create custom obfuscators using its dependency injection framework. Notably, it provides a web-based interface for easy obfuscation, ensuring that user uploads are securely wiped after processing.

CLI-Anything-WEB

2026-08-16 Python ★ 214
CLI-Anything-Web is a tool that transforms any website into a production-ready command-line interface (CLI) by capturing its live HTTP traffic. It is primarily used for generating Python CLIs for web applications that lack public APIs, featuring capabilities such as authentication handling, a REPL mode, JSON output, and built-in tests. Designed for prototyping and automation, this tool eliminates the need for manual reverse-engineering by automatically generating CLI interactions based on live traffic data.

delink

2026-08-16 Rust ★ 13
delink is a versatile tool designed for splitting binaries in decompilation projects, supporting multiple formats such as shared objects, Mach-O, and Windows PE with associated PDBs. It features an IDA import mechanism that allows users to leverage IDA's analysis for splitting binaries without needing direct debug information, thereby enabling detailed function and relocation management. The output is customizable, accommodating usage across various architectures with a focus on both ELF and PE outputs.

MacAssistant

2026-08-16 Swift ★ 75
MacAssistant is a native macOS application designed for system maintenance and Apple binary handling, replacing scattered scripts and terminal commands with intuitive workflows. It features comprehensive system health monitoring, safe cleanup options, app repair capabilities, and a developer toolkit for managing DEB packages, DYLIBs, and Mach-O files. The tool emphasizes user confidence with preview-first actions, no telemetry, and support for macOS 13 and later.

medc17-checksum-tool

2026-08-16 Python ★ 47
The MEDC17 Checksum Tool is a specialized software designed to analyze and correct checksums for Bosch MED17 and EDC17 ECU firmware binaries, supporting CRC32, ADD32, and ADD16 algorithms. Notable features include automatic block detection, instant CRC32 solving via GF(2) matrix algebra, RSA signature forging, and calibration verification number (CVN) correction, all while ensuring safe operation by preserving original files. The tool is implemented in Python and offers both command-line and web-based usage options for convenience.

revula

2026-08-16 Python ★ 72
Revula is a production-grade MCP server designed for universal reverse engineering automation, facilitating connections between various compatible IDEs and custom tooling to an extensive reverse engineering backend through the Model Context Protocol. Its primary use case focuses on both static and dynamic analysis, featuring a robust suite of over 70 tools including binary parsing, disassembly, decompilation, and exploit development, alongside comprehensive support for Android reverse engineering and traffic interception capabilities. Additionally, Revula offers integration with numerous clients, enhanced debugging support, and a versatile configuration model, making it suitable for advanced security analysis and vulnerability research.

Zygisk-Loader

2026-08-16 C ★ 102
Zygisk-Loader is an ultra-lightweight Zygisk module developed in Pure C that facilitates the dynamic injection of external shared libraries into Android application processes. Its primary use case is to enable seamless and immediate updates of payloads without the need for device reboots, thanks to its "Hot-Swap" capability and robust memfd-based RAM injection, which ensures a zero forensic footprint. Key features include support for multiple target apps via a JSON configuration, no runtime dependencies, and compliance with the latest Zygisk API for enhanced compatibility with tools like Magisk.

docker-packing-box

2026-08-15 Python ★ 66
Packing Box is a Docker container that offers a command-line interface (CLI) environment designed for the static detection of executable packing. It integrates various executable analyzers, packing detectors, and tools for generating datasets, specifically tailored for evaluating detection techniques and automating machine learning pipelines involving packed and unpacked executables across different formats such as PE, ELF, and Mach-O. The toolkit features a user-friendly YAML configuration system, enabling straightforward customization for research evaluations and model training.

demuxusb

2026-08-15 C++ ★ 35
DeMuxUSB is a C++20 tool suite designed for capturing, demultiplexing, and analyzing USB sessions involving Apple iDevices, focusing particularly on reverse engineering recovery and restore protocols. It enables forensic analysis by allowing users to examine device restores against known baselines to identify deviations or unauthorized modifications, with features such as detailed USB transaction tracking, protocol demultiplexing, and support for various input capture formats like PCAPNG. Noteworthy capabilities also include reconstructing USB device states and extracting TCP streams and plist data, making it a valuable resource for cybersecurity analysis and digital forensics in the Apple ecosystem.

fingerprint-pro-internals

2026-08-15 JavaScript ★ 49
Fingerprint Pro Internals is a deobfuscated and documented version of the Fingerprint Pro v4 library, providing detailed insights into its 143 defined signal collectors, signal map, and wire format operations. The tool allows developers to analyze and run collectors independently without a network, enabling the examination of the library's inner workings in a browser environment. Notable features include a comprehensive signal map, individual collector source files, and the ability to explore the wire format from JSON to bytes in an organized manner.

rlapi

2026-08-15 Go ★ 54
_rlapi_ is a Go SDK that provides access to Rocket League's internal APIs through a reverse-engineered framework, enabling functionalities like authentication, item shop access, player stats retrieval, and match history. It includes capabilities for traffic interception using Frida for dynamic instrumentation and features a MITM proxy to log API requests and responses while managing authentication tokens. The library allows developers to manipulate network traffic and reconstruct HTTP and WebSocket requests, although not all API endpoints are fully documented.

awesome-touhou

2026-08-15 CSS ★ 82
Awesome Touhou is a comprehensive resource hub for the Touhou Project, a bullet hell shoot 'em up game series by ZUN, facilitating access to official resources, game tools, and community-driven enhancements. It features categories for tools related to game launching, input configuration, patching, and modding, along with gameplay tools for scoring and replays, making it an essential platform for both newcomers and seasoned players in the Touhou gaming community. Notable offerings include compatibility tools for various operating systems and community patches that enhance the gameplay experience.

dll-proxy-generator

2026-08-15 C++ ★ 153
Dll Proxy Generator is a tool designed to create a proxy DLL that intercepts calls between a game and its original DLL, allowing for the inspection and modification of DLL interactions. Its primary use case is for game developers and researchers seeking to debug or enhance game functionality through DLL manipulation. Notable features include the automatic generation of proxy DLL source code and the capability to handle specific public Windows DLLs effectively, although some limitations exist with game-specific DLLs that have mangled function names.

dsh-reverse-skill

2026-08-15 PowerShell ★ 94
dsh-reverse-skill is a comprehensive DeepSeek Harness (dsh) plugin that encapsulates 85 skills from the upstream reverse-skill repository, providing seamless integration into the dsh environment without manual maintenance of skill lists. The tool automatically registers a complete library of skills upon startup, includes both domain and CTF-oriented skills, and offers a straightforward installation process via GitHub or configuration files. It is specifically designed for authorized reverse engineering, penetration testing, and security research.

Frida-Script-Runner

2026-08-15 JavaScript ★ 373
Frida Script Runner is a web-based toolkit designed for comprehensive Android and iOS penetration testing and mobile application security analysis. It streamlines interactions with Frida through a user-friendly Flask interface and supports advanced functionalities such as AI-powered script generation, real-time output, and automated analysis with integration for Ghidra and JADX. Notable features include APK/IPA dumping, SSL detection, multi-device monitoring, and an extensive set of tools for script management and execution.

jadx-mcp-server

2026-08-14 Java ★ 29
JADX MCP Server is a pure-Java Model Context Protocol server that facilitates the reverse engineering of Android APK files utilizing the JADX decompiler. Designed for security researchers and developers, it enables detailed analysis through features such as APK loading, code decompilation, component extraction, and comprehensive manifest analysis, all while maintaining cross-platform compatibility and requiring no external dependencies.

FridaBox

2026-08-14 Java ★ 28
FridaBox is an Android mobile-security research tool that enables authorized dynamic analysis of original APKs within dedicated private virtual environments, eliminating the need for root access or modification of the APKs. Its notable features include the ability to import unmodified APKs for byte-for-byte analysis, provide multiple launch modes (on-device, computer, and clean), and load Frida Gadget at the earliest possible point in the application lifecycle, allowing for precise instrumentation without altering the application's integrity.

ai-browser-mcp

2026-08-14 HTML ★ 46
AI-Browser-MCP is a Windows-based browser automation service that leverages AI to execute predefined tasks through natural language commands. It features 255 pre-packaged tools capable of automating data collection, reverse engineering, debugging, and form filling, all orchestrated via intuitive commands without the need for scripting. The tool integrates easily with various AI agents and utilizes a local server for API communication, emphasizing privacy and ease of use.

dewolf

2026-08-14 Python ★ 235
dewolf is a research-oriented decompiler designed as a plugin for Binary Ninja, allowing users to decompile binaries into a more understandable format using its Medium-Level intermediate language. Primarily targeted at software researchers and security analysts, dewolf offers both GUI and command-line interfaces for inspecting decompiled code. Notable features include caching of decompiled code, function navigation within the GUI, and automatic decompilation toggling, though it remains a prototype with potential bugs and optimization limitations.

maskromtool

2026-08-14 C++ ★ 388
Maskromtool is a CAD tool designed for photographing mask ROMs and extracting their bit contents for recovery purposes. Its primary use case is in the analysis and decoding of ROM data, particularly for vintage microcontrollers and gaming systems. Notable features include support for handling ambiguous or damaged bits, a user-friendly GUI with keyboard shortcuts, and integration with GoodASM for assembly tasks, alongside various enhancements for efficient bit extraction and analysis.

cs16-goldsrc-client

2026-08-14 C++ ★ 18
The CS 1.6 Steam GoldSrc Client is an open-source replacement for the `client.dll` in Counter-Strike 1.6, specifically designed for the original 32-bit Steam GoldSrc engine. This experimental tool maintains the native client ABI while reviving essential features such as the original VGUI, weapon prediction, and spectator interface, offering enhanced user experience without reliance on non-native APIs. Notable features include integration with original HUD sprites, correct widescreen rendering, and support for Steam Rich Presence and Discord RPC.

dirplayer-rs

2026-08-14 Rust ★ 398
DirPlayer is a Rust-based emulator for Shockwave Player that facilitates the playback of legacy browser games in modern web environments. Its primary functionalities include a Chrome extension that auto-replaces `<embed>` elements linked to Shockwave files, a standalone application for debugging Lingo scripts, and a JavaScript polyfill for easy integration into web pages. Key features comprise a complete debugging toolset and a self-contained polyfill that includes a WebAssembly (WASM) virtual machine.

G2CC

2026-08-14 TypeScript ★ 13
G2CC is a custom operating environment designed for Even Realities G2 smart glasses, transforming them into a fully functional, PC-driven windowed computer while bypassing the limitations of the vendor's companion app. Its standout features include a comprehensive windowing system that streams various applications like email, terminal sessions, and media players directly to the glasses, leveraging a PC server for processing and rendering, ensuring enhanced privacy and customization. The architecture features a Node server for session management, while the glasses serve as a lightweight display, facilitated by an Android service for connectivity.

kasada-vm

2026-08-14 JavaScript ★ 21
The kasada-vm is a browserless tool designed for solving Kasada's fingerprinting mechanism by running a Node.js sandbox that executes the `p.js` fingerprint VM. Its primary use case is to generate valid session tokens (`x-kpsdk-ct`, `x-kpsdk-h`) from a captured fingerprint blob, while offering features such as bytecode dumping, string table cracking, and a framework to analyze and disassemble various versions of `p.js`. The tool is intended for research and educational purposes, emphasizing the need for compliance with Kasada's terms of use.

alive_reversing

2026-08-14 C++ ★ 430
R.E.L.I.V.E. is an open-source engine replacement for Oddworld: Abe's Oddysee and Oddworld: Abe's Exoddus, designed to fix bugs and enhance the original gameplay experience. It aims to provide a modding and level creation interface, allowing users to study and modify the engine for new projects. Notable features include quick save/load functions and customizable display options such as aspect ratio and fullscreen toggling.

GlyphDbg

2026-08-14 C ★ 17
GlyphDbg is a deterministic introspection engine designed for remote analysis of processes and memory, offering deep insights into the Windows NT environment without traditional debugging APIs. Notable features include advanced memory and pointer introspection, remote PE reconstruction for malware analysis, symbolic command interfaces, and a stealth execution engine to avoid detection. It emphasizes a raw, low-level approach to analysis, treating system components as integral narratives rather than mere metadata, and enables extensibility through custom DLL integration.

hudhook

2026-08-14 Rust ★ 355
Hudhook is a Rust-based rendering hook library designed for creating overlays with Dear ImGui, supporting rendering through DirectX 9, 11, 12, and OpenGL 3 on Windows and Wine/Proton. Its notable features include seamless integration for various graphics APIs, extensive documentation, and easy implementation through customizable render loops. The tool is particularly useful for developers looking to add interactive graphical interfaces to existing applications.

hxy

2026-08-14 Rust ★ 26
hxy is a hex editor developed in Rust that operates on both desktop and web platforms, utilizing the egui framework for its user interface. Its main use case is to provide a comprehensive tool for editing and inspecting binary data, featuring a file-backed hex view, data inspector, and support for various archive formats with a VFS browser. Notable functionalities include an integrated 010 Editor Binary Template runtime, ImHex pattern support, and IPC capabilities for opening files through the command line.

openqore

2026-08-14 Python ★ 33
OpenQore is an open-source toolkit designed for patching, modifying, and enhancing the firmware of Soundcore Q-series headphones, with plans to extend support to additional models. The project encompasses a patcher for the stock firmware and an SDK tailored for headphones utilizing the bes2300p SoC, featuring functionalities such as unlocking audio support and implementing customizable firmware patches. It is a work in progress, reflecting a personal learning journey in hardware reverse-engineering and embedded systems, with community contributions encouraged.

SonyBridge

2026-08-14 C++ ★ 32
SonyBridge is an open-source desktop application designed for managing various functionalities of Sony headphones, including noise cancelling, ambient sound control, equalization, and battery monitoring, without the need for a mobile device. This tool leverages a reverse-engineered protocol to support both first and second-generation Sony headphone models, offering features like real-time battery status, adaptive sound management, and a modern UI across macOS, Windows, and Linux platforms. Notable capabilities include codec information retrieval, live button sync, and a high degree of customization in audio settings.

Flutter-Reverse-Engineering-Labs

2026-08-14 Dart ★ 58
The Flutter Reverse Engineering Labs repository offers a series of progressive challenges aimed at teaching the techniques involved in reverse engineering Flutter applications. It includes hands-on tasks that lead users from basic concepts to more advanced practices such as network traffic interception and integrity check bypassing, with each challenge accompanied by detailed, step-by-step solutions. Notable features include the provision of compiled APKs for challenges, practical source code examples, and integration with commonly used tools like Frida and APKTool for a comprehensive learning experience.

reverse-engineering-agent

2026-08-13 Python ★ 10
Reverse Engineering Agent is an autonomous system designed to analyze and reverse engineer binary challenges using both static and dynamic analysis techniques. It features a multi-agent architecture for executing tasks and self-correcting mechanisms to refine the analysis process, along with support for various large language model providers for enhanced reasoning capabilities. The tool integrates GDB for dynamic program inspection and utilizes `pexpect` for interactive binary analysis, making it suitable for effectively tackling complex crackme challenges.

metaai-api

2026-08-13 Python ★ 92
metaai-api is an unofficial Python SDK and API server designed to interact with Meta AI, enabling users to generate images from text prompts, engage in chat conversations using Llama, and manage their interactions. This tool leverages cookie-based authentication, eliminating the need for API keys, and incorporates browser automation for image generation and prompt submissions, while also providing REST API server capabilities for broader integration. Notable features include support for multiple chat modes, media fetching by card ID, and a straightforward setup process.

pokepuzzle

2026-08-13 Assembly ★ 77
Pokémon Puzzle Challenge is a disassembly project for the Game Boy Color game, allowing users to modify and reassemble the original ROM using RGBDS. The primary use case is to facilitate the analysis and development of custom patches, while notable features include a straightforward build process and the integration of community support through Discord. The repository provides essential files for assembly, including the original ROM requirement and a specified patch for customization.

th105

2026-08-13 C++ ★ 74
The TH105 project is a reverse engineering initiative aimed at reconstructing the source code of the Japanese game "東方緋想天 ~ Scarlet Weather Rhapsody" version 1.06a, with a focus on achieving reproducible binary comparisons. The tool utilizes Ghidra and IDA Pro for semantic analysis, and incorporates a structured workflow that emphasizes exact matching and function byte comparisons, ensuring the integrity of the reconstructed code. Notable features include the generation of a machine-readable function ledger and project-scoped tools for streamlined analysis and verification.

binsync

2026-08-13 Python ★ 745
BinSync is a collaborative decompiler tool that integrates with Git to facilitate fine-grained reverse engineering across multiple decompilers, enabling users to share and synchronize Reverse Engineering Artifacts (REAs) such as function headers, stack variables, structs, enums, and comments. Notable features include support for multiple decompilers, installation via Python, and enhanced functionalities for chat and artifact syncing, tailored for environments like IDA Pro, Binary Ninja, angr-management, and Ghidra. The tool's design fosters seamless collaboration among reverse engineers, making it easier to maintain consistency in shared analysis.

bitwig-nitro-tools

2026-08-13 Python ★ 22
Bitwig Nitro Tools is an offline reverse-engineering toolchain specifically designed for the Nitro DSP format used in Bitwig Studio. It facilitates the decryption, decompilation, parsing, editing, and re-serialization of native devices and Grid modules, allowing users to comprehensively analyze and modify the digital signal processing behind each module. Key features include the ability to extract keys from the user's Bitwig installation, decompile modules into readable pseudo-source format, and repack modified modules without altering their byte structure, ensuring a seamless editing experience.

claude-code

2026-08-13 TypeScript ★ 26
Claude Code Source is a reverse-engineered TypeScript repository of the `@anthropic-ai/claude-code` CLI tool, designed for educational and security research purposes. It deobfuscates and restores the original module structure, enabling exploration of an advanced AI coding agent's internal workings, including features such as file editing, web fetching, and integration with various tools. The repo is strictly for learning and does not support redistribution or bypassing the official tool.

game-patches

2026-08-13 Python ★ 600
Game patches for the Xenia emulator

LTSDM_hack

2026-08-13 Python ★ 34
The LTSDM hack repository provides a framework for reverse engineering the Little Tikes Story Dream Machine cartridges, enabling users to create custom stories through extensive cartridge data analysis and extraction techniques. Key features include cartridge dumping workflows, audio pipeline experiments, and detailed hardware documentation to facilitate the modification process. This project is currently a work in progress aimed at legal modding and educational use only.

McAFuse

2026-08-13 Python ★ 19
McAFuse is an open-source utility designed for the Digital Forensics and Incident Response (DFIR) community to handle encrypted disk images created with the McAfee Full Disk Encryption (FDE) toolset. The tool provides a static read-only FUSE filesystem, allowing users to access both a plain FAT partition and the encrypted disk image, facilitating the analysis of encrypted data during digital investigations. Notable features include the ability to specify a keyfile for decryption, options for verbose output, and functionality to expose all disk contents beyond just the encrypted volumes.

Persona4-Decompilation

2026-08-13 Assembly ★ 15
The Persona4-Decompilation tool is a project designed to achieve a byte-for-byte decompilation of the PlayStation 2 game Shin Megami Tensei: Persona 4, specifically the USA version 1.00 (SLUS_217.82). Its primary use case is to reconstruct the game's source code and executable image using various tools and setups, while providing extensive metrics on decompiled functions, recovery quality, and build processes, ensuring a high fidelity to the original codebase. Notable features include support for detailed testing and verification, as well as the capability to manage dependencies and configurations for a successful build environment.

ps1-recomp

2026-08-13 C++ ★ 10
PS1Recomp is a static recompilation tool that transforms PlayStation 1 game binaries from MIPS R3000A machine code into native C++ executables for PC, enabling them to run at full CPU speed without runtime interpretation. Its architecture includes a dedicated analyzer for game binary parsing, a recompilation component that accurately emits C++ code, and a full hardware simulation runtime facilitating various PlayStation functionalities. Notable features include a GUI studio for exploring and editing configurations, comprehensive unit tests, and support for hardware simulation via SDL2 and OpenGL, promoting both performance and ease of use in game development and emulation.

th07

2026-08-13 C++ ★ 28
The th07 project focuses on the reverse engineering and reconstruction of the original Japanese executable for `東方妖々夢 ~ Perfect Cherry Blossom` version 1.00b. Its primary use case is to achieve reproducible binary comparisons through an extensive function-by-function analysis, employing tools like IDA Pro for semantic analysis. Notable features include a structured workflow integrating knowledge from related projects, strict validation gates for function verification, and a comprehensive inventory and progress tracking system.

th08

2026-08-13 C++ ★ 129
The th08 project is focused on reverse-engineering and reconstructing the source code of the original Japanese game "東方永夜抄 ~ Imperishable Night" (version 1.00d). Its primary use case allows for reproducible binary comparisons against the original executable, while facilitating the build process in multi-platform environments. Notable features include a detailed analysis workflow, dependency management, and documentation of progress and architecture, with components built upon contributions from previous related projects.

melitta-barista-ha

2026-08-12 Python ★ 12
The Melitta Barista & Nivona for Home Assistant is a custom integration that enables the control of Melitta Barista T/TS Smart and various Nivona coffee machines via Bluetooth Low Energy (BLE) within the Home Assistant ecosystem. It allows users to monitor machine status, manage brewing recipes, adjust settings, and perform maintenance tasks through a unified dashboard, with additional features like an AI Coffee Sommelier for recipe generation accessible via conversation agents. The tool supports multiple languages and is designed to streamline the coffee-making experience through automation and integration with smart home setups.

Mira

2026-08-12 C ★ 100
Mira is a mobile runtime detection workbench designed for iOS and Android, facilitating the analysis of real-time runtime conditions through reusable workflows and detection knowledge. Notable features include real app sandbox access, live logic execution capabilities, and fast setup for immediate results, enabling users to inspect and navigate app runtimes efficiently for enhanced security analysis. The tool integrates AI capabilities, allowing for a hands-on approach to runtime analysis and compounding detection intelligence from real findings.

Noctyra

2026-08-12 Python ★ 17
Noctyra is an AST-based Python framework for code transformation and deobfuscation, offering a modular pipeline that simplifies complex expressions and logic in Python source code. Key features include the ability to resolve static values, unroll dynamic execution blocks, and optimize obfuscated constructs through a sequence of pluggable transformers. Designed for flexibility, it facilitates the analysis and processing of Python code while emphasizing the importance of running untrusted code in isolated environments for security.

apihash_to_yara

2026-08-12 YARA ★ 17
apihash_to_yara is a tool designed to generate YARA signatures based on Windows API hashes, facilitating malware detection and hunting through obscured imports. It allows users to extract API exports from DLLs and creates YARA rules with customizable thresholds for various hash variants, making it particularly useful against malware that utilizes API hashing techniques to evade detection. Notable features include support for custom API lists and the generation of multiple hash variants to enhance detection capabilities in malware analysis workflows.

room-server

2026-08-12 Python ★ 37
room-server is a server implementation designed to facilitate connectivity for the Wii no Ma platform. It primarily serves as a backend solution for users seeking to self-host the service, enabling enhanced multiplayer interaction and community features. Notable features include flexible self-hosting options and an open contribution policy that promotes collaborative development.

Telkin

2026-08-12 C++ ★ 11
A dynamic Wii U mod loader.

AIDebug

2026-08-12 Python ★ 10
AIDebug is a command-line interface and terminal UI tool designed for malware reverse engineering, emphasizing evidence collection and analysis. Its primary use case involves deterministic offline triage of PE and ELF files, whole-file hex inspection, and in-depth structure analysis with features such as Ghidra-backed reconstruction and local ELF debugging, while also offering optional integration with large language models for enhanced review capabilities. Notable functionalities include paged hex viewing, customizable output formats for analyst reviews, and a robust history tracking system for SHA-256 indexed analyses.

ALPC-Enumerator

2026-08-12 C++ ★ 23
ALPC Enumerator is a Windows userland tool designed to enumerate and classify Advanced Local Procedure Call (ALPC) ports, including those associated with Protected Process Light (PPL) processes that evade standard enumeration techniques. It dynamically resolves ALPC Port types and employs `NtQueryInformationProcess` for classification, addressing blind spots in conventional tools, thereby benefiting threat hunters and vulnerability researchers by accurately mapping high-privilege targets and identifying potentially malicious activity. Notably, it has been validated against kernel debugger output for precision and reliability.

blackbox-re-agent

2026-08-12 Python ★ 35
Revagent is a black-box program analysis agent that leverages natural language processing to automate reverse engineering tasks across various file formats, including APKs, firmware, and executable binaries. Users can query the agent directly for insights, bypassing manual command inputs, while it dynamically assembles the necessary tools for tasks like unpacking, disassembly, and reporting findings. Notable features include support for Android and automotive firmware analysis, as well as a unified interface for interacting with different artifact types through a single command.

CanLab

2026-08-12 Python ★ 79
CanLab is a comprehensive reverse-engineering workstation for CAN bus data, designed to facilitate the analysis, diagnostics, and modification of automotive communication protocols. It features a user-friendly PyQt6 interface that supports loading and inspecting CAN frames, running offline analyses, and utilizing AI assistance for interpreting IDs. Notable capabilities include DBC building and export, diagnostic protocol support, signal injection and fuzzing, as well as built-in safety mechanisms to prevent accidental misuse in live vehicle environments.

CoBRA

2026-08-12 C++ ★ 328
CoBRA is a Mixed Boolean-Arithmetic expression simplifier designed to deobfuscate complex arithmetic expressions that interleave arithmetic, bitwise, and shift operators, often used in software obfuscation. It employs a worklist-based orchestrator and features various techniques such as signature-based analysis, semilinear processing, and decomposition to simplify expressions efficiently. Notable functionalities include verification via spot-checking or Z3 proofs and the ability to handle weighted sums of bitwise atoms, making it a robust tool for analyzing obfuscated code.

CoD4-DM1

2026-08-12 C++ ★ 28
CoD4 DM1 is a tool designed for the reverse engineering of CoD4 and CoD4X `.DM_1` demo files, facilitating the parsing of snapshot information, gamestate, frames, entities, clients, and server messages. Notable features include support for CoD4 & CoD4X protocols, Huffman coding for CoD4 and Q3, and a demo reader API, enabling extensive analysis of game data. The tool is accessible as a command-line interface and a library, and is available for integration via vcpkg.

deepspider

2026-08-12 JavaScript ★ 19
DeepSpider is an AI-driven reverse engineering platform designed for JavaScript, enabling users to analyze encrypted links and reconstruct algorithms based on actual request evidence. It integrates OpenCode Agent, Patchright browser, and Chrome DevTools Protocol to provide a comprehensive environment for real-time analysis, effortless debugging, and the generation of runnable scraping code, while ensuring validation through multi-sample comparisons. Its notable features include progressive analysis of obfuscated code, direct browser interactions, a structured eight-stage workflow for reverse engineering, and support for seamless transitions between browser and standalone environments.

IzEngine

2026-08-12 C++ ★ 13
IzEngine is a cross-platform engine framework designed for creating modded game clients with flexibility and adaptability across various platforms and backends. It features a robust plugin system enabling dynamic module reloading at runtime and incorporates a just-in-time assembler for efficient code generation. This makes IzEngine particularly suitable for developers looking to enhance the gameplay experience through custom modifications.

project-igi-research-data

2026-08-12 Assembly ★ 26
IGI-Research-Data is a comprehensive repository that houses extensive research information and data pertaining to the Project I.G.I game, serving as a resource for educational purposes. It includes various data sections encompassing AI behaviors, game graphs, a detailed cheat engine table, and a multitude of structural analyses of game files, memory, and coding practices. Notable features comprise custom-built tools for compiling game binaries, visualizing graphs, and analyzing game natives, enhancing both research and exploration of the game's intricate systems.

sighook

2026-08-12 Rust ★ 43
Sighook is a runtime patching library primarily designed for low-level software experimentation, reverse engineering, and custom instrumentation workflows. It enables instruction-level manipulation through features such as inline detours, byte patching, and callback mechanisms for capturing execution at specified instructions. Notable capabilities include support for multiple architectures (x86_64 and aarch64), and functions for instrumenting calls, restoring original bytes, and handling function-entry hooks, making it adaptable for diverse use cases across different platforms.

unleash

2026-08-12 Go ★ 63
Unleash is a comprehensive operator toolkit designed for managing local coding agents, providing functionalities for installation discovery, in-place binary patching, and configuration of operator authorization. It ensures the integrity and performance of tools like Claude Code and OpenAI Codex through features such as multi-install awareness, update survival mechanisms, and a robust safety model that includes timestamped backups and verification processes. With a flexible architecture that supports various platforms, Unleash enhances the operational capabilities of coding agents while safeguarding against disruptions during updates.

UtechSmart-Venus-Pro-Linux-MMO-Mouse-Utility

2026-08-12 Python ★ 20
The UtechSmart Venus Pro Config utility is a reverse-engineered configuration tool for the UtechSmart Venus Pro MMO gaming mouse, specifically designed for Linux users. It allows for comprehensive device configuration, including button remapping, macro management, DPI adjustment, and RGB lighting customization, all without the need for Windows software. Notable features include a macro engine, battery monitoring, and a user-friendly interface that adapts to connected devices, ensuring effective management of mouse functionalities.

zerokey

2026-08-12 JavaScript ★ 14
ZeroKey is a self-hosted, OpenAI-compatible local AI proxy designed for interfacing with models like DeepSeek, Claude, and ChatGPT using personal credentials. It supports IDE integration, session persistence, and a range of built-in tools for enhanced functionality, allowing users to utilize AI capabilities directly from their development environments. Notable features include streaming responses, multi-IDE selection, and in-memory session tracking with support for custom tool calls.

macos-re

2026-08-11 Python ★ 16
MacRE is a suite of scripts and tools designed for reversing macOS applications, focusing on security analysis and malware investigation. Notable features include the App Security Passport for extracting and simplifying macOS app metadata, MachoEntropy for detecting packed or encrypted Mach-O sections, and various analysis scripts for malware datasets. This toolkit facilitates security assessments and research on macOS applications through effective data extraction and entropy analysis.

myslt-alerts

2026-08-11 JavaScript ★ 15
myslt-alerts is a lightweight Node.js tool designed to monitor Sri Lanka Telecom broadband usage and send threshold-based notifications without relying on external dependencies. It automatically logs into the MySLT backend to track data consumption, alerting users via a designated channel when their remaining data reaches specified limits. Key features include configurable alert thresholds, execution via GitHub Actions for seamless setup without the need for a personal server, and the ability to receive immediate usage snapshots on demand.

skoolkit-game-revs

2026-08-11 HTML ★ 15
Skoolkit-game-revs is a repository focused on reverse engineering classic video games, primarily for platforms like the ZX Spectrum and TI-83 Plus, utilizing the SkoolKit framework. It features multiple projects for various games, providing insights, code instruction analysis, and ongoing development status with detailed resources for each game. Notable features include extensive documentation and linked follow-up projects for users interested in further exploration of game code.

apk-info

2026-08-11 Rust ★ 136
apk-info is a comprehensive tool for parsing Android APK files, designed primarily for analyzing and extracting information regarding APK contents and signatures. Its notable features include support for multiple APK signature schemes, excellent extraction capabilities for Android Binary XML and resources, and user-friendly command-line and Python bindings for easy integration into workflows. The tool also enhances malware analysis with its specialized extraction functionalities and provides accurate identification of the main activity in Android applications.

GameTracking-SteamVR

2026-08-11 JavaScript ★ 25
GameTracking-SteamVR is a tool designed for tracking and monitoring games played in SteamVR. Its primary use case is to automate the tracking process, providing users with an organized overview of their gaming activities without manual input. Notable features include integration with the main GameTracking repository and a supportive community through Discord.

idaxex

2026-08-11 C++ ★ 213
idaxex is a native loader plugin for IDA Pro 9.4 that facilitates the loading of Xbox 360 XEX and XBE executables, enhancing reverse engineering capabilities for these formats. It provides extensive support for various Xbox executable versions, handles both compressed and uncompressed images, and automatically names known imports, improving analysis efficiency. Notable features include AES-NI support for faster loading, integration of exception handling information, and the ability to apply patches directly back to input files.

OpenScope-2C53T

2026-08-11 C ★ 102
OpenScope 2C53T is an open-source firmware developed as a replacement for the FNIRSI 2C53T handheld oscilloscope, multimeter, and signal generator, addressing limitations and bugs in the stock firmware through a clean-room rewrite. Its primary use case includes providing a customizable interface and various diagnostic tools for signal analysis, although it currently lacks live oscilloscope functionality due to unresolved FPGA configuration issues. Notable features include a four-mode UI, variable bitmap fonts, a robust battery management system, and various analysis algorithms, while emphasis is placed on ongoing development for reliable live data capture.

RatDecomp

2026-08-11 C++ ★ 31
RatDecomp is a decompilation tool for the Ratatouille game, targeted primarily at developers and modders who require insight into the game's code structure. The tool allows users to compile and modify the game's source code without containing any game assets, requiring a legitimate copy of the game for usage. Notable features include support for various game versions, a build system via Python and Ninja, and an object diffing capability for tracking changes in the code during development.

SchemaCrawler-AI

2026-08-11 Java ★ 11
Free database schema discovery and comprehension tool

unlimited-ticktick-windows

2026-08-11 C# ★ 811
Unlimited TickTick for Windows is a patching tool that modifies the original TickTick application to unlock pro features such as unlimited habits, calendar views, and customizable themes. Users can replace the original executable with a patched version to maintain premium capabilities after updates, ensuring continuous access to enhanced functionalities. The tool also supports cloud-based builds via GitHub Actions, allowing users to compile their version of the patched executable without a local development environment.

usbsnoop

2026-08-11 JavaScript ★ 85
usbsnoop is a real-time USB traffic sniffer that provides a colorized, compact feed of USB transactions system-wide, utilizing fentry hooks for universal compatibility across various host-controller drivers. Its primary use cases include reverse-engineering USB peripherals, debugging drivers, inspecting mass-storage commands, and capturing errors, with features such as decoded SETUP packets, latency measurements, and JSON output for offline analysis. The tool operates without the need for hardware sniffers or traditional monitoring setups, allowing instantaneous observation and analysis of USB device communications.

wii-ipl

2026-08-11 C ★ 190
The Wii IPL repository is a work-in-progress project focused on the decompilation of the Wii Menu version 4.3 across multiple regions (USA, Europe, Japan, and Korea). It provides detailed progress tracking for each version, including metrics for decompiled code and functions, though it does not contain any executable assets. This tool is primarily aimed at developers interested in understanding the Wii Menu's implementation for educational or development purposes.

willplus-jig

2026-08-11 TypeScript ★ 10
WillPlus-Jig is a tool designed for exploring and manipulating older WillPlus ADV games prior to the AdvHD version. It leverages Frida, a dynamic instrumentation toolkit, to provide various functions for flag manipulation, script execution, and game state modifications directly from a REPL or as an RPC agent. Notable features include the ability to peek and poke flag banks, register and manipulate in-memory scripts, and save/load game states, which facilitate extensive game modifications and debugging.

xbox-controller-driver-macos

2026-08-11 C ★ 22
The Xbox One Controller Driver for macOS is a userspace driver that translates Xbox One controller inputs into keyboard and mouse events, functioning system-wide across applications. Notable features include customizable button mappings, a menu bar application for connection status, automatic reconnection capabilities, and a JSON configuration with hot-reloading support. The driver utilizes libusb for communication with the controller and injects events through the macOS Accessibility API, adhering to limitations that prevent it from simulating a virtual gamepad.

awesome-cybersecurity-books

2026-08-11 ★ 42
This repository offers a curated collection of over 70 free cybersecurity books organized by domain and difficulty, facilitating self-paced learning in various cybersecurity disciplines. Notable features include a structured learning roadmap progressing from beginner to advanced levels, an emphasis on community maintenance for up-to-date resources, and a direct link to an extensive Google Drive library containing the materials.

opendw

2026-08-10 C++ ★ 10
OpenDW is an open-source reimplementation of the online game Deepworld, originally designed for MacOS and iOS. Its primary use case is to allow users to build and run the game on different platforms using the Axmol Engine, although it does not aim for 100% accuracy compared to the original due to engine and platform differences. Notable features include compatibility with a separate server, build instructions for Windows, and a customizable asset framework, requiring users to provide their own game assets.

octabam

2026-08-10 Assembly ★ 25
Octabam is a tool designed for creating custom digital signal processing (DSP) effects for the Elektron Octatrack MKII, allowing users to replace stock effects with original assembly-coded algorithms. The primary use case revolves around enabling a shared mixing bus for effects, allowing multiple tracks to feed into a single reverb and delay, features that were previously unavailable in the stock firmware. Notable capabilities include the ChonVerb, a versatile reverb effect with multiple modes and modulated taps, as well as the potential for a delay that interfaces with the reverb, all while providing comprehensive build and testing tools to ensure reliability without risking hardware integrity.

Academia-Tehnica-Militara

2026-08-10 ★ 20
Acest repository oferă un curs amplu despre analiza malware-ului, combinând concepte teoretice și metode practice pentru investigarea și contracararea amenințărilor informatice. Structurat în module, cursul acoperă subiecte precum tipologiile malware-ului, ingineria inversă, tehnici de detecție și analize comportamentale, dotând participanții cu abilitățile necesare pentru a înțelege și a combate atacurile cibernetice. Notabilele sale caracteristici includ discuții despre criptografie, tehnici avansate de analiză, utilizarea instrumentelor specializate și o privire detaliată asupra strategiilor de infecție și persistență.

anya

2026-08-10 Rust ★ 11
Anya is a fast, offline static malware analysis platform that processes a wide variety of file formats, including PE, ELF, PDF, and Office documents, without executing them. Key features include high-speed analysis of over 250 files per minute, detailed output such as hashes, entropy, and risk scores, while offering integration with MITRE ATT&CK mappings and support for both GUI and CLI interfaces across multiple operating systems. It should be noted that Anya is transitioning its development to the MalChela project for future enhancements.

Auto-Android-App-Modding-Tool

2026-08-10 Python ★ 18
UAMT (Ultimate Auto Android App Modding Toolkit) is a Termux-based toolkit for modifying Android APKs without requiring root access. Its primary use case includes injecting Frida Gadget and custom native libraries, alongside features such as a full APK rebuild pipeline, smart detection of injection methods, and an interactive TUI for user-friendly operation. Notable functionalities include automatic dependency management, safe modding practices, and optimized performance for Android security research and reverse engineering tasks.

dotscope

2026-08-10 Rust ★ 25
dotscope is a high-performance, cross-platform framework designed for the analysis, reverse engineering, and modification of .NET PE executables, implemented in pure Rust. It offers features such as efficient memory access, comprehensive metadata analysis, assembly modification capabilities, and a full bytecode interpreter, allowing users to manipulate CIL bytecode and structure without dependence on Windows or the .NET runtime. Additionally, it incorporates advanced functionalities like deobfuscation and static analysis, making it a versatile tool for .NET developers and security researchers.

GM2Godot

2026-08-10 Python ★ 29
GM2Godot is a conversion tool designed to facilitate the migration of GameMaker LTS 2026 source projects to Godot 4.7.1, utilizing both a graphical user interface and a headless command line interface. Key features include GML transpilation into GDScript, comprehensive diagnostics and compatibility reporting, and support for multiple platform settings, along with a robust asset conversion process for various GameMaker resources. The tool also incorporates customizable conversion options and detailed validation processes, ensuring a reliable transition while preserving project integrity.

niimbluelib

2026-08-10 TypeScript ★ 137
NiimBlueLib is an open-source library designed for communicating with NIIMBOT printers, providing an accurate implementation of the associated protocol. Primarily used within the NiimBlue project, it is currently in an Alpha state, meaning the API is subject to change and should be used in exact versions. Noteworthy features include seamless integration via NPM and CDN, as well as support for CLI use cases through related packages.

openswx

2026-08-10 C++ ★ 14
Openswx is a cross-platform toolkit designed to read SolidWorks files (.SLDPRT, .SLDASM, .SLDDRW) without requiring a SolidWorks installation or any Windows dependencies. It features a C++20 library for file parsing and BOM (Bill of Materials) generation, alongside an HTTP server and CLI tools for metadata browsing and JSON output, making it suitable for applications needing SolidWorks data access in non-Windows environments. Notable features include comprehensive document property extraction, component path resolution, and a user-friendly web interface for metadata interaction.

rfvp

2026-08-10 Rust ★ 130
rfvp is a non-official Rust-based cross-platform implementation of the FVP engine and IDE, enabling users to run and debug games while also functioning as an operating system with UEFI support. Notable features include the ability to use custom fonts, support for different text encodings for translated games, and platform-specific installation guides across major operating systems. Additionally, rfvp offers a debug HUD and the potential to develop applications based on the engine, thus enhancing its versatility.

sba

2026-08-10 C++ ★ 49
SBA (Scalable Binary Analysis Framework) is a comprehensive binary analysis tool designed to perform high-fidelity static analysis on ELF, PE, and Mach-O executable formats through a robust, architecture-agnostic disassembler. Its notable features include a ControlFlowGraphAPI for diverse graph construction, an efficient AnalysisAPI incorporating forward and backward dataflow analysis, and a pre-disassembly method that processes raw binary data efficiently, allowing for scalable analysis without the limitations of traditional disassembly. The framework's applications encompass advanced jump table analysis and function property checks, enhancing the robustness and accuracy of binary analysis tasks.

sleigh

2026-08-10 CMake ★ 191
The Sleigh library is a specialized tool for defining the semantics of instruction sets of general-purpose microprocessors, primarily used in the reverse engineering of compiled software. It serves as a component of the Ghidra reverse engineering platform, facilitating disassembly and decompilation processes. Notable features include a CMake-based build system for standalone usage, support for multiple operating systems, and an included example tool (`sleigh-lift`) for disassembling bytecode or lifting it to p-code.

SAMP-Mobile

2026-08-09 ★ 95
SAMP Mobile provides source code for an Android client that enables users to interact with SA-MP (San Andreas Multiplayer) tailored for Grand Theft Auto: San Andreas. The tool features support for both ARM32 and ARM64 architectures, with notable integrations like Gloss for version 2.11 and ShadowHook for version 2.10, catering to different user needs and ensuring optimized performance on mobile devices. This repository serves primarily for educational and research purposes, allowing developers to explore and modify multi-platform client functionalities.

CDMW-Full

2026-08-09 Python ★ 12
Crimson Desert Mod Workbench (CDMW) is a comprehensive Windows desktop application designed for modding the game **Crimson Desert**. It allows users to browse and extract game archives, preview and edit meshes using a native D3D11 renderer, author DDS textures, and create material and mesh replacement packages, all while providing extensive controls and tools for texture editing and model manipulation. Notable features include an Archive Browser with filtering and preview options, a Mesh Editor with advanced selection and editing tools, and various workflows for texture manipulation.

hexerator

2026-08-09 Rust ★ 369
Hexerator is a versatile GUI hex editor for Linux designed for binary file exploration and pattern recognition. It leverages the latest nightly Rust features for enhanced functionality while encouraging contributions that optimize code without compromising performance or maintainability. The tool is particularly suited for developers and researchers who require advanced capabilities in analyzing binary data.

inform-inspect

2026-08-09 Go ★ 15
inform-inspect is a tool designed for inspecting and debugging Ubiquiti Unifi Inform packets, which is essential for analyzing communication with Unifi SDN Controllers. Its notable features include support for both AES-128-CBC and AES-128-GCM encryption methods, a two-step decoding process for raw byte streams, and the ability to output decoded data in JSON format or as a hexdump. The tool requires access to incoming inform packets and the respective encryption keys stored in the controller’s MongoDB for effective analysis.

ubi-gs

2026-08-09 Python ★ 14
The Ubisoft Game Service (GS) is a software development kit that facilitated online features such as user authentication, matchmaking, in-game chat, and CD key validation for Ubisoft games released between 2000 and 2005. It integrates with a dedicated network protocol for game server communication and includes components for both web service operations and specific game server implementations, exemplified by its integration with 'Heroes of Might and Magic V'. Notably, the project comes with a structured directory for common services, game-specific implementations, and testing scripts, requiring Python 3.11 or higher for execution.

agile-net-devirtualizer

2026-08-09 C# ★ 30
AgileDevirtualizer is a specialized tool designed to reverse the method virtualization applied by Agile.NET, converting virtualized bytecode back into standard CIL format without relying on hardcoded opcode tables. Its primary use case is for security research, allowing analysts to recover the original method bodies from protected assemblies by interpreting the unique opcode mappings generated per build. Notable features include runtime analysis of the method's virtualized logic, structural identification of handler types, and a comprehensive process of control-flow graph generation and dead-code elimination, making it robust against variations in Agile.NET's protection mechanisms.

DexFile

2026-08-09 Java ★ 33
DexFile is a library designed for the manipulation of DEX files, enabling users to read, generate, modify, and write these files, which are crucial for Android applications. Key features include support for multiple DEX versions up to 041, the ability to handle ODEX files, and the implementation of advanced instruction sets like expanded jumbo opcodes. This library aims to provide comprehensive functionality for developers working with DEX files in Java applications.

knife

2026-08-09 Rust ★ 39
Knife is a comprehensive binary analysis tool designed for reverse engineers, enabling static examination of PE, ELF, and Mach-O file formats without execution. It consolidates multiple analysis functions—such as header parsing, IOCs extraction, and disassembly—into a single command, while providing detailed triage reports on exploit mitigations and dangerous API calls. Key features include a variety of commands for deep analysis, an interactive TUI mode, and extensive output options tailored for vulnerability research and malware analysis.

letshackit

2026-08-09 HTML ★ 11
Let's Hack It is a web-based tool designed for penetration testing and ethical hacking. Its primary use case is to facilitate security assessments of web applications by identifying vulnerabilities. Notable features include a user-friendly interface and integration with various penetration testing methodologies.

MegaDownloader-Revival

2026-08-09 Visual Basic .NET ★ 25
MegaDownloader is a download manager for MEGA cloud storage, designed to function seamlessly with the newer MEGA link formats. Its notable features include multi-threaded downloading, path security mechanisms to prevent directory traversal attacks, and comprehensive download integrity checks. Updated versions enhance usability with theme switching and various security improvements, ensuring both performance and safety during file retrieval.

MK7-Memory

2026-08-09 C++ ★ 20
MK7-Memory is a collection of data structures specifically designed for reverse engineering Mario Kart 7. It streamlines the process of generating these data structures from template files using a specialized syntax, facilitating easier modifications and enhancements by developers. Key features include automated header file generation and compatibility with C++23 for project integration.

RB3Enhanced

2026-08-09 C ★ 90
RB3Enhanced is a mod for Rock Band 3 designed to enhance the user experience by adding features, fixing bugs, and increasing song storage capacity to 8000 songs, specifically for modified Xbox 360 and Wii consoles. Notable features include support for custom songs, multiplayer functionality without Xbox Live, additional game modifiers, and integration with other platforms like Rock Band 3 Deluxe and GoCentral. This tool aims to provide a more customizable and expansive gameplay environment for Rock Band 3 enthusiasts.

re-docs

2026-08-09 Python ★ 582
The repository provides comprehensive guidance on setting up environments for security researchers across multiple operating systems, including macOS, Windows, Ubuntu, and Fedora. It also offers detailed analyses of Lua program reverse engineering, covering topics such as Luac file format, bytecode disassembly, and developing IDA Pro loaders and processors for Luac. Notably, it serves as a practical resource for those looking to enhance their skills in reverse engineering Lua applications.

revkit

2026-08-09 Python ★ 13
Revkit is a comprehensive reverse-engineering toolkit designed for analyzing and modifying iOS and Android applications. It facilitates iOS tweak development through Theos/Orion, enables dynamic instrumentation with Frida, and incorporates HTTP traffic interception using mitmproxy, alongside binary analysis tools like Ghidra and radare2. Its modular structure supports a variety of scripting and disassembly functionalities, making it suitable for both dynamic and static analysis of mobile apps.

SiriRemoteForge

2026-08-09 Swift ★ 44
SiriRemoteForge is a macOS application that transforms the Apple TV remote into a highly customizable input device, allowing users to remap all buttons, swipes, and the trackpad to perform any desired action. Its notable features include per-app profiles, the ability to assign multiple actions to single key presses, and a hot-reloading configuration file for instant updates without a restart. This tool leverages private frameworks for advanced input options and supports extensive customization tailored to the currently active application.

Codex-Prompt

2026-08-09 ★ 80
Codex-Prompt is a comprehensive system prompt designed to enhance the accuracy, rationality, and technical precision of AI responses, particularly for applications in engineering, technical analysis, AI usage, and cybersecurity research. Notable features include a focus on factual correctness over user expectation, detailed breakdowns of technical issues from multiple perspectives, and structured responses that emphasize clarity and actionable insights while minimizing emotional language and superficial expressions. The prompt is particularly well-suited for tasks involving programming analysis, system design discussions, vulnerability assessments, and binary security issues.

PE-pal

2026-08-08 HTML ★ 12
PE-pal is a web-based Portable Executable (PE) file analysis tool that translates the internal structure of Windows executables into a user-friendly format, making it accessible for beginners. It features entropy analysis to detect anomalies, classification of imported functions, and string flagging for suspicious elements, all while ensuring that file processing occurs locally in the user's browser for privacy. Notably, PE-pal does not function as a virus scanner but provides insights into the file's behavior and characteristics.

pocket-libre

2026-08-08 Python ★ 10
Pocket Libre is a tool designed to replace the vendor app for the Pocket AI voice recorder, allowing users to extract recordings locally via Bluetooth. It features local transcription using Whisper, speaker identification, and optional summarization through API calls, ensuring that user audio data remains on their personal devices. The tool operates without reliance on cloud services and offers a web interface for managing recordings and transcripts, enhancing control over audio processing and data privacy.

agents-reverse-engineer

2026-08-08 TypeScript ★ 19
AGENTS REVERSE ENGINEER (ARE) is a tool designed to facilitate the reverse engineering of codebases into AI-friendly documentation, specifically generating `.sum` files and `AGENTS.md` documentation. It is primarily utilized for enhancing communication between developers and AI assistants like Claude Code and OpenCode by providing structured insights into codebase architecture. Notable features include compatibility with multiple AI platforms and a user-friendly installation process.

antigravity-patch-proxy

2026-08-08 Dart ★ 12
The Google Antigravity Custom Model Proxy serves as an advanced patch that enables integration of various LLM models, such as Claude, OpenAI, and others, directly within the Google Antigravity IDE. It facilitates compatibility by intercepting and translating internal API communications into suitable payloads for over 19 LLM providers while offering features like real-time bi-directional SSE streaming, tool calling, and robust AES-256-GCM encryption for enterprise-level security.

McProtoNet

2026-08-08 C# ★ 19
McProtoNet is a high-performance .NET library designed for interfacing with the Minecraft Java Edition protocol, currently under active development. Its primary use case includes creating custom clients and tools for Minecraft, featuring an asynchronous API, support for multiple Minecraft versions (1.12.2 to 1.21.4), and capabilities for parsing Named Binary Tag (NBT) data. Additionally, it allows connections to cracked servers, enhancing its versatility for developers working with Minecraft protocol interactions.

morphe-patches

2026-08-08 Kotlin ★ 49
hxreborn Patches provides a collection of modifications for Android applications built upon the Morphe framework. Its primary use case is to enhance user experience by implementing features such as hiding upgrade prompts, enabling custom themes, and unlocking premium functionalities across various apps like Proton Mail and Showly. Notable features include the ability to disable tracking and customize UI elements, catering to users who seek greater control over their app interactions.

awesome-ai-reverse

2026-08-08 ★ 790
Awesome AI Reverse Engineering is a curated collection of tools that integrates AI-driven methodologies into reverse engineering processes, facilitating JavaScript reverse engineering, binary analysis, Android security research, and traffic capture. Key features include the use of the Model Context Protocol (MCP) to enable AI assistants to control professional tools like IDA Pro and Ghidra, as well as a focus on automating workflows with the latest AI techniques for enhanced efficiency and effectiveness in security analysis.

gamesir-linux-tools

2026-08-08 Python ★ 14
Deadband is a Linux GUI application designed for configuring gaming input devices such as controllers and mice through their vendor-specific interfaces. It features live input monitoring, extensive customization options for profiles, lighting effects, and button remapping, as well as diagnostic tools to troubleshoot device connectivity issues. Additionally, the tool supports multiple devices with potential for extension to others, offering a user-friendly interface and customizable themes.

ghost

2026-08-08 Rust ★ 387
Ghost is a robust process injection detection tool developed in Rust, designed to monitor running processes for signs of code injection, memory manipulation, and other malicious activities on Windows, Linux, and macOS. Its notable features include detection of memory anomalies, shellcode patterns, API hooks, and thread hijacking, all while mapping behaviors to the MITRE ATT&CK framework to aid in threat documentation. The tool offers both a command-line interface and an interactive terminal UI, providing real-time scanning results and support for extensible features like YARA rule scanning and neural ML integration.

malsnitch

2026-08-08 Go ★ 39
malsnitch is a command-line tool designed to assist malware reverse engineering by scanning various artifact formats for embedded secrets within binaries. Its notable features include the ability to detect hardcoded credentials, C2 infrastructure, and crypto keys in binary files, with support for multiple input formats such as raw strings dumps, FLOSS JSON output, and Binary Ninja exports. The tool also offers structured JSON output, automatic deduplication, and the capability to scan memory dumps, making it an efficient resource in identifying obscured sensitive information utilized by malware authors.

openremap-core

2026-08-08 Python ★ 23
OpenRemap is a Python library and CLI tool designed for ECU binary identification, diffing, and patching, enabling users to automate workflows or integrate it into applications without reliance on the internet. Its key features include accurate identification of binary files, batch processing for multiple binaries, generation of detailed diff recipes, and secure patching with complete verification. The tool provides a comprehensive, open-source solution for automotive software analysis, eliminating the need for costly commercial software.

r2unity

2026-08-08 C ★ 33
`r2unity` is a command-line tool and plugin for radare2 designed to inspect Unity IL2CPP builds by parsing `global-metadata.dat` and correlating it with native binaries for reverse engineering purposes. Key features include support for various metadata wire versions, comprehensive recovery of managed images and method metadata, detection of companion files across multiple platforms, and the ability to generate CycloneDX SBOMs. It also recognizes Unity SerializedFile v22 assets and BGDatabase v6 repositories, enhancing its capability for analyzing Unity game builds.

radmin-vpn-linux

2026-08-08 C ★ 162
Radmin VPN for Linux allows users to run the Radmin VPN client via Wine on Linux systems, enabling VPN network access without the overhead of a Windows virtual machine. The tool employs a custom driver that bridges Wine to a Linux TAP device, overcoming compatibility issues and ensuring a fully functional VPN experience. Notable features include AI-assisted reverse engineering for protocol implementation, AppImage distribution for simplicity, and command-line options for flexible usage scenarios.

repro-evidence-kit

2026-08-07 Python ★ 14
`repro-evidence-kit` is a command-line interface designed for maintainers to effectively review artifact-heavy pull requests and automate release processes by generating comprehensive hash manifests and evidence bundles. Its notable features include the creation of SHA-256 manifests, manifest diffs to identify changes, sandbox output verification against specified allowlists, and the ability to validate and tamper-proof evidence bundles, all while preserving command context for comprehensive review without revealing sensitive data. This tool is particularly beneficial for CI, security research, and data processing contexts, ensuring that artifact reviews are manageable and secure.

badpiggies-editor

2026-08-07 Rust ★ 10
Bad Piggies Editor is a cross-platform tool for editing levels and saves in the game "Bad Piggies," developed in Rust. It allows users to manipulate various file formats, including `.bytes` and `.yaml`, while offering features such as a six-pass wgpu renderer for enhanced graphical representation and a CLI for file conversion and encryption. The application employs a shared backend architecture for both native and web environments, utilizing Web Workers for optimized processing and rendering tasks.

conf-presentations

2026-08-07 ★ 319
The Quarkslab repository serves as a comprehensive archive of presentations delivered at various conferences and seminars, focusing on topics related to cybersecurity, reverse engineering, and hardware challenges. It features notable material such as workshop slides and papers on advanced techniques in Bluetooth hacking, binary instrumentation, and exploiting software vulnerabilities. This resource is primarily used for sharing knowledge and promoting discussions within the cybersecurity community through detailed lecture content and insights from industry experts.

cookidoo-api

2026-08-07 Python ★ 145
The Cookidoo API is an unofficial Python package designed to facilitate access to the Cookidoo platform. It utilizes the `aiohttp` library for asynchronous requests, requiring OAuth2 login through stored credentials, and handles various exceptions related to API interactions. Notable features include support for cross-domain cookies and detailed usage documentation with example scripts.

ERPLibre

2026-08-07 Python ★ 22
ERPLibre is a versatile CRM/ERP platform designed for managing Odoo modules, supporting multiple Odoo versions (12.0 to 18.0) within a single workspace using independent Python environments. Key features include a guided interactive CLI for module management, automated module code generation, Selenium-driven web testing, and production-ready Docker deployment options, ensuring ease of installation and robust functionality in a local environment. The integration of pre-trained Generative Transformers enhances data management and automation capabilities.

gravit-designer

2026-08-07 JavaScript ★ 43
Gravit Designer - Self-Hosted Edition is a locally hosted vector design tool that allows users to utilize all Pro features without needing a cloud account. Notable features include full offline capability, a reverse-engineered module system, native desktop applications for Windows and Linux, and built-in documentation provided through a local server. This tool is ideal for users seeking a fully functional graphic design application that operates independently of internet connectivity.

greenfield

2026-08-07 ★ 252
Greenfield is a tool designed to reverse engineer clean behavioral specifications from any codebase, producing outputs such as behavioral specs, test vectors, and acceptance criteria while maintaining a full provenance trail. It integrates into the Claude Code environment and employs a multi-layered analysis pipeline that synthesizes specification data from various sources, enabling implementation teams to develop against clear and sanitized specifications without exposure to the original code's structure. Notable features include versatility in analyzing diverse code structures, the ability to re-sanitize existing workspaces, and a comprehensive output organization for ease of access to generated specifications and audit trails.

lineageos-echo-show-camera

2026-08-07 Shell ★ 32
The lineageos-echo-show-camera repository facilitates the functionality of the front camera on the Amazon Echo Show 5 (2nd gen) by integrating a complete camera stack into the unofficial LineageOS 18.1 environment. Key features include image capture at 1600x1200 resolution, live preview with accurate color representation, and advanced image processing capabilities such as exposure adjustment and lens shading correction. This tool is essential for users seeking to enhance their device's multimedia capabilities within a custom Android framework.

OpenAlpha

2026-08-07 Swift ★ 132
OpenAlpha is a Swift package designed for retrieving images from compatible Sony digital cameras via Wi-Fi. Its primary use case involves connecting to the camera's hotspot to access and download various image sizes, including thumbnails and high-resolution originals. Notable features include support for QR code integration to configure hotspots, as well as specific asset management for efficient media retrieval, tailored to manage potential battery implications during operation.

PeAR

2026-08-07 Python ★ 17
PeAR is a versatile binary instrumentation tool leveraging the GTIRB framework, designed to add AFL++ or WinAFL instrumentation to x64 Linux and x86/x64 Windows binaries, as well as coverage tracing for x64/ARM64 Linux binaries. Key features include multiplatform support, preservation of original binary properties, the ability to import Ghidra function names into stripped binaries, and advanced fuzzing options such as persistent and shared memory modes. PeAR is particularly effective for real-world binaries, even those that are stripped, enabling practical application in binary fuzzing and tracing.

pin-it

2026-08-07 JavaScript ★ 18
The pin-it tool enables users to pin any tweet to their X (formerly Twitter) profile through a UserScript or executable bookmark. Although it was designed for ease of use via Tampermonkey or Greasemonkey, it currently faces functionality issues due to changes in the X API, with no planned fixes. Notable features include the ability to run as a UserScript or bookmarklet, though usability may be hindered by Content Security Policies.

pokepinballrs

2026-08-07 Assembly ★ 138
Pokémon Pinball: Ruby & Sapphire is a disassembly project that facilitates the building of the ROM for the Pokémon Pinball: Ruby & Sapphire game. This tool is primarily used for archival and development purposes, allowing users to analyze and modify the game code. Notable features include the provision of a specific ROM SHA-1 hash for validation and detailed setup instructions in the INSTALL.md file.

reSL

2026-08-07 C++ ★ 36
reSL is a reverse-engineered version of the DOS game ShortLine v1.1, adapted for modern mobile and touch-controlled devices. Its primary use case is to provide an accessible way to play a classic game in a browser while maintaining the original experience, featuring improvements such as enhanced UI for touch interaction, fixed bugs from the original game, and cross-platform compatibility. Notable features include mouse/touch controls for menus, error handling enhancements, and visual updates, all aimed at recreating the game closely to its original form while ensuring a smoother gameplay experience.

rever-browser

2026-08-07 TypeScript ★ 22
rever-browser is an Electron application designed for API reverse engineering, enabling users to interact with targeted websites in an embedded Chromium tab while capturing and analyzing network requests. Its notable features include live traffic capture, AI-assisted code agent interactions, browser automation capabilities, and advanced JavaScript bundle analysis, facilitating the reproduction of API calls within a seamless interface.

sthenos-embedded-toolkit

2026-08-07 Shell ★ 17
The Sthenos Embedded Toolkit is a comprehensive solution for building static debugging and analysis tools tailored for embedded systems across over 50 architectures. Notable features include support for both musl and glibc toolchains, a range of available tools such as strace and tcpdump, and the capability to compile specific tools for designated architectures using a Docker-based build environment. This toolkit enables streamlined development and troubleshooting for embedded systems, ensuring reliable performance in diverse operating environments.

ameen-morphe

2026-08-06 Kotlin ★ 18
Ameen's Morphe Patches is a collection of bytecode-level modifications designed for enhancing the functionality of various Android applications using the Morphe framework. The tool primarily serves to unlock premium features in apps like Foodvisor and PhotoGrid, allowing users to bypass limitations and watermarks. Key features include ease of use through the Morphe Manager or CLI, as well as the ability to apply custom logic to APKs without requiring the original source code.

fripack-inject

2026-08-06 C++ ★ 31
Fripack-inject is a payload injection tool designed to work with the Fripack framework, facilitating the manipulation of packaged applications. Its primary use case is to provide a seamless injection mechanism that enhances the functionality of the Fripack environment. Notable features include compatibility with the Fripack ecosystem and the ability to customize payload injections for various scenarios.

heretek

2026-08-06 Rust ★ 389
Heretek is a GDB TUI dashboard that facilitates debugging by allowing seamless connections to remote targets without the need for a functioning `gdbserver`. It is designed to operate without Python dependencies, is architecture-agnostic, and can work with minimal requirements (just `gdb`, `nc`, `cat`, and `mkfifo`), making it an ideal tool for developers facing issues with standard `gdbserver` binaries. Notable features include static linking for ease of use and robust support for various GDB commands execution.

RTCV

2026-08-06 C# ★ 383
Real-Time Corruptor Vanguard (RTCV) is a dynamic data corruption tool designed for video games, enabling users to intentionally corrupt game data in real-time to create glitches. It supports multiple emulators, including Bizhawk, Dolphin, and PCSX2, along with features like customizable corruption algorithms, a package manager for plugins, and tools for managing and generating corruption instructions. RTCV also includes functionalities for file corruption and a dedicated user interface for enhanced interaction.

VandalHearts-PcPort

2026-08-06 C ★ 28
Vandal Hearts — Native PC Port is a fan-driven preservation project that recreates the PlayStation 1 classic by decompiling and porting it to modern desktop environments using SDL2, OpenGL, and OpenAL. Key features include a byte-exact matching decompilation of the original game, an optional Tactical Mode for rebalanced gameplay, enhanced graphics with a PSX-accurate integer rasterizer, and an HD pack for improved assets. The project maintains compatibility on both Windows and Linux, ensuring a faithful yet enriched gaming experience.

web-global-metadata-parser

2026-08-06 JavaScript ★ 11
The web-global-metadata-parser is a tool that parses and extracts metadata from web files, facilitating enhanced data accessibility and management. Its primary use case is to enable seamless integration and retrieval of metadata across various web-based applications, while notable features include its capability to handle multiple file formats and its reliance on shared utility scripts for enhanced functionality.

codex5.6-coldbrew

2026-08-06 Python ★ 73
Codex 5.6 ColdBrew is a sophisticated tool designed for advanced task routing and processing across multiple domains, employing a dual-engine framework named MAX. Its notable features include Armor Break configurations for enhanced target prioritization and integrity checks, as well as Mature M5 for adult-oriented content generation, all supported by a comprehensive command set for session management and task execution. The tool is tailored for users seeking to leverage versatile interactions for technical and creative applications within a structured environment.

damai

2026-08-06 Jupyter Notebook ★ 507
damai is a community-driven tool designed for automated ticket purchasing across major Chinese platforms such as Damai, Maoyan, and PiaoXingQiu. It provides resources for ticket monitoring, reverse engineering on Android, and specialized tutorials for packet capturing and process isolation, facilitating advanced ticket procurement strategies for users ranging from beginners to tech-savvy developers. Notable features include user-driven tutorials, a dedicated community for technical discussions, and integration with various methodologies for effective circumvention of platform restrictions.

displaydeck

2026-08-06 Objective-C ★ 19
DisplayDeck is a macOS utility designed to provide comprehensive control over displays and windows, featuring capabilities such as enabling/disabling screens, adjusting brightness, forcing HiDPI resolutions, and managing window tiling/snapping. It operates without telemetry or subscriptions, leveraging Apple's private frameworks and emphasizing a lightweight, user-friendly experience. Notable features include remote access, auto-night color warmth adjustments, and a robust failsafe for display management in various configurations.

fretwire

2026-08-06 Rust ★ 20
fretwire is an independent Linux editor for the Line 6 HX Stomp and Helix Floor, developed in Rust. It interfaces with the pedal via the MI_00 USB control protocol, allowing users to import data from their own HX Edit installation to manage presets and settings. Notable features include a graphical user interface built with WebKitGTK and Svelte, a command-line interface for device operation, and the ability to run a mock device for UI demonstration without hardware.

game-and-watch-patch

2026-08-06 C ★ 196
The `game-and-watch-patch` repository provides custom firmware and a patching utility for newer Nintendo Game and Watch consoles, enabling the enhancement of stock firmware functionality. It seamlessly integrates with `retro-go`, allowing users to run retro games, store the entire firmware internally without external flash, customize graphics, and dump playable ROMs. Notable features include configuration options for easter eggs, graphical dynamics, and additional ROM hack capabilities, optimizing the gaming experience on supported devices.

GameTracking

2026-08-06 Shell ★ 302
GameTracking is a modular toolset designed to automate the tracking and updating of game repositories through GitHub Actions. Its primary use case is to manage game updates by using a reusable workflow that integrates with individual game repositories, automating the download of necessary files and the execution of update scripts. Notable features include support for manual triggers, a lightweight file downloader for selective content retrieval, and cross-platform compatibility for both Linux and Windows systems.

gemini-web2api-go

2026-08-06 Go ★ 336
gemini-web2api-go is a tool that acts as a reverse proxy, converting the Google Gemini web interface into an OpenAI-compatible API, enabling users to access its functionalities without requiring an official Google API key or payment quotas. Key features include OpenAI-like endpoints for model interactions, anonymous usage with advanced session management including a proxy and cookie pooling mechanism, and a built-in Chinese management panel for monitoring and configuring usage. The tool supports various models and offers enhanced security and anonymity through real browser fingerprinting and independent rate limiting for each IP.

ILSpy-Mcp

2026-08-06 C# ★ 50
ILSpy MCP Server is a .NET 9-based Model Context Protocol (MCP) server that provides in-memory decompilation and structural analysis of .NET assemblies, enabling AI assistants to interact with compiled .NET binaries such as `.dll` and `.exe` files using natural language. Notable features include JSON-RPC 2.0 communication for seamless integration, validation of tool requests, and robust handling of inputs to facilitate various analysis tasks through an organized processing pipeline. This tool serves as a bridge between AI clients and the ILSpy decompiler, enhancing the capabilities of language models in inspecting and manipulating .NET code.

jadx-mcp-server

2026-08-06 Python ★ 764
JADX-MCP-SERVER is an automated server designed for analyzing Android APKs through the connection with the JADX-AI-MCP Plugin, utilizing large language models like Claude to facilitate reverse engineering. Its primary use case involves uncovering vulnerabilities and parsing APK manifests, streamlining the reverse engineering process for security professionals. Notable features include seamless integration with LLMs for advanced analysis and fully automated operations to enhance efficiency in vulnerability detection.

M2TWEOP-library

2026-08-06 C++ ★ 92
The M2TW Engine Overhaul Project (M2TWEOP) enhances the gameplay capabilities of *Medieval 2: Total War* by modifying the game's in-memory code using C++ and Assembly, accessible through a comprehensive Lua scripting API. Key features include extensive customization options, removal of engine limitations, robust debugging tools, and support for custom sounds and mod integration. The tool also fixes several engine bugs and allows users to create unique gameplay experiences with capabilities such as online Hotseat battles and strategic map viewing.

MachOKit

2026-08-06 Swift ★ 242
MachOKit is a library designed for parsing MachO files, facilitating the extraction of various components and data structures from both file and memory representations. It supports operations such as parsing load commands, symbol listing, and rebase and binding operations, along with advanced features like handling dyld shared caches. Notably, MachOKit enables developers to work with single MachO files, Fat files, and dyld caches seamlessly through structured interfaces.

objdiff

2026-08-06 Rust ★ 525
objdiff is a local diffing tool designed for analyzing changes between decompilation project object files, providing detailed comparisons of functions and data within these files. It features built-in C++ symbol demangling, automatic rebuild on source changes, project-specific configuration options, and support for multiple architectures including ARM, MIPS, and x86. Additionally, the tool integrates with a web interface and has a Visual Studio Code extension in development, enhancing user accessibility and functionality in object file analysis.

th07

2026-08-06 C++ ★ 37
th07 is a reimplementation and decompilation of the game "Perfect Cherry Blossom" (version 1.00b) by Team Shanghai Alice, designed to be functionally identical to the original executable while achieving a high accuracy rate. It provides a fully playable main game executable (th07.exe) alongside a configuration tool (custom.exe), both of which currently require the original game files for certain features like icon extraction. Notable features include the handling of integrity checks and options for non-matching builds, with ongoing improvements aimed at enhancing accuracy and usability across platforms.

unixtract

2026-08-06 Rust ★ 29
unixtract is a Rust-based extraction tool designed to unpack various firmware package formats primarily used in TVs and AV devices, ensuring compatibility across multiple platforms including Windows, Linux, MacOS, and Android. Its notable features include support for various file formats such as Amlogic burning images and Android OTA payloads, along with the ability to specify options for format-specific behaviors, while maintaining simplicity as it does not involve re-packing of the extracted files.

FlutterTap

2026-08-06 C++ ★ 105
FlutterTap is a Zygisk module designed for intercepting network traffic from Flutter applications by redirecting it to a configurable proxy, effectively bypassing BoringSSL's TLS certificate verification without the need for a certificate installation or app repackaging. Its primary use case focuses on persistent traffic interception during mobile application analysis, providing an easy-to-use manager app for selecting target applications and configuring proxy settings. Notable features include automatic operation on device boot, minimal impact on non-selected apps, and the ability to capture native traffic without the drawbacks associated with traditional methods such as Frida or LSPosed.

Java-Triage

2026-08-05 Python ★ 15
Java Triage is a static analysis tool designed for examining suspicious Java codebases, decompiled JARs, and Minecraft mods. It features extensive capabilities including decompilation with CFR, advanced string recovery, and detection of malicious indicators and behaviors, all while producing comprehensive reports in various formats. Notable functionalities include runtime command and control resolution, detailed scoring for findings, and support for detecting obfuscation tactics commonly used in malware.

crackmesone_python

2026-08-05 Python ★ 10
Crackmes.one is a Python and Flask-based platform designed for sharing and solving reverse engineering challenges, enabling users to upload crackmes and their corresponding solutions. Key features include user registration and authentication, a content moderation system, a rating feature, notifications, and search functionality, making it a comprehensive tool for collaboration in reverse engineering. The application integrates with MongoDB for data storage and supports deployment configurations for both development and production environments.

gemini-python-api

2026-08-05 Python ★ 27
The Gemini Chat API is an automated browser wrapper framework that serves as a programmatic interface to Google's Gemini web platform, enabling users to synchronize session states and interact with Gemini's conversational capabilities. Notable features include session-based automation using persistent cookies, structured data extraction for integration with downstream projects, and automated handling of media payloads generated during interactions. This open-source tool is intended for educational and research applications within controlled environments, rather than commercial use.

RESim

2026-08-05 Python ★ 194
RESim is a dynamic analysis tool designed for reverse engineering and vulnerability assessment on simulated networked systems, utilizing the Simics platform for high-fidelity emulation of hardware. Its key features include tracing process execution, integrated debugging with IDA Pro and Ghidra, reverse execution, and a custom AFL fuzzer for direct memory injection, all while offering external observation without altering the state of the simulated environment. This tool is particularly effective for analyzing processes and data flow in both Linux and Windows systems without requiring kernel-level knowledge.

SFP

2026-08-05 C# ★ 654
SFP (formerly SteamFriendsPatcher) is a utility designed for customizing the Steam client by applying custom skins and scripts. Its primary use case is to enhance user experience through personalized visual designs and functionality, enabling users to modify various Steam pages via CSS and JavaScript. Notable features include support for separate folders for skins and scripts, customizable application configurations, and JavaScript injection capabilities, allowing for extensive personalization while cautioning users about potential risks associated with untrusted scripts.

th06

2026-08-05 C++ ★ 546
The GensokyoClub/th06 repository focuses on reverse engineering and reconstructing the source code of the Touhou game "Embodiment of Scarlet Devil" version 1.02h. Its primary use case is to allow for the game's reimplementation and porting to platforms like Linux and modern Windows, utilizing a customized build system with dependencies such as Python and Wine. Notable features include automated dependency management, integration with Ghidra for reverse engineering, and tools for object file comparison through objdiff, facilitating contributions to the reimplementation effort.

Tools

2026-08-05 Python ★ 209
This repository offers a collection of tools and scripts specifically designed for reverse engineering computer and console games using Python 3 and MexScript. The scripts are ready to run without compilation, requiring only appropriate interpreters such as Python or quickBMS, making them accessible for game modding projects. Notable features include the variety of tools developed over years of expertise in game reverse engineering, providing practical support for modders.

tpp-server-emulator

2026-08-05 C++ ★ 48
The tpp-server-emulator is a reimplementation of the backend server for *Metal Gear Solid V: The Phantom Pain*, designed primarily for academic research purposes. It allows players to experience the game's online features in a controlled environment, featuring comprehensive installation instructions, scripting capabilities, and support for multiple platforms. The tool emphasizes responsible usage and provides build customization options for developers.

Ballanced

2026-08-05 CMake ★ 45
Ballanced is a source-level reimplementation of the Ballance game runtime, designed to rebuild game components, player, and engine libraries into a Ballance-compatible layout. It allows users to play the game without the need for compatibility modes or registry edits by integrating original game assets and simplifying installation, making it suitable for both players and developers. Notable features include support for multiple platforms, a structured repository with Git submodules for modular components, and straightforward build instructions using CMake.

cilfi

2026-08-05 C# ★ 45
CILFI (Common Intermediate Language Function Identification) is a specialized tool designed to match methods in .NET binaries against a library of known signatures, facilitating the reverse engineering process. Its notable features include the ability to create generalized signatures using wildcards and regular expressions, support for batch analysis with multiple binaries, and output compatible with .NET deobfuscators. CILFI is offered as both a standalone binary and a reusable library, making it accessible for various analytical workflows.

Cryogenic

2026-08-05 C# ★ 57
Cryogenic is a C# re-implementation of the Dune CD game's DOS executable, designed to replace x86 assembly routines with .NET methods while running in the Spice86 emulator. Its primary use case is to enhance gameplay by enabling ongoing updates and modifications through hybrid ASM/.NET execution. Notable features include the ability to incrementally override functions in the original binary without disrupting the game, full compatibility with sound and music, and a structured approach for managing memory segments and function overrides.

d2-dedicated-server

2026-08-05 Zig ★ 19
The d2-dedicated-server project provides a self-hosted, open-source dedicated game server for Diablo II version 1.14d, functioning as a cloud-native replacement for PvPGN. It features a headless architecture that integrates an injected Zig DLL to manage the game engine and a clean-room realm server, enabling seamless multiplayer experiences for unmodified retail clients. Designed for containerized environments, it supports Kubernetes and Docker, with stateless scalability and compatibility with modern observability tools like Grafana.

DisplayDeck

2026-08-05 Objective-C ★ 13
DisplayDeck is a macOS tool that offers comprehensive control over your Mac's displays and windows, enabling users to disable and enable screens, force HiDPI resolutions, and adjust brightness and color warmth settings. Notable features include window tiling and snapping, transparency effects, remote access capabilities, and a lightweight design with no telemetry. It is designed to replace multiple paid utilities with a single, free, and open-source solution that operates efficiently without background processes.

EUVA

2026-08-05 C# ★ 44
EUVA IDE is a versatile reverse engineering platform that combines a hex editor, decompiler, and advanced disassembly tools, designed for enhanced customization and user experience in security research and educational purposes. Its notable features include a user-friendly decompiler aimed at conveying program logic clearly, a DSL for sharing binary patches, and extension capabilities that allow integration with other analysis tools. The platform emphasizes community-driven development and flexibility, making it suitable for both individual and industrial use cases.

hbkit

2026-08-05 Python ★ 61
`hbkit` is a command-line tool designed to extract files from Synology Hyper Backup (`.hbk`) archives without requiring Synology software, offering a robust alternative for recovering backups. It operates seamlessly on Linux and macOS, supporting interactive browsing via a text-based user interface (TUI) and ensuring data integrity by validating every file against the archive's MD5 and CRC32 checksums. Notable features include handling encrypted backups, a variety of command options for probing and extracting data, and the ability to recover files while preserving their directory structure and modification times.

HexCtrl

2026-08-05 C++ ★ 216
HexCtrl is a versatile hex control library designed for Windows applications, facilitating the display and manipulation of binary data in hexadecimal format. Its primary use case is in software that requires a user interface component for editing binary files, with notable features including virtual data mode, customizable colors, support for bookmarks, and various methods for data management and interaction. The library also allows for the integration of classic and dialog-based controls, making it adaptable for different development environments.

Patcherex2

2026-08-05 Python ★ 58
Patcherex2 is an advanced patching tool designed for binary analysis and modification across multiple platforms, extending the capabilities of the original Patcherex project. It enables users to insert, remove, and modify instructions and data within binaries, supporting a wide range of architectures including x86, ARM, and PowerPC. Notable features include detailed documentation, installation via PyPI and Docker, and extensive support for various patch types, enhancing its utility for cybersecurity researchers and developers.

pwn

2026-08-05 Ruby ★ 76
PWN is an open-source Ruby toolkit designed for offensive security automation, integrating various tools used in OSINT, network scanning, and vulnerability testing within a single workspace. Its primary use case is to streamline red teaming and pentesting efforts by providing a unified framework that supports automation through a tool-calling AI agent and a flexible plugin architecture. Notable features include 66 plugins, support for multiple LLM engines, and a feedback loop system that learns from previous mistakes, enhancing the efficiency of security assessments.

resource_dasm

2026-08-05 C++ ★ 153
resource_dasm is a comprehensive suite of reverse-engineering tools primarily aimed at classic Mac OS applications and games, with additional support for Nintendo GameCube formats. Notable features include the ability to read and convert resource files, disassemble binaries, and generate game maps, making it a versatile solution for analyzing and modifying legacy software and media. The project includes specialized utilities for handling various resource formats, image rendering, and music sequence synthesis, enhancing its utility for developers and researchers in the field of software preservation and analysis.

TinyLoad

2026-08-05 C++ ★ 187
TinyLoad is a PE crypter and packer for 64-bit Windows executables, designed to protect input binaries against reverse engineering by appending a payload to itself and employing various layers of encryption and compression. It features a custom VM encryption method with obfuscated opcodes, a unique LZ77 compression algorithm, and Veh page fault decryption to keep most of the payload encrypted in memory during execution. Additionally, it includes anti-dumping techniques to safeguard critical APIs and prevent reconstruction of the import table.

Unpacker

2026-08-05 Python ★ 27
Unpacker is a modular tool designed for malware analysts to detect and unpack various malware packers such as UPX, ASPack, Themida, and VMProtect, facilitating static analysis. It leverages multiple detection methods including section names, entropy, and heuristics, allowing users to unpack multi-layer packed samples through a streamlined command pipeline. The tool outputs an unpacked file along with validation notes, enhancing the analyst's ability to perform further examinations and providing outputs suitable for integration with other analysis tools.

vxlang-page

2026-08-05 C++ ★ 769
VxLang is a cybersecurity tool designed to protect Windows executables, dynamic link libraries, kernel drivers, and .NET binaries from reverse engineering and unauthorized access. Its notable features include virtualization, code obfuscation, and packing functionality to thwart static and dynamic analysis attempts. The tool supports x86-64 architectures and is expanding to include additional file formats and functionalities in future releases.

xenon

2026-08-05 C++ ★ 293
Xenon is an experimental Xbox 360 emulator developed in C++ for Windows and Linux, primarily designed to run low-level programs such as XeLL, Linux, and LK. As an early-stage project, it currently supports only limited functionality, making it suitable for developers and testers interested in Xbox 360 architecture and emulation. Key features include native support for multiple operating systems and a focus on community contributions to advance the emulator's capabilities.

jddlab

2026-08-04 Python ★ 22
jddlab is a comprehensive tool designed for decompiling and deobfuscating Java and Android APKs through a Docker image, providing a robust command-line interface for users. Its primary use case is to simplify the process of accessing various decompilation tools while ensuring system safety via Docker's isolation. Notable features include easy installation with a single Docker pull command, quick updates through container versions, and accessibility of all files within the current working directory during operation.

DracoLure

2026-08-04 Python ★ 15
DracoLure is a dragon vector honeypot designed to deceive and analyze attackers by serving realistic fake web assets, thereby enticing them to interact. It features real-time detection and classification of probing attacks, assigns threat scores from 0–100, and automatically quarantines malicious sources when they exceed predefined threat thresholds. With its comprehensive signature library for various attack vectors and real-time response mechanisms, it provides a robust defense mechanism for cybersecurity environments.

iocx

2026-08-04 Python ★ 29
IOCX is a deterministic static IOC extraction engine designed for modern security pipelines, specifically focusing on malware analysis and incident response. It ensures zero execution risk by performing pure static analysis on Portable Executable (PE) files, delivering stable and reproducible outputs while effectively handling adversarial input. Key features include a binary-aware parser, high-performance extraction, and compatibility with CI/CD environments, positioning IOCX as a reliable tool for automated threat detection and defense.

ElementCopy

2026-08-04 JavaScript ★ 10
Elementor Extractor is a Chrome extension that facilitates the extraction and reconstruction of Elementor page structures from live WordPress sites by analyzing the DOM. It generates two types of JSON outputs: one suitable for direct import as an Elementor template and another providing a detailed technical report of all extracted elements, assets, and configurations. Notable features include comprehensive asset detection, extraction of over 30 widget types, and the ability to map Elementor-specific settings and structures for developers and content migrators.

ida-minsc

2026-08-04 Python ★ 333
IDA-minsc is a plugin for IDA Pro designed to streamline the scripting of the IDAPython plugin, allowing reverse engineers to execute scripts with minimal effort. It introduces a simplified structure for the IDAPython API, featuring a tagging system, support for multicased functions, and filtering capabilities, enabling users to perform search and annotation tasks efficiently with concise code. The installation process is straightforward, requiring the user to clone the repository and install necessary Python dependencies before utilizing its enhanced functionality directly within IDA Pro.

KittyMemory

2026-08-04 C++ ★ 540
KittyMemory is a C++ library designed for runtime memory manipulation and analysis on Android and iOS platforms, featuring capabilities such as memory patching, dumping, scanning, and module introspection for ELF and Mach-O formats. Notable features include comprehensive pattern scanning methods, detailed ELF and Mach-O introspection tools, memory mapping and region enumeration, alongside support for instruction decoding and memory dump utilities. This tool is particularly valuable for developers and researchers involved in reverse engineering and low-level binary analysis on mobile platforms.

KittyMemoryEx

2026-08-04 C++ ★ 178
KittyMemoryEx is an advanced memory manipulation toolkit designed for remote memory patching, scanning, and ELF introspection on Android and Linux platforms. Its notable features include dual remote memory backends, comprehensive pattern scanning, various ptrace utilities for process control, and the ability to perform remote function and syscall calls, making it an essential tool for security researchers and developers focused on reverse engineering and debugging applications in remote environments.

ps5rs

2026-08-04 Rust ★ 19
ps5rs is a Rust-based framework designed for analyzing PS5 binaries, facilitating virtual loading and host-side emulation. Its primary use case involves parsing various binary formats, resolving imports, and extracting clean ELFs, while notable features include an interactive dashboard for analysis reports and a host-side emulator that executes guest binaries using pure Rust high-level emulation (HLE) modules. The framework leverages Rust's memory safety benefits to manage untrusted binary data securely.

AndKittyInjector

2026-08-04 C++ ★ 359
AndKittyInjector is a ptrace-based library injector designed for Android that facilitates the injection of shared libraries into running processes or newly launched applications across multiple Android versions and CPU architectures. Notable features include support for injecting multiple libraries simultaneously, bypassing Android linker namespace restrictions, and advanced injection triggers such as breakpoints on library loading or specific symbols. This tool is especially useful for debugging and modifying the behavior of Android applications in a stealthy manner.

AndUEDumper

2026-08-04 C++ ★ 459
AndUEDumper is a tool designed to extract SDK and function scripts from Unreal Engine games on Android. It supports multiple architectures (ARM64, ARM, x86, x86_64) and automates the discovery of critical game components such as GUObjectArray and GNames, while generating usable JSON scripts for reverse engineering tools like IDA and Ghidra. Noteworthy features include memory dumping capabilities, extensive logging options, and compatibility with a variety of popular Unreal Engine titles.

IDA_ClassInformer_PlugIn

2026-08-04 C++ ★ 334
Class Informer is a Hex-Rays IDA Pro plug-in that scans Microsoft Visual C++ binaries for virtual function tables (vftables) utilizing Run-Time Type Identification (RTTI) data. It enhances reverse engineering capabilities by labeling and commenting on vftables, defining associated data structures, and providing a browsable list of class objects. Noteworthy features include the identification of class hierarchies and the processing of static initializers, aimed at streamlining analyses of MSVC-compiled binaries.

ida-sigmaker

2026-08-04 Python ★ 217
SigMaker is a cross-platform plugin for IDA Pro 9.0+ that enables the creation of binary signatures with zero dependencies, supporting x86, x64, ARM, and MIPS architectures. It offers optional SIMD optimizations for improved performance and aims to remain compatible with future IDA versions without requiring SDK recompilation, facilitating community contributions. Noteworthy features include processor-aware operand wildcarding, a straightforward installation process, and batch search capabilities for efficient signature management.

pikmin

2026-08-04 C ★ 290
A decompilation of Pikmin brought to you by fans of the series.

AlwaysOnTop

2026-08-04 C ★ 69
AlwaysOnTop is a Windows utility designed to elevate a program's window to a higher Z-order position by obtaining UIAccess permissions, allowing it to remain on top of other windows, including system-level tools like the Task Manager. Its primary use case is to prevent interruptions during screen recording or marking sessions by ensuring that the program window is not obscured. Notably, it optimizes the UIAccess acquisition process, minimizing the number of required process startups and simplifying the privilege elevation methodology.

anything-analyzer

2026-08-04 TypeScript ★ 3596
Anything Analyzer is a comprehensive traffic capturing and analysis tool designed for various sources, including web applications, desktop apps, and command-line interfaces. Its primary use case revolves around automatic protocol reverse engineering and security auditing, leveraging AI to streamline the analysis process. Notable features include support for multiple capture environments, unified session management, two-phase intelligent analysis, and the ability to generate detailed reports on encryption and API interactions.

awesome-reverse-engineering-and-malware-analysis

2026-08-04 Shell ★ 89
Awesome Reverse Engineering & Malware Analysis is a comprehensive resource that serves as a curated guide for reverse engineering and malware analysis tools, methodologies, and educational content. It categorizes entries across various disciplines such as static and dynamic analysis, exploit development, and digital forensics while providing quality assurance by checking all links and content for relevance. Notable features include structured learning tracks for different areas of focus, detailed tagging for easy navigation, and inclusion of community resources to enhance collaboration and knowledge sharing.

bindata

2026-08-04 Ruby ★ 653
BinData is a Ruby library designed for declaratively reading and writing structured binary data, offering a more elegant and readable alternative to the traditional `#pack` and `#unpack` methods. It simplifies the process of defining data formats, supporting common primitive types and built-in handling for dependent and variable length fields. This tool is particularly useful for developers working with intricate binary data structures who seek to improve code clarity and maintainability.

Brochacha20

2026-08-04 C ★ 31
Brochacha20 is a discontinued static client decryptor for Roblox, designed to extract and decrypt game files from the Roblox client directory. Users can specify a directory path and optional output file via command-line arguments, with features including silent mode and manual issue reporting through GitHub. Despite its current inoperability, the tool provides insights into the decryption process of Roblox's runtime page data.

Bypass-SetWindowDisplayAffinity

2026-08-04 C++ ★ 146
Bypass-SetWindowDisplayAffinity is a kernel-level tool designed to bypass Windows' screen capture protections enforced by the SetWindowDisplayAffinity API. Its primary use case is for educational and research purposes, demonstrating how display affinity can be neutralized at the kernel level without relying on user-mode APIs or DLL injection techniques. Noteworthy features include its functionality in a virtualized environment and the emphasis on thorough documentation for kernel modifications and driver installation considerations.

cinnamon

2026-08-04 C ★ 366
Cinnamon is an open-source re-implementation of the GameMaker: Studio runner specifically designed for the Nintendo 3DS and Wii U platforms. Its primary use case is to enable the execution of GameMaker Language (GML) games compiled as bytecode, thus allowing titles such as Undertale and Deltarune to be ported to these consoles. Notable features include support for bytecode versions 16 and 17, optimization for older hardware, and ongoing development aimed at increasing game compatibility across various GML titles.

claude-code-reverse-engineering

2026-08-04 HCL ★ 31
Claude Code CLI is a reverse engineering tool designed to create implementation-ready specifications for Anthropic's Claude Code CLI, utilizing source map analysis of the npm package. It features approximately 1,900 files and over 512,000 lines of TypeScript code, offering a terminal UI, a core engine with 45+ tools, and an extension layer for plugins and skills. The tool emphasizes security with multiple permission modes and includes a tracking system for cost management and query execution.

CollapseScanner

2026-08-04 Rust ★ 14
CollapseScanner is a static security analysis tool specializing in the inspection of Java JARs, class files, and nested archives without executing them. It detects high-risk elements such as hardcoded secrets, suspicious APIs, and obfuscation techniques, allowing for customizable scans through various detection modes and options for detailed reporting. Notable features include support for configuration via TOML files, multi-threading for enhanced performance, and output in machine-readable JSON format for easier integration into automated workflows.

copilot-proxy

2026-08-04 TypeScript ★ 37
Copilot Proxy is a local single-user adapter that facilitates access to GitHub Copilot's capabilities through APIs compatible with OpenAI and Anthropic tools, like Claude Code and Codex. It specifically targets individual users wishing to expose their Copilot identity for personal projects while providing a setup that integrates with various client configurations and offers diagnostics capabilities. Notable features include its ability to run as a reverse-engineered proxy, diagnostic dashboards for monitoring, and support for multiple AI models through a streamlined setup process.

GhidraDeviceTreeBlob

2026-08-04 Java ★ 37
Ghidra Device Tree Blob is an extension designed to import Device Tree information into the Ghidra memory map, facilitating the reverse engineering of firmware from proprietary devices that lack published SVD files. Notable features include a straightforward import process through the Ghidra interface and compatibility with Ghidra's extension manager for easy installation. This tool is particularly useful for developers and security researchers working with embedded systems.

GhidraSVD

2026-08-04 Java ★ 49
Ghidra SVD is a Ghidra plugin designed to import CMSIS SVD (System View Description) files into the Ghidra memory map, facilitating the reverse engineering of firmware for devices that provide SVD files. Its primary use case is enhancing the analysis of hardware-specific memory layouts, which is crucial for embedded systems development and security assessments. Notable features include ease of installation via Ghidra's Extension Manager, automatic memory map updates upon SVD file import, and support for numerous SVD file sources.

gta2_re

2026-08-04 C++ ★ 90
GTA2 RE is an open-source tool designed for reverse engineering and building modifications for the classic game Grand Theft Auto 2. It allows users to set up and run patched versions of the game through a straightforward build process using Python, with notable features including automatic setup of the game's executable and the option to run standalone or patched versions directly after building. The project encourages community contributions and provides a dedicated hub for collaboration and additional resources.

Hook-Chrome-Chromium-SSL

2026-08-04 ★ 79
Hook-Chrome-Chromium-SSL is a C++ tool designed to intercept and manipulate the SSL_read and SSL_write functions utilized by Google Chrome and Chromium, enhancing capabilities for monitoring encrypted data transmission. By manually locating and hooking internal SSL routines, the tool allows practitioners to capture and analyze secure network communications, which is particularly challenging due to the non-exported nature of these functions within the chrome.dll binary. Notable features include the ability to leverage Chrome's source code and BoringSSL library for function discovery and analysis.

JD.Efcpt.Build

2026-08-04 C# ★ 13
JD.Efcpt.Build is an MSBuild integration tool for automating the generation of Entity Framework Core models using a database-first approach during the `dotnet build` process. Its notable features include automatic DbContext and entity generation based on schema changes, support for both live database connections and SQL Projects, smart configuration discovery, and compatibility with CI/CD environments, making it suitable for seamless integration in database-driven application development.

LibreShockwave

2026-08-04 C++ ★ 79
LibreShockwave is a C++20 library designed for parsing Macromedia/Adobe Director and Shockwave files, aiming to create a comprehensive software suite that includes a Director player and a replacement for Director MX. The tool features a Lingo bytecode virtual machine and player for executing Director movies, along with a Qt-based editor for inspecting projects. It supports various file formats and incorporates options for native C++ use as well as browser/WASM deployment, although the development is ongoing and not yet production-ready.

playdate-reverse-engineering

2026-08-04 Python ★ 305
The cranksters/playdate-reverse-engineering repository provides a collection of unofficial documentation and tools for reverse-engineering the Playdate handheld console's game files and file formats. Key features include a range of conversion tools for proprietary file types, an API for server interaction, and utilities for evaluating Lua scripts over USB, enabling in-depth analysis and manipulation of Playdate games and applications.

RemoteHiddenDesktop

2026-08-04 C ★ 142
KHVNC is a remote desktop tool that enables users to create and manage a hidden virtual desktop session on a remote machine, thus allowing the execution of applications and scripts without disrupting the physical user's activities. Notable features include browser automation in stealth mode and support for multiple web browsers, making it suitable for educational and research applications. The tool consists of a server component for hosting hidden sessions and a client for controlling those sessions remotely.

rusty_box

2026-08-04 Rust ★ 30
Rusty Box is a Rust-based emulator for 32/64-bit x86 architecture that supports full system virtualization and various advanced features such as integration with the x87 FPU and AVX extensions. It is capable of booting multiple Linux distributions, including DLX and Alpine, both in headless and GUI modes, and can be executed in web browsers using WASM. The tool also supports UEFI applications and provides multiple build configurations, including no_std environments for embedded targets, making it versatile for a range of use cases in emulation and testing.

SetWindowDisplayAffinity-Bypass

2026-08-04 ★ 136
SetWindowDisplayAffinity-Bypass is a tool designed to bypass Windows' screen capture protections that utilize the `SetWindowDisplayAffinity` API. It employs a non-invasive technique to capture screenshots of applications protected by flags like `WDA_MONITOR` or `WDA_EXCLUDEFROMCAPTURE`, without resorting to DLL injection or API hooking, thus avoiding modification of the target process. This method aims to provide a stealthier approach for researching screen capture limitations, though it may not be universally effective across all Windows versions or GPU drivers.

sigmatcher

2026-08-04 Python ★ 13
Sigmatcher is an automation tool tailored for matching Java classes and methods across various application versions, utilizing signatures from smali code for accurate correlation. It serves as a vital asset in long-term reverse engineering projects by enabling users to create customizable signature files in YAML format and analyze multiple types of Android package inputs efficiently. Notable features include the ability to decode APK files, apply specified signatures, and produce detailed analysis results that highlight matched classes, methods, and fields.

UnpackThemida

2026-08-04 Python ★ 194
ThemidaUnpacker is a Python 3 tool designed for dynamically unpacking executables protected by Themida and WinLicense versions 2.x and 3.x. It supports unpacking both 32-bit and 64-bit portable executables (PEs) and .NET assemblies, automatically recovering the original entry point and import table. Notable features include a user-friendly drag-and-drop interface, command-line options for advanced control, and specific handling for executables requiring license files.

pymodhook

2026-08-04 Python ★ 122
`pymodhook` is a Python library designed for recording function calls within Python modules, facilitating reverse engineering and analysis tasks. It operates across major platforms and allows users to hook into arbitrary method calls of module classes alongside tracking invocation arguments and return values, providing features akin to the Xposed framework for Android. Notable functionalities include customizable hooking parameters, support for specific module imports, and detailed logging of the raw and optimized code paths of executed functions.

APKLab

2026-08-03
APKLab is an integrated development environment for advanced Android reverse engineering within Visual Studio Code, combining multiple open-source tools such as Apktool, Jadx, and Frida. Its notable features include capabilities for decoding, editing, and rebuilding APK files, extensive support for Smali language, automated signing and installation of APKs, and functionality for interactive malware analysis. This tool is designed to streamline the app analysis process while leveraging the full IDE experience.

apk2gold

2026-08-03
apk2gold is an Android decompiler designed to streamline the decompilation process by combining multiple tools into a single, efficient workflow. Its notable features include the regeneration of R.* references, which improves code readability and resource identification, as well as the organization of decompiled outputs to closely resemble the original app structure. The tool is aimed at facilitating Android app introspection, making it easier for users to analyze and understand APK files.

iced

2026-08-03
Iced is a high-performance x86 instruction decoder, disassembler, and assembler that supports Intel and AMD architectures across various platforms including .NET, Rust, Python, and JavaScript. Notable features include advanced decoding speeds exceeding 250 MB/s, comprehensive instruction support with extensive formatting options, and the ability to re-encode instructions while providing detailed metadata about instruction behavior. The tool is rigorously tested against other disassemblers for accuracy and reliability, making it a robust solution for developers working with low-level x86 code.

magisk-frida

2026-08-03 Shell ★ 1437
MagiskFrida is a tool that enables the automatic execution of the Frida server on device boot across multiple root solutions, including Magisk, KernelSU, and APatch. It supports various architectures such as arm64, arm, x86, and x86_64, and provides instant updates by integrating with the official Frida build process. This tool is particularly beneficial for developers, reverse-engineers, and security researchers looking to leverage dynamic instrumentation in rooted Android environments.

lbcdec

2026-08-03
A Lua 5.1 Bytecode Decompiler written in Rust

androguard

2026-08-03 Python ★ 6218
Androguard is a comprehensive Python tool designed for analyzing Android files, including DEX, ODEX, and APK formats. Its notable features include disassembling DEX/ODEX bytecodes, a basic decompiler, dynamic analysis support via Frida, and the capability to handle Android's binary XML and resources. The tool is aimed at developers and security researchers looking to assess Android applications for vulnerabilities or conduct reverse engineering.

apkx

2026-08-03
apkx is a Python-based tool designed for decompiling Android APK files, providing a simplified interface for interacting with various dex converters and Java decompilers. Its primary use case is to facilitate reverse engineering of Android applications by automating the extraction of Java source code while allowing users to customize the decompilation process with different libraries. Notable features include support for multiple decompiler options like CFR and Procyon, and the ability to adjust converter settings seamlessly through command-line flags.

ghidra-headless-scripts

2026-08-03
The Ghidra Headless Scripts repository provides Python 2 scripts designed to automate the analysis of binaries using Ghidra's Headless Analyzer, specifically focusing on decompilation and disassembly tasks. Notable features include the `decompile_simple.py` script for generating simplified pseudo C output, the full `decompiler.py` for detailed decompilation, and the `disassembler.py` for producing assembly code, all operable via command line with user-defined project parameters and output specifications.

decomp2dbg

2026-08-03
decomp2dbg is a tool designed to facilitate synergy between static decompilation and dynamic debugging processes in reverse engineering. Its primary use case is to enable seamless synchronization of symbols and lines between decompilers such as IDA Pro, Binary Ninja, and Ghidra, and debuggers like gdb, thereby minimizing context switching and enhancing analysis efficiency. Notable features include a generic API for decompiler-to-debugger communication and support for various well-known decompilers and debuggers, allowing users to easily connect and share insights between tools.

BinAssistMCP

2026-08-03 Python ★ 49
BinAssistMCP is a comprehensive Model Context Protocol (MCP) server designed to enhance Binary Ninja's binary analysis capabilities with AI-powered reverse engineering tools. It facilitates AI-assisted tasks through dual transport support and offers an extensive suite of 44 tools, streamlining the analysis process while managing multiple binaries concurrently and providing features like guided prompts and efficient caching for improved performance.

FIDL

2026-08-03
FIDL is a Python library designed to facilitate the use of the decompiler API within IDA Pro, focusing on vulnerability research and bug hunting in binaries. It provides a set of utilities that simplify the decompilation process for reverse engineering tasks, making it accessible for both specific security assessments and wider reverse engineering applications. Notable features include easy installation via pip, support for development mode with live editing, and comprehensive online documentation.

LLM4Decompile

2026-08-03
LLM4Decompile is an advanced open-source large language model designed specifically for decompiling binary code into human-readable source code. It utilizes a two-phase process that includes structure recovery and meaningful identifier naming, enhancing the accuracy and usability of the decompiled output. Notably, the tool achieves high re-executability rates and supports various training datasets for improved performance in reverse engineering tasks.

Rikugan

2026-08-03
Rikugan is a reverse-engineering agent designed for integration with IDA Pro and Binary Ninja, leveraging a multi-provider LLM to enhance the analysis experience directly within the disassembler UI. Key features include an agentic loop for real-time interaction, over 60 tools for various reverse-engineering tasks, experimental natural language patching and deobfuscation capabilities, and robust memory management for persisting analysis findings. This tool enables users to execute complex workflows without the need to switch contexts or rely on external MCP clients.

awesome-connected-things-sec

2026-08-03 ★ 3527
The Awesome Connected Things Security Resources repository provides a comprehensive collection of security knowledge pertinent to IoT, embedded systems, industrial control systems, and automotive technologies. Its primary use case is to serve as a centralized reference for security practices and tools, featuring over 900 resources that cover various aspects of security, including hardware hacking, firmware analysis, and wireless protocols. Notable features include detailed sections on specific attack methodologies, categorized resources for easy navigation, and community engagement via platforms like Telegram and Discord.

awesome-reverse-engineering

2026-08-03
The awesome-reverse-engineering repository serves as a comprehensive collection of over 3,500 tools and 2,300 articles related to reverse engineering across multiple platforms including Windows, Linux, macOS, and Android. Its primary use case is to provide resources for security analysts and reverse engineers, focusing on topics like PE, DLL injection, and process analysis, while also categorizing tools and articles by functionality. Notable features include the inclusion of both open-source tools and informative articles, with some descriptions available in Chinese for broader accessibility.

RE-Thing

2026-08-03
RE-Thing is a comprehensive catalog of reverse engineering and binary analysis tools, primarily focused on Android and Java applications. Notable features include tools for decompiling Android APKs, analyzing bytecode, and binary analysis, such as Angr and Ghidra, enhancing the capabilities for both static and dynamic analysis. This repository facilitates developers and security researchers in their project work by providing curated resources and tool recommendations.

reverse-engineering

2026-08-03
The "Reverse Engineering" repository provides a curated collection of resources for reverse engineering, primarily aimed at enhancing skills in malware analysis and binary exploitation. It includes links to books, courses, practice challenges, and various tools such as disassemblers and hex editors, making it a comprehensive guide for both beginners and advanced practitioners in the field. Notable features include a categorized compilation of educational materials and practical exercises for real-world application.

Awesome-Binary-Analysis-Automation

2026-08-03
Awesome Binary Analysis Automation is a curated collection of tools and resources designed for automating binary analysis, vulnerability research, and reverse engineering. Its primary use case is to facilitate the analysis of binaries and firmware through various methodologies, including static and dynamic analysis, as well as machine learning techniques. Notable features include categorization of tools for decompilation, automated vulnerability detection, and scripts for firmware modification, with indicators for particularly noteworthy resources.

librepods

2026-08-03 Kotlin ★ 29606
LibrePods is a tool designed to replicate AirPods functionalities on non-Apple platforms, leveraging the proprietary protocol for communication between AirPods and Apple devices. It enables features such as noise control mode adjustments, ear detection, and battery status reporting on Linux and Android systems. Notable features include customization options for conversational awareness, automatic connections, and various control settings, ensuring users can fully utilize their AirPods outside of the Apple ecosystem.

luadec

2026-08-03
Lua Decompiler for lua 5.1 , 5.2 and 5.3

unluac

2026-08-03
unluac is a Java-based decompiler designed to convert Lua bytecode versions 5.0 through 5.4 back into human-readable Lua source code, enabling analysis and debugging of Lua applications. Notable features include multi-version support, a command-line interface for ease of use, and capabilities to handle custom opcode and type mapping for modified Lua implementations, such as xLua. The tool requires bytecode compiled with debug information and is cross-platform compatible, making it suitable for various development environments.

r2retdec

2026-08-03
r2retdec is a decompiler tool that serves as an interface between radare2 and retdec, enabling the decompilation of individual functions within binaries. It offers functionality such as generating summaries of strings, cross-references, and function calls, alongside user-friendly, mouse-interactive windows for navigation. Notably, it supports multiple architectures and provides command-line options for output customization, including Python syntax formatting.

binnavi

2026-08-03
BinNavi is a binary analysis Integrated Development Environment (IDE) designed for inspecting, navigating, editing, and annotating control-flow graphs of disassembled code, while also allowing for the management of execution traces and analysis results among teams. It prominently features integration with the yFiles graph visualization library for advanced graph rendering, and it utilizes a PostgreSQL database for storing disassemblies and other relevant data. Although the project is no longer under active development, it provides a structured environment for detailed code analysis and collaboration.

DISCOverflow

2026-08-03
DISCOverflow is an archived visualization tool designed to represent data from the binary disassembly tool @DisCo through two main components: a 2D control-flow graph viewer and a 3D visualization option. The tool leverages an OrientDB database to process disassembled code, offering detailed graphical representations that assist users in analyzing the structures of binaries, though it is no longer maintained and is not recommended for production use. Notable features include compatibility across operating systems and detailed installation instructions for both manual and Docker-based setups.

gigahorse-toolchain

2026-08-03 HTML ★ 383
Gigahorse is a binary lifter and toolchain designed for decompiling and analyzing Ethereum smart contracts by translating low-level EVM code into a higher-level, function-based three-address representation, akin to LLVM IR or Jimple. It provides a robust framework for contract analysis with optional feature sets for Datalog parsing and interactive visualization. The tool facilitates easy integration and deployment via Docker, along with comprehensive setup instructions for dependencies, making it accessible for various environments.

JADXecute

2026-08-03
JADXecute is a plugin for the JADX decompiler that enhances it with dynamic code execution capabilities, allowing users to run Java code to modify or display components of the jadx-gui output. This tool is tailored for Android reverse engineers, facilitating more efficient analysis of APK files by leveraging standard Java libraries alongside JADX's APIs. Notable features include script examples and a user-friendly interface, inspired by IDAPython, which streamline the reverse engineering process.

jd-core

2026-08-03
JD-Core is a Java decompiler library designed to convert Java bytecode back to readable Java source code, supporting versions from Java 1.1.8 to Java 12. Key features include the ability to handle modern Java constructs like lambda expressions and method references, and it serves as the core engine for the JD-GUI application. It provides a flexible API that allows users to implement custom loaders and printers for decompilation tasks.

jd-eclipse

2026-08-03
JD-Eclipse is a Java decompiler plug-in designed for the Eclipse IDE that enables users to view Java source code during the debugging process, even in the absence of complete source files. This tool features a simple installation process and customizable settings for file associations and decompilation preferences, enhancing the debugging experience by integrating seamlessly with the Eclipse environment.

jd-gui

2026-08-03
JD-GUI is a standalone graphical utility designed to decompile Java ".class" files and display their source code. Its primary use case is for developers needing quick access to Java methods and fields from compiled code, featuring an intuitive interface that allows for file browsing, drag-and-drop functionality, and support for extensions. Notable features include support for building deployable packages across different operating systems and ease of use through a simple file opening process.

Malimite

2026-08-03
Malimite is a decompiler tailored for iOS and macOS applications, specifically designed to analyze and decode IPA files and application bundles. It leverages Ghidra's decompilation capabilities to support Swift and Objective-C code, automatically decodes iOS resources, and features built-in LLM method translation. This tool is compatible across multiple platforms including Mac, Windows, and Linux, enhancing the reverse engineering efforts of security researchers.

mitmproxy2swagger

2026-08-03 HTML ★ 9595
mitmproxy2swagger is a tool designed to automate the conversion of HTTP traffic captured by mitmproxy into OpenAPI 3.0 specifications. Its primary use case is reverse-engineering REST APIs by capturing traffic during application execution, enabling developers to easily document and understand API structures. Notable features include support for merging existing schemas, handling HAR files exported from browser DevTools, and generating detailed endpoint descriptions after initial traffic capture.

Kyber

2026-08-03 Dart ★ 368
KYBER is an open-source tool designed to create private servers for STAR WARS™ Battlefront™ II (2017), enabling players to host and manage their own gaming environments. Key features include a C++ game module for client integration, a server proxy, an API service, and command-line interface tools for enhanced customization and management. Its modular architecture supports development through a monorepo structure, facilitating a collaborative approach to feature enhancements and updates.

ILSpy

2026-08-03
ILSpy is an open-source, cross-platform .NET assembly browser and decompiler that allows developers to analyze and decompile .NET binaries into readable C# code. Its notable features include a user-friendly desktop UI, integration with Visual Studio and Visual Studio Code, support for project-wide decompilation, and extensibility through plugins. ILSpy also offers advanced navigation capabilities and comprehensive assembly metadata exploration, making it a powerful tool for reverse engineering and code analysis.

PowerUp

2026-08-03
PowerUp is a comprehensive productivity tool designed for disassembly and decompilation across multiple programming languages including C#, F#, Go, Rust, and C++. Its primary use case involves monitoring source code, translating it to intermediate representations (IR), and generating assembly outputs, while offering features such as live IDE watching, a .NET JIT disassembler, and advanced interactive capabilities for C# including benchmarking and class layouts. Notable functionalities include multiple compiler support, detailed assembly documentation options, and an intuitive command-line interface for users.

retdec

2026-08-03
RetDec is a versatile retargetable machine code decompiler based on LLVM, capable of analyzing a variety of executable file formats, including ELF, PE, and Mach-O across multiple architectures. Its primary use case involves static analysis of binaries, extracting debugging information, and reconstructing high-level constructs such as functions and C++ class hierarchies. Notable features include detailed static analysis, support for both C and a Python-like output language, demangling symbols, and generating graphical representations of call and control flow graphs.

capstone

2026-08-03 C ★ 8987
Capstone is a versatile disassembly framework designed for binary analysis and reverse-engineering, catering to the security community. It supports a wide array of hardware architectures and provides a lightweight, intuitive API with detailed disassembly output and semantics of instructions, making it suitable for high-performance malware analysis and integration into various applications, including firmware and OS kernels. With native compatibility across multiple platforms and extensive language bindings, Capstone is a powerful tool for developers and security professionals.

Learning-Linux-Binary-Analysis

2026-08-03
Learning Linux Binary Analysis is a comprehensive resource designed to equip users with the techniques and knowledge necessary for analyzing ELF binaries in the context of security and reverse engineering. It covers essential topics such as UNIX virus analysis, binary patching, anti-tampering methods, and advanced forensic techniques, all tailored for the Linux environment, particularly focusing on x86 architectures. The provided code examples allow users to apply practical skills in areas like memory manipulation and tool design using the C programming language.

OverRide

2026-08-03
OverRide is a cybersecurity training tool designed to explore disassembly, binary exploitation, and reverse-engineering through a series of ten progressively challenging levels. Each level includes a reverse-engineered binary, assembly disassembly notes, and a password required to advance, encouraging users to identify and exploit vulnerabilities using tools like GDB. Notable features include hands-on challenges such as Ret2Libc attacks, format string vulnerabilities, and stack overflows, making it an effective resource for enhancing penetration testing skills.

Binary-Analysis-Cookbook

2026-08-03
The Binary Analysis Cookbook provides actionable recipes aimed at disassembling and analyzing binaries to identify security vulnerabilities. Designed for security professionals and Linux system administrators, it covers topics including ELF specifications, tools for disassembling binaries, dynamic taint analysis, and effective interpretation of analysis outputs. This resource serves as a comprehensive guide to mastering binary analysis using open-source tools in Linux environments.

luadec51

2026-08-03
Lua Decompiler for Lua version 5.1

rewolf-pcausa-exploit

2026-08-03 C++ ★ 39
The rewolf-pcausa-exploit is a Windows local privilege escalation tool targeting the PCAUSA Rawether vulnerability. Its primary use case is to enable users to gain elevated permissions within a Windows environment, exploiting specific weaknesses in the PCAUSA driver. Notable features include its focus on local escalation and detailed documentation linked for further information.

awesome-infosec

2026-08-03 ★ 108
Awesome Infosec is a curated collection of Information Security resources and tools designed to aid individuals in their studies and practices of cybersecurity. It encompasses various topics, including recon, web security, penetration testing, and exploit development, while also providing links to educational courses and labs. The continuously updated repository serves as a valuable resource for both beginners and experts in the field.

Windows-Kernel-Exploitation

2026-08-03 Python ★ 20
Windows Kernel - Exploration is a repository that provides a collection of notes, tools, and code snippets for exploiting Windows kernel drivers, aimed at both research and offensive security applications. It covers both legacy driver vulnerabilities and modern exploitation techniques, including Bring Your Own Vulnerable Driver (BYOVD) methods, while offering resources for kernel debugging, PDB analysis, and understanding core primitives related to kernel exploits. Notable features include detailed discussions on essential exploit techniques, kernel mitigations, and various tools for PDB parsing and debugging.

Writeups

2026-08-03 HTML ★ 157
The repository contains a collection of writeups detailing solutions and methodologies used in various Capture The Flag (CTF) competitions, including Hack The Box (HTB). Its primary use case is to provide insights and explanations for participants looking to learn from past challenges. Notable features include links to social media for support and engagement, as well as visual representation of stargazers over time.

awesome-cyber

2026-08-03 ★ 111
awesome-cyber is a curated repository that aggregates a diverse range of cybersecurity tools catering to red, blue, and purple team operations. This resource aims to provide an up-to-date collection of tools across various cybersecurity domains, including offensive and defensive techniques, forensics, and incident response. Notable features include organized categories for easy navigation and an open invitation for community contributions to keep the toolset relevant.

ApkClaw

2026-08-03 Kotlin ★ 13
ApkClaw is a tool that enables users to control Android devices by sending plain language messages through popular chat applications like WeChat, Telegram, and Discord. Its primary use case involves delegating tasks such as opening apps, tapping buttons, and checking status directly from a computer, leveraging an AI agent for task execution on the Android device. Notable features include multi-platform messaging support, easy setup instructions, and the ability to manage Android tasks remotely, simplifying user interactions with their devices.

capa

2026-08-03 Python ★ 6162
Capa is an advanced tool designed to analyze executable files, specifically PE, ELF, .NET modules, and shellcode, by detecting their operational capabilities. It provides detailed insights into potential functionalities, such as backdoor activities and methods of communication, while allowing interactive exploration of results via a web interface. Notable features include the ability to respond to custom rules, integration with the MITRE ATT&CK framework, and multiple output options for comprehensive analysis.

dotscope

2026-08-03 Rust ★ 25
dotscope is a high-performance, cross-platform framework designed for analyzing, reverse engineering, and modifying .NET PE executables using Rust. Its key features include efficient memory access for parsing and modifying CIL bytecode, comprehensive metadata analysis, method injection capabilities, and a rich set of tools for static analysis and deobfuscation. The tool supports native PE operations and is built with robustness in mind, providing memory safety and extensive error handling.

drakvuf-sandbox

2026-08-03 Python ★ 1333
DRAKVUF Sandbox is an automated black-box malware analysis system that operates without requiring agents on the guest operating system, utilizing the DRAKVUF engine for its core functionality. It features a user-friendly web interface for uploading and analyzing suspicious files, along with an installer that simplifies the setup process for beginners while allowing for advanced configuration by experienced users. This tool is designed to facilitate the identification of malicious files efficiently, though it requires specific hardware and software setups for optimal performance.

ghidra-cli

2026-08-03 Rust ★ 198
Ghidra CLI is a Rust-based command-line tool designed for automating reverse engineering tasks within the Ghidra framework. It features a direct communication bridge to Ghidra's JVM, enabling fast, in-memory queries and program analysis without the overhead of separate JVM invocations for each command. Notable functionalities include batch operations, flexible output formats, type system manipulation, and the ability to execute scripts, all of which enhance the efficiency of reverse engineering workflows.

HydraDragonAntivirus

2026-08-03 YARA ★ 236
Hydra Dragon Antivirus is an open-source antivirus tool primarily designed for x86-64 Windows systems, focusing on real-time protection against automated threats while avoiding the overhead of heavy signature-based detection. The tool features a minimalistic approach by utilizing key components like Owlyshield and OpenEDR, emphasizing efficiency and instant threat response without interfering with legitimate user actions. It is currently in active development, intended for expert malware analysts, and anticipates future alignment with professional testing standards.

lancelot

2026-08-03 Rust ★ 113
Lancelot is an Intel x86(-64) code analysis library designed to reconstruct control flow, facilitating detailed program analysis. It supports WebAssembly, enabling execution in browser environments, and includes a Zydis-based disassembler for enhanced disassembly capabilities. Notable features include integration with Cranelift for advanced code generation and the ability to create JavaScript bindings for easy deployment in Node.js and browser contexts.

LIEF

2026-08-03 C++ ★ 5551
LIEF is a cross-platform library designed for parsing, modifying, and abstracting executable formats such as ELF, PE, and Mach-O, along with others like COFF, OAT, and DEX. Notable features include a user-friendly API for accessing format internals, support for runtime information, debugging data, and disassembler functionality for multiple architectures. The library provides interfaces for various programming languages including C++, Python, Rust, C, and Node.js, making it highly versatile for developers in the cybersecurity domain.

PE-Library

2026-08-03 C++ ★ 22
PE Library is a modern C++ library focused on parsing and manipulating Windows Portable Executable (PE) files, supporting both PE32 and PE32+ formats. Key features include comprehensive access to PE file headers and sections, utilities for address conversions, and specific structures like import/export tables and resource directories. The library emphasizes performance and simplicity, and it includes a fuzzer that has been utilized to enhance its robustness by identifying and resolving parsing edge cases.

procscope

2026-08-03 C ★ 35
procscope is an eBPF-based process tracer for Linux that enables real-time observation of process behavior, including lifecycle events, file activity, and network connections, with minimal overhead and configuration. It is primarily designed for security researchers and incident responders to trace malware behavior and audit container workloads without the complexities of traditional monitoring tools like EDR. Notable features include support for various process-related events, file operations, and privilege transitions, allowing users to effectively monitor and analyze runtime activity.

rust-malware-gallery

2026-08-03 ★ 232
The Rust Malware Sample Gallery is a curated collection designed to assist malware reverse engineers by providing samples of malware written in the Rust programming language. Its primary use case is to enhance the understanding and skills necessary for reversing Rust binaries, particularly as malicious software in Rust becomes increasingly prevalent. Notable features include links to downloadable samples from reputable sources and technical writeups that explore various malware families, offering insights into their characteristics and behaviors.

stringsifter

2026-08-03 Python ★ 759
StringSifter is a machine learning tool designed for ranking strings to enhance malware analysis efficiency. It mimics GNU binutils' `strings` functionality while providing additional capabilities like ranking strings based on relevance, supporting batch processing, and offering customizable output options. Notably, it integrates with various input sources, making it adaptable for extracting insights from memory dumps and obfuscated binaries.

ai-reverse-engineering

2026-08-03 Python ★ 154
Rev·Deck is a localized static-analysis workstation that integrates Ghidra with an AI-driven web interface for reverse engineering binaries. It allows users to browse deterministic evidence from analyzed binaries without executing them, while an AI assistant provides fact-based responses citing specific evidence. This tool supports various LLM backends and enables secure, efficient analysis with a user-friendly interface.

alkahest

2026-08-03 Rust ★ 88
Alkahest is a tool designed to facilitate the analysis and transformation of shader code, specifically targeting optimization and adaptability for game development. Its primary use case lies in improving visual fidelity and performance in rendering engines, particularly for projects inspired by the technological advancements in games like Destiny 2. Notable features include support for multiple shader languages and an extensive library of resources linked to graphics technology in the gaming industry.

android-frida-hooks

2026-08-03 JavaScript ★ 11
Android Frida Hooks is a collection of Frida scripts designed for device spoofing, integrity bypass, and exploring application tampering detection on Android devices for educational and security research purposes. It includes two versions: "full stealth," which encompasses extensive Java and native hooks for deep coverage against aggressive app checks, and "clean and minimal," focusing on essential spoofing while maintaining a lower detection footprint. Notable features include device ID generation, process list filtering, Play Integrity token faking, and safety mechanisms against common detection methods, making it suitable for a range of security testing scenarios.

attack-shark-x11-driver

2026-08-03 TypeScript ★ 26
The Attack Shark X11 Driver is a TypeScript library designed for configuring various settings of the Attack Shark X11 gaming mouse on cross-platform environments, with an emphasis on Linux. It allows users to adjust DPI, remap buttons, create macros, control lighting, and set polling rates while providing USB HID communication capabilities. Notable features include extensive customization options, support for multiple operating environments like Node.js and Bun, and an active open-source community for ongoing development and enhancements.

Awesome-Bootkits-Rootkits-Development

2026-08-03 HTML ★ 263
The Awesome Bootkits & Rootkits Development repository provides a comprehensive collection of resources focused on the development of bootkits and rootkits, targeting both BIOS/UEFI specifications and Windows kernel intricacies. Notable features include analysis tools, tutorials, source code examples for various operating systems, and insights into kernel security mechanisms such as Driver Signature Enforcement and Kernel Patch Protection. This repository serves as a vital resource for security researchers and developers interested in low-level malware development and analysis.

awesome-game-file-format-reversing

2026-08-03 Python ★ 207
The "Awesome Game File Format Reversing" repository is a curated collection of tools, documentation, and resources aimed at developers and modders for reverse engineering and manipulating various video game file formats. It encompasses a wide range of asset types, including models, textures, audio, and scripts, providing essential tools for extraction, conversion, and analysis. The repository also encourages community contributions, fostering a collaborative environment for enhancing game modding and development practices.

bindiff

2026-08-03 Java ★ 3147
BinDiff is an open-source binary file comparison tool designed for vulnerability researchers and engineers, enabling them to swiftly identify differences and similarities within disassembled code across various architectures such as x86, ARM, and PowerPC. It facilitates the identification of identical functions, the porting of function names and comments between different binary versions, and highlights changes in function variants, thereby enhancing the efficiency of vulnerability analysis and knowledge transfer. Notable features include support for multiple disassemblers like IDA Pro, Binary Ninja, and Ghidra, alongside a user-friendly visual interface for detailed analysis.

bn6f

2026-08-03 Assembly ★ 40
The dism-exe/bn6f tool is a disassembly of the MegaMan Battle Network 6: Cybeast Falzar game, designed for developers to analyze and modify the game’s code and assets. Its primary use case is for ROM hacking and community-driven modding projects. The repository includes the ROM build with a specific SHA1 hash, facilitating easy setup and contributions from other developers.

ChaseHQ

2026-08-03 C ★ 35
Chase H.Q. is a reverse-engineered project for the ZX Spectrum, featuring a comprehensive disassembly and a C implementation of the original game. It utilizes SkoolKit to generate detailed assembly listings and includes a human-readable C reimplementation with SDL3 integration, allowing users to explore the game's mechanics through both disassembly and functional re-creation. Notable features include support for the 128K version, a well-structured Makefile, and the ability to create custom cheat codes via POKEs.

DarkRide

2026-08-03 TypeScript ★ 11
DarkRide is a self-hosted, AI-native workbench tailored for mobile reverse engineering, primarily focusing on Android devices. It provides comprehensive features such as live device control, APK analysis, HTTPS traffic capture, and Frida instrumentation, all accessible through a unified web interface with a TypeScript automation engine and plugin system for extensibility. Additionally, it includes advanced functionalities like an AI agent for tool interaction, session history management, and a robust proxy pool for enhanced pentesting capabilities.

debugger

2026-08-03 C++ ★ 329
The Binary Ninja Debugger is a C++ plugin designed for the Binary Ninja reverse engineering platform, facilitating debugging across multiple operating systems and target environments. It supports local and remote debugging for macOS, Linux, and Windows, as well as compatibility with various debugging protocols such as GDB and LLDB. Notable features include support for iOS debugging, Windows kernel debugging, and integration with virtualization tools like QEMU and VMware.

decksurf-sdk

2026-08-03 C# ★ 31
DeckSurf SDK is an unofficial Software Development Kit for interfacing with Stream Deck devices, designed for .NET applications using C#. This SDK allows developers to manage connected Stream Decks by providing functionalities such as button press event handling, image setting for buttons, and brightness control, while also supporting structured error handling for device communication issues. Currently in its alpha stage, the SDK is actively developed, indicating potential breaking changes prior to its 1.0.0 release.

Deroute

2026-08-03 C# ★ 75
Deroute is a specialized tool designed for reverse engineering integrated circuits and printed circuit boards by facilitating the management of intricate wire connections. Its primary use case involves the organization and visualization of interconnected elements, such as wires and various IC components, through a custom control called EntityBox. Notable features include a dual-coordinate system for displaying vector data and the ability to save and load entity collections in XML format.

dexdec

2026-08-03 Rust ★ 78
DexDec is a native reverse-engineering tool designed for decompiling and analyzing complex Android applications, capable of handling large APK files and producing high-fidelity Java or Kotlin code. Its notable features include fast project opening and responsive exploration, symbol-aware navigation, and seamless integration with AI agents for enhanced code analysis. Additionally, it supports a professional workspace with customizable themes and reversible renaming capabilities, making it an efficient choice for developers and security analysts.

eblenix_csgo_public

2026-08-03 C++ ★ 31
eblenix_csgo_public is a hacking tool for Counter-Strike: Global Offensive, designed primarily for educational purposes in game hacking. It enables users to inject custom functionalities into the game by compiling the source code with Visual Studio, utilizing dependencies such as Minhook and Lua. Notable features include an injector executable that facilitates the integration of modifications during gameplay.

fear-vr

2026-08-03 C++ ★ 39
F.E.A.R. VR is an open-source virtual reality mod designed for the single-player base version of F.E.A.R. 1.08, offering immersive gameplay features such as native stereo world rendering, headtracking, and comprehensive controller support through OpenXR. Notable capabilities include a world-locked menu, a VR-optimized HUD, and flexible first-person perspective options, allowing for enhanced player interaction within the game environment. The mod can be installed easily alongside the existing F.E.A.R. files, catering to users with compatible VR setups on Windows 10/11.

gbfr-ultrawide

2026-08-03 C++ ★ 24
GBFRUltrawide is an x64 ASI plugin designed to enhance the gameplay experience of Granblue Fantasy: Relink v2.0.3 by providing custom resolution and aspect ratio fixes specifically for ultrawide displays (21:9 / 32:9). Notable features include a corrected HUD layout, full-screen visual effects, and various settings for adjusting the field of view and camera distances, ensuring optimal display performance without distortion. Additionally, it offers detailed logging for troubleshooting and maintaining compatibility with future game updates.

ghidra

2026-08-03 Java ★ 74134
Ghidra is a comprehensive software reverse engineering (SRE) framework developed by the National Security Agency, designed to analyze compiled code across multiple platforms, including Windows, macOS, and Linux. Notable features include disassembly, decompilation, extensive graphing capabilities, and user-customizable scripting options in Java or Python, making it suitable for both manual and automated code analysis. Ghidra supports various processor architectures and executable formats, facilitating deep insights into vulnerabilities and malware investigation in cybersecurity contexts.

ghidra-hexagon-sleigh

2026-08-03 Python ★ 41
The Ghidra Hexagon SLEIGH tool provides an implementation of the Qualcomm Hexagon "QDSP6" architecture for the Ghidra reverse engineering framework, enabling comprehensive disassembly of multiple Hexagon instruction versions and HVX support. Notable features include support for hardware loops, constant extenders, and Pcode for numerous operations, alongside specialized scripts for decompression and log message annotation. While modern Ghidra versions offer native Hexagon support, this plugin maintains unique functionalities and caters to specific disassembly needs for advanced users.

gotohp

2026-08-03 Go ★ 441
Gotohp is an unofficial desktop GUI client for Google Photos that facilitates the upload of media files with a focus on user configurability and ease of use. Its notable features include drag-and-drop interface, real-time progress tracking, and support for both individual and recursive uploads, while also allowing advanced command-line interactions for streamlined workflows. The tool supports Apple Live Photos pairing and provides robust credential management, making it a versatile solution for users looking to manage their photo library effectively.

hl2sdk

2026-08-03 C++ ★ 461
Half-Life 2 SDK Mirrors

IDACLI

2026-08-03 Python ★ 42
IDA-CLI is a command-line interface for IDA Pro and Hex-Rays that allows AI agents to interact with IDA databases directly via a low-latency JSONL protocol, bypassing traditional GUI and middleware constraints. Its primary use case is to facilitate unrestricted execution of IDAPython code for enhanced analysis capabilities, featuring persistent session management, built-in caching, and integration with agent frameworks, enabling features like parallel analysis and dynamic database modifications. Notable functionalities include the ability for agents to execute arbitrary IDAPython commands, simplified installation of agent skills, and support for effective multi-agent collaboration.

IW3SR

2026-08-03 C++ ★ 18
IW3SR is a client modification for Call of Duty 4 that enhances gaming performance and experience through features such as an in-game GUI, a runtime plugin system, and advanced movement physics. Notable functionalities include support for various movement styles, offline shader playback, and integrated video playback capabilities. This tool aims to provide players with improved gameplay mechanics and customization options while maintaining compatibility with existing game environments.

j5-ev-dashboard

2026-08-03 HTML ★ 19
The J5 EV Dashboard is a self-hosted telematics solution designed for Jaecoo J5 EV vehicles, providing users with comprehensive insights into vehicle performance metrics such as battery status, range, efficiency, and charging sessions. This mobile-first Progressive Web App (PWA) allows users to access real-time data from their own car while also offering features like a trip planner and an interactive EV charger map. Notably, it guarantees high accuracy in charge-cost reporting, closely matching users' receipts, and is designed to operate exclusively with the owner's vehicle data.

jshookmcp

2026-08-03 TypeScript ★ 1965
@jshookmcp/jshook is an MCP server designed for AI agents, offering over 600 tools across 34 domains primarily for JavaScript analysis and security research. Its notable features include AI-driven deobfuscation and crypto detection, full-stack browser automation with anti-detection capabilities, network interception, and a dynamic reverse engineering toolchain. The tool allows for efficient session and resource management, enabling multiple clients to share a single daemon instance while maintaining isolated sessions.

kaitai_struct

2026-08-03 Shell ★ 4660
Kaitai Struct is a declarative language designed for describing binary data structures like file formats and network packet formats. Its primary use case is simplifying the parsing and representation of binary data by allowing a single format description (.ksy file) to be compiled into source files in various programming languages, thereby providing an easy-to-use API for accessing the data. Notable features include support for multiple programming languages, a visualizer for debugging format definitions, and a rich collection of pre-existing format descriptions.

mcrit

2026-08-03 Python ★ 103
The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework designed to streamline the implementation of the MinHash algorithm for code similarity analysis, specifically targeting disassembled function comparisons. It integrates with disassembly reports from SMDA and features both a REST API for server interaction and a command-line interface (CLI) for user operations, with persistent data storage facilitated by MongoDB. Notably, MCRIT allows for easy deployment through Docker, ensuring compatibility across its components.

MoovitPatcher

2026-08-03 Python ★ 16
A patcher for the moovit application to unlock premium features and removed ads.

MQReawakened

2026-08-03 C# ★ 93
MQReawakened is a community-driven server emulator for the game MQ, developed entirely from scratch in C#. Its primary use case is to allow users to host their own servers while faithfully recreating the game's original experience from earlier builds. Notable features include a fully integrated server architecture with support for custom setups, and the project adheres to legal constraints by requiring users to provide their own game assets and DLLs.

mtkview

2026-08-03 Rust ★ 15
mtkview is a tool designed for loading GFH preloader binaries and MTK Little Kernel partitions within the Binary Ninja environment. Its primary use case is to facilitate the analysis of MTK firmware binaries by providing support for preloader and LK formats. Notable features include integration with Binary Ninja, allowing users to select and analyze these specific binary types, and the ability to build and install the tool manually from the source.

Multivoid

2026-08-03 C++ ★ 23
Multivoid is a standalone mod designed to introduce drop-in co-op functionality to the single-player game Voices of the Void without modifying original game files. It supports up to four players via LAN or Internet and offers features such as seamless mid-game joining, 3D positional voice chat, and a comprehensive synchronization system for various game mechanics. The project is currently in its alpha phase, focusing on establishing a solid multiplayer foundation and ensuring game systems are accurately synced.

native-predicate-solver

2026-08-03 C++ ★ 52
The Native Predicate Solver is a C++ plugin for Binary Ninja that efficiently removes opaque predicates from binary functions, thereby optimizing decompilation and analysis. It leverages multi-threading for parallel function processing and conducts iterative analysis to ensure comprehensive removal of constant conditional branches. The tool is designed for speed and performance, making it particularly effective for managing large binaries.

nge_2_re

2026-08-03 Python ★ 15
The EVA-zh-Hans/nge_2_re project is focused on creating a comprehensive and reproducible Chinese localization patch for the PSP game "Neon Genesis Evangelion 2: The World Created." It includes notable features such as text structure parsing, translation management, and automated patch building, enabling it to successfully replicate the game's intricate internal mechanics and narrative elements. The project leverages advanced technologies like machine translation and relational database storage for efficient handling of translation tasks.

open-apollo

2026-08-03 C ★ 58
Open Apollo is an open-source project that provides Linux drivers and tools for Universal Audio's Apollo Thunderbolt and USB audio interfaces, enabling full duplex audio routing, preamp and monitor control, and system integration. Key features include comprehensive support for multiple sample rates, low-latency audio capture and playback, a DSP mixer with audio effects, and compatibility with PipeWire for seamless audio management. This experimental project is actively developed to enhance audio interface functionality on Linux but is not yet ready for production use due to potential stability issues.

OpenFusion

2026-08-03 C++ ★ 416
OpenFusion is a reverse-engineered server for the online game FusionFall, enabling players to access and play versions `beta-20100104` and `beta-20111013`. The tool supports easy installation via a launcher or standalone zip file and allows users to host their own servers with customizable options for IP and game version. Notable features include automatic progress saving and support for Linux through Wine, making it accessible to a wider range of users.

openskp

2026-08-03 Python ★ 34
OpenSKP is an open-source, cross-platform parser for SketchUp (`.skp`) binary files that allows developers to access and manipulate 3D model data programmatically without the need for the SketchUp application or its SDK. It supports both modern and legacy file formats, offering features such as 3D geometry extraction, dynamic component handling, scene baking, and export capabilities to various formats including GLB and OBJ. Built in multiple programming languages, it emphasizes low-memory parsing and includes comprehensive observability for error management.

pokeheartgold

2026-08-03 Assembly ★ 574
This repository features a work-in-progress disassembly of the Pokémon HeartGold and SoulSilver ROMs, facilitating modifications and enhancements for developers. Its primary use case is enabling developers to analyze and modify game code, with notable features including the ability to build specific ROM versions tailored for testing or development.

protocol

2026-08-03 Dart ★ 15
OpenStrap protocol is a pure Dart package designed for decoding raw byte data from wearable devices, specifically targeting historical records and command/event processing without any external dependencies. Its notable features include byte-level framing, CRC checks, and the ability to parse a variety of record types, such as R24 for heart rate and wearable metrics, all while ensuring that data remains on-device with no reliance on cloud services. This tool is primarily used for reading and interpreting data from personal tracking bands, supporting developers in building applications that analyze this data locally.

Pyamoto

2026-08-03 Python ★ 12
Pyamoto is an enhanced level editor for the game Super Mario Maker, designed as an advanced fork of the original Miyamoto editor, primarily aimed at improving functionality and user experience. It features a streamlined installation process, supports automated releases and Homebrew installation for macOS, and includes comprehensive usage documentation on its wiki. Notably, Pyamoto encourages community contributions and offers a dedicated environment for developers to collaborate and contribute to the project.

pylabview

2026-08-03 Python ★ 147
Pylabview is a set of Python tools designed for extracting, modifying, and recreating LabVIEW RSRC files, such as VIs and CTLs. Its primary use case involves enabling batch processing of these files, allowing users to make bulk modifications outside the LabVIEW GUI, and facilitating the recovery of files that LabVIEW cannot read. Notable features include the capability to extract RSRC files into a structured format for easier manipulation, support for binary and text extraction, and the generation of outputs that aim for binary-level fidelity to the originals, despite some known exceptions.

quokka

2026-08-03 Python ★ 226
Quokka is a binary exporter that facilitates the manipulation of binary files without the need for ongoing disassembly after the initial export, supporting disassembly backends like IDA Pro, Ghidra, and Binary Ninja. It provides a clean interface by abstracting the APIs of various disassemblers and generates .quokka files, which can be loaded for further processing. Notable features include the ability to export in LIGHT mode for block-level data export and the upcoming FULL mode for comprehensive instruction and operand exporting.

Reach

2026-08-03 C++ ★ 29
Reach is a decompilation project for Halo Reach that enables developers to examine and modify the game's code structure. Its primary use case is to facilitate reverse engineering for educational and modding purposes, although it requires a legitimate copy of the game to function. Notable features include detailed progress tracking for both code and data decompilation, alongside support for specific debug tag versions.

Reversecore_MCP

2026-08-03 Python ★ 194
Reversecore MCP is an AI-powered server designed to facilitate reverse engineering and security analysis by integrating 120 analysis tools into a unified interface. It utilizes natural language processing to allow AI assistants to perform tasks like malware analysis, vulnerability research, and source code auditing, significantly simplifying the interaction with complex command-line tools. Notable features include structured tool results that AI can reason about and chain into follow-up queries, making it highly efficient for rapid security assessments and investigations.

Rootkits-Development-Starter-Pack

2026-08-03 C ★ 23
The Rootkits Development Starter Pack provides a collection of Windows kernel-mode driver examples that demonstrate fundamental rootkit functionalities such as thread creation, process callbacks, and filesystem filtering. Its primary use case is to educate users on kernel-level development and guide them through creating modular steps for advanced rootkit development. Notable features include a comprehensive set of proof-of-concepts, detailed instructions on building drivers, and essential information on Windows kernel operations and security measures.

snowboardkids2-decomp

2026-08-03 C ★ 186
The Snowboard Kids 2 decompilation project provides an environment for reverse-engineering the classic Nintendo 64 game by extracting game assets from an existing ROM and combining them with C code to create an identical ROM. Its primary use case is for developers and enthusiasts interested in studying or modifying the game, and it features support for building on Debian/Ubuntu and macOS, with dependencies for C code compilation and asset extraction. The project is strictly non-commercial and emphasizes community contributions for code documentation and compatibility improvements.

Spice86

2026-08-03 C# ★ 657
Spice86 is a PC emulator designed for reverse engineering and modification of real mode DOS programs where source code is unavailable. It methodically generates a self-contained C# project from the executed code's Control Flow Graph (CFG), facilitating gradual rewriting from low-level assembly to higher-level code, while also supporting Ghidra integration for deeper static analysis. The tool operates across multiple platforms (Windows, macOS, and Linux) and provides extensive runtime data dumps to aid in the analysis and reconstruction process.

tsa

2026-08-03 Kotlin ★ 32
TSA (TON Symbolic Analyzer) is a static analysis tool designed for evaluating smart contracts on the TON blockchain through symbolic execution. Its primary use cases include detecting potential runtime errors, generating regression tests, and identifying malicious contracts, with the capability to analyze any language compiled to TVM bitcode format. Notable features include its test generation capabilities and detailed analysis of integer processing issues and data handling in smart contracts.

Tsuru

2026-08-03 C++ ★ 32
Tsuru is a platform designed for modders of New Super Mario Bros. U, providing a comprehensive toolset and API for custom code development. It includes numerous code examples and pre-made patches to assist new modders while aiming to unify various coding projects for easier access. The tool supports the standalone version 1.3.0 of the game and offers a patch installer for seamless integration.

unicorn

2026-08-03 C ★ 9282
Unicorn Engine is a versatile, multi-platform CPU emulator framework that supports various architectures, including ARM, x86, and MIPS, enabling users to execute and analyze software in a controlled environment. Its notable features include a simple and lightweight API, high performance through Just-In-Time compilation, and support for instrumentation and thread-safety, making it ideal for security research, software debugging, and development tasks across different programming languages.

VM-Packages

2026-08-03 PowerShell ★ 245
The Mandiant VM-Packages repository provides PowerShell scripts that facilitate the installation and configuration of tools for binary analysis environments, specifically FLARE VM and CommandoVM. Notable features include automated package building and testing using GitHub Actions, a public MyGet package feed for easy access, and community contributions for package development and improvement. This setup enhances transparency and reduces manual maintenance for users, ensuring that tools can be effortlessly integrated into their virtual machine environments.

WhatsAppPatcher

2026-08-03 Java ★ 253
A patcher that decompiles WhatsApp APK, patches the smali, recompiles and signs it.

areclaw

2026-08-03 JavaScript ★ 62
areclaw is an automated command-line environment designed for Android application security analysis, enabling tasks such as decompilation, traffic interception, dynamic instrumentation, secret scanning, and API discovery. It leverages an AI-driven orchestrator, Claude Code, to streamline the analysis process, and includes an automated installer for essential tools, a structured workspace for outputs, and various utility scripts for enhanced interaction and reporting.

Awesome

2026-08-03 Shell ★ 171
Awesome is an open-source repository that aggregates a variety of tools and resources across multiple domains including communication, development, finance, and information security. Its primary use case is to provide users with a centralized catalog of high-quality software, libraries, and educational resources, aiding in quick access to knowledge and tools. Notable features include a structured table of contents for easy navigation and a focus on simplicity, readability, and collaboration best practices.

Bullseye

2026-08-03 C++ ★ 15
Bullseye is a reverse engineering tool specifically designed for the game Resident Evil: Dead Aim, facilitating the extraction of game assets such as audio files, model data, and textures, with ambitions of achieving full decompilation. It supports meticulous matching of the original executable by reconstructing the binary byte-for-byte, ensuring that every loadable portion is accurate, a characteristic vital for developers and modders aiming to analyze or modify the game's code. Key features include a structured build process utilizing an EE binutils toolchain and compatibility with original game dumps, allowing users to verify the integrity of their builds against the original release.

capa-rs

2026-08-03 Rust ★ 19
capa-rs is a file capability extractor designed to analyze executable files, including PE, ELF, Mach-O, and .NET binaries. It identifies specific capabilities and behaviors, such as potential backdoor functions or security attributes like ASLR and NX, while providing a command-line interface for ease of use. The tool is a Rust implementation of the original Python capa, offering high accuracy and customizable security checks, making it suitable for in-depth malware analysis and binary security assessments.

decompose

2026-08-03 Go ★ 139
Decompose is a reverse-engineering tool designed for analyzing Docker environments by extracting and visualizing all network connections from containers. It supports multiple output formats including graphviz dot, structurizr DSL, and CSV, providing detailed insights into container interconnections, including ports and statistics. Notable features include high-speed scanning capabilities, deep inspection of process connections, and a single-binary deployment for cross-platform compatibility.

GD

2026-08-03 C++ ★ 29
The Geometry Dash (1.710) decompilation project aims to recreate the core functionality of the game using an older version of the cocos2d-x framework to address limitations present in later versions, such as broken screen orientations and lack of slope features. Currently in a work-in-progress state, it supports multiple platforms, including iOS, Android, macOS, Windows, and Linux, while facilitating community contributions and providing SHA-1 file hashes for various builds.

gitreverse

2026-08-03 TypeScript ★ 1867
GitReverse transforms public GitHub repositories into concise synthetic user prompts suitable for various language models, enabling users to generate code from the project context. Key features include the extraction of repository metadata and file structure, as well as support for multiple LLM providers, allowing for flexible integration and enhanced user experience in coding projects.

HBC-Tool

2026-08-03 Python ★ 28
HBC-Tool is a Hermes bytecode disassembler and assembler specifically designed for React Native bundles, facilitating reverse engineering, inspection, and patching of applications that utilize the Hermes engine. Key features include the ability to disassemble bytecode into a human-readable format (HASM), modify the contents, and reassemble valid Hermes bundles, with options for enhanced performance through native C++ acceleration and fast JSON processing. The tool supports multiple Hermes bytecode versions and offers a command-line interface for various operations such as disassembly and assembly.

khdays-decomp

2026-08-03 C ★ 27
khdays-decomp is a matching decompilation project for Nintendo DS's *Kingdom Hearts 358/2 Days*, aiming to produce C source code that can be compiled into an identical binary as the original game. Currently in early development, it reports progress by tracking the count of fully decompiled C functions and distinguishing between real C implementations and temporary ASM placeholders. Notable features include detailed progress metrics and separate handling for SDK/library byte-match identifications.

kUML

2026-08-03 Kotlin ★ 22
Architecture that compiles. Kotlin DSL for UML 2.x, SysML 2 and C4 diagrams-as-code — CLI, Compose Desktop, IntelliJ & Obsidian plugins, Asciidoctor extension on Maven Central, ELK layout, reverse engineering (Java/Kotlin), XMI import/export, plugin SPI. Apache-2.0.

llm4free

2026-08-03 Python ★ 357
LLM4Free is a versatile Python toolkit that provides access to over 40 AI models, web search capabilities, and image and voice generation, all through a unified interface that mimics the OpenAI SDK. Its notable features include a built-in free tier for various models, multi-provider support with automatic failover, and an OpenAI-compatible server, allowing for seamless integration and development. The tool is fully typed and documented, making it user-friendly for developers.

mgbdis

2026-08-03 Assembly ★ 318
mgbdis is a Game Boy ROM disassembler that converts ROM files into assembly code compatible with the RGBDS assembler. It supports multi-bank ROMs and utilizes symbol files to define regions of code, data, and other elements, enhancing disassembly accuracy. Additional features include outputting makefiles for ROM rebuilding and generating image files from graphical data blocks.

MikuTrace

2026-08-03 Rust ★ 36
traceMiku is an instruction-level dynamic tracing and runtime analysis tool designed for ARM64 Android devices. It captures real execution paths and provides various analysis features, including control flow graphs (CFG), call trees, taint tracking, and memory queries. Notably, it integrates with Frida for data collection and supports structured JSON output for automated analysis, complementing static tools like IDA and Ghidra.

open-claude-in-chrome

2026-08-03 HTML ★ 199
Open Claude in Chrome is an open-source reimplementation of the official Claude in Chrome extension, providing complete web navigation without the restrictions of an allowlist. It supports any Chromium-based browser and maintains identical performance and feature parity, offering all 18 MCP tools while eliminating any blocked domains. This tool primarily enhances browser automation capabilities by allowing users to access a wider range of websites that the original extension restricts.

OpenTestDriveUnlimited

2026-08-03 C++ ★ 110
Open Test Drive Unlimited (OpenTDU) is a source port for the PC version of Test Drive Unlimited, aimed at enhancing compatibility with modern systems by addressing issues related to AI, rendering, and security while providing cross-platform support. This tool allows users to run the game on Windows, Linux, and macOS, necessitating a legal copy of the original game assets. Notable features include a debug menu, command line options for various game modes, and a structured approach to ongoing project development status.

sa2

2026-08-03 C ★ 641
Sonic Advance Trilogy (SAT-R/sa2) is an ongoing decompilation project focused on the Sonic Advance series, specifically Sonic Advance 1 and 2, with plans for Sonic Advance 3. The tool provides a fully cross-platform and matching C codebase transcribed from the original ROMs, enables compilation for multiple platforms including Windows and PlayStation, and features comprehensive extraction of audio and graphic assets alongside detailed documentation of game mechanics. Notably, it is still under active development, with a significant portion of the original functionality and metadata already extracted and converted.

Severed-Chains

2026-08-03 Java ★ 514
Severed Chains is a tool designed to reverse engineer the classic game Legend of Dragoon into a high-level language, specifically Java, while offering a modding API for customization. The project features a fully functional game engine with no known crashes, comprehensive controller support, and an automatic update mechanism that preserves user data. Users can enhance their gameplay experience through a variety of controller options and GPU preference settings, making the tool suitable for both players and mod developers.

skyrim_vr_address_library

2026-08-03 Python ★ 25
The Skyrim VR Address Library is a specialized tool that facilitates the conversion of Skyrim Special Edition (SSE) mod addresses to their corresponding Virtual Reality (VR) addresses, enabling modders to adapt existing mods for use in Skyrim VR. It provides a collection of CSV files that serve as a community resource for identifying and mapping addresslib IDs, along with automated and manual verification of addresses to ensure compatibility. Notable features include a comprehensive database for address mapping, release CSV generation for plugin integration, and analysis CSVs to assist in tracking changes and maintaining accurate mappings across various Skyrim versions.

slicer

2026-08-03 Svelte ★ 161
Slicer is a modern Java reverse engineering tool designed to operate in a web environment, offering disassembly and decompilation of Java class files through various decompilers like CFR and Procyon. Its notable features include a multi-pane workspace for simultaneous file viewing, graph visualizations of code structures, bytecode-level search capabilities, and a JS scripting API for enhanced functionality. Ideal for quickly examining class files without local setup, Slicer caters to users seeking a straightforward and accessible reverse engineering experience.

TombExtract

2026-08-03 C# ★ 24
TombExtract is an open-source savegame manager specifically designed for remastered versions of Tomb Raider I-VI, enabling users to import, manage, and convert savegames across different platforms such as PC, PS4, Android, and Nintendo Switch. Notable features include savegame management (deletion, reordering), platform and patch conversion, and the ability to create new savegames via level selection. The tool ensures compatibility across various gaming platforms and incorporates automated patch detection to facilitate seamless savegame conversions.

Unreal-Library

2026-08-03 C# ★ 473
UELib is an API designed for parsing and deserializing Unreal Engine game package files, such as .UDK and .UPK formats. Its primary use case is to decompile UnrealScript byte-code and reconstruct the original source from various Unreal data classes. Notable features include support for deserializing multiple Unreal asset types like textures, sounds, and fonts, as well as the ability to manage and initialize package objects efficiently.

vanmoof-tools

2026-08-03 C ★ 50
vanmoof-tools facilitates the reverse engineering of VanMoof S3/X3 electric bike firmware, providing utilities for analyzing various firmware images from multiple microcontrollers used in the bike's components. Notable features include detailed specifications for firmware structure, including boot loader and image header formats, CRC calculation methods, and support for different firmware generation containers. The toolset is designed to operate on Linux, macOS, or Raspberry Pi, making it accessible for users across various platforms.

VanMooof-Module

2026-08-03 Go ★ 18
The VanMooof-Module ES3 is a specialized tool designed for interfacing with and extracting information from the MX25L51245GMI-08G-TR SPI Flash Chip used in VanMoof electric bicycles. Its primary use case includes reading and writing BLE keys, managing firmware updates, and performing detailed analyses of logs and sound files, which can help in troubleshooting and enhancing system performance. Notable features include authentication key extraction, firmware encryption/decryption, BLE permission inspection, and support for uploading firmware via y-modem.

xiaomi-hyperos-bootloader-unlock

2026-08-03 Python ★ 26
Xiaomi MTK Bootloader Unlock is a tool designed to bypass the Dual-Layer Lock Verification for Xiaomi MTK devices running HyperOS or MIUI14+. It enables the unlocking of the bootloader by erasing a specific magic string stored in the Replay Protected Memory Block (RPMB), thus allowing the device to revert to the seccfg unlock state. The tool requires specific hardware conditions and careful execution to prevent common pitfalls associated with USB connections during the unlocking process.

yap

2026-08-03 C++ ★ 28
Yet Another Packer (YAP) is a tool designed for the obfuscation and protection of x86_64 Windows PE applications, such as executables and DLLs, specifically excluding C# files. Its primary use case focuses on enhancing application security through a packer that encapsulates the original application to hinder static and dynamic analysis, as well as a reassembler that mutates and reassembles code to further obscure its functionality. Notable features include anti-debugging and anti-dumping mechanisms, alongside an SDK for seamless integration within protected applications.

adobo

2026-08-03 Kotlin ★ 241
Adobo is a patching tool designed for enhancing the functionality of Android applications like YouTube and Reddit through the Morphe framework. Its primary use case involves modifying apps to block ads, remove unnecessary permissions, and introduce privacy-focused features. Notable capabilities include disabling tracking, enabling incognito modes for input methods, and extensive customization options for popular apps.

AGaMEMnon

2026-08-03 Python ★ 46
AGaMEMnon is an SDK that facilitates the synthesis and generation of flashable bitstreams for the AG32 microcontroller and its integrated FPGA fabric, enabling users to leverage a fully open toolchain without vendor binaries. It allows for Verilog-based development, providing functionalities such as synthesis, placement, routing, and programming, effectively serving as an IceStorm-like solution tailored to this unique RISC-V and FPGA combination. Notable features include support for real hardware peripherals and flexible integration of custom logic on the FPGA, making it a versatile tool for embedded systems development.

Aidyn

2026-08-03 C++ ★ 38
Aidyn is a decompilation project for the Nintendo 64 game Aidyn Chronicles: the First Mage, aimed at analyzing the game's internal mechanics and potentially porting it to modern platforms. The repository includes symbolic tables, pseudocode of source files, and headers, enabling insights into the game's structure and functionality. Despite challenges in producing usable code due to compiler limitations and the nature of the original programming, the project explores various porting avenues to enhance performance and modernize gameplay.

Android-Mem-Kit

2026-08-03 C ★ 15
Android-Mem-Kit is a lightweight C library designed for Android security research, offering functionalities such as memory patching, function hooking, and symbol resolution. Notable features include integration with ShadowHook for inline function hooking, XDL for dynamic linker bypassing, and SLJIT for platform-independent JIT code generation, all optimized for minimal overhead and ease of use in native Android applications.

APKdevastate

2026-08-03 C# ★ 60
APKdevastate is a Windows application designed for the security analysis of Android APK files, focusing on identifying malware signatures, potential security risks, and suspicious behaviors by evaluating permissions, certificate details, and known RAT indicators. Key features include permission analysis, certificate verification, RAT detection, hash generation, and risk assessments, streamlining the process of evaluating APKs for malicious content. The tool also supports a CLI version for Linux users, further enhancing its accessibility for different platforms.

augur

2026-08-03 Rust ★ 120
Augur is an advanced IDA headless plugin designed for efficient analysis of binary files by extracting strings and associated pseudocode. Its primary use case is to streamline vulnerability research by organizing and storing the pseudocode of functions that reference specific strings in an intuitive directory structure, leveraging the Hex-Rays decompiler's capabilities. Notable features include rapid processing, support for various architectures, and a robust decompilation process using the `decompile_to_file` API from the Haruspex library.

bg3se-macos

2026-08-03 C ★ 55
BG3SE-macOS is a native implementation of the Baldur's Gate 3 Script Extender for macOS, enabling the use of mods that require scripting capabilities, including gameplay tweaks and UI enhancements. It aims for full parity with the Windows version, supporting a wide range of modding functionalities while specifically omitting certain features like UI scripting and input injection. The tool is built from the ground up, offering compatibility with both Apple Silicon and Intel Macs, and allows users to easily integrate and manage mods directly through Steam.

d810-ng

2026-08-03 Python ★ 293
D-810 ng is an IDA Pro plugin designed to enhance reverse engineering by deobfuscating code during the decompilation process. It integrates seamlessly into the IDA workflow and allows for the rapid creation and configuration of deobfuscation rules, significantly simplifying complex expressions and restoring natural control flow. Notable features include a wide array of instruction-level optimizations, such as mixed Boolean arithmetic and constant folding, as well as control-flow unflatteners that tackle various obfuscation techniques, making it a comprehensive tool for malware analysis.

decomp.me

2026-08-03 TypeScript ★ 605
Decomp.me is a collaborative online platform for decompilation and reverse engineering, leveraging Next.js and Django technologies. It facilitates the decompilation process, allowing users to contribute and share compilers, and provides comprehensive documentation for setups, contributions, and maintenance. Key features include community engagement through a Discord server and the ability to run the platform locally via Docker.

DeepZero

2026-08-03 Python ★ 626
DeepZero is an automated vulnerability research pipeline engine that allows users to define and orchestrate data processing workflows using YAML configuration files. Notable features include support for parallel execution, resumable runs, integration with language model providers, and extensibility for custom processing components, making it ideal for analyzing and assessing vulnerabilities in a target corpus of files. The tool is built to enhance efficiency in vulnerability research while ensuring fault tolerance and state management during execution.

digital-fauxice

2026-08-03 Python ★ 40
Digital Fauxice is an open-source tool that emulates the infrared dust and scratch removal functionality of Nikon's Digital ICE, producing identical image outputs without utilizing Nikon's code. Its primary use case is to process scanned film images by leveraging a four-channel input (RGB and infrared) to accurately identify and repair surface defects, while an optional hybrid mode enhances defect handling by integrating modern inpainting techniques for severe damage. Notable features include a validation mechanism that ensures output fidelity to Nikon's original processing and a CUDA-backed implementation for accelerated processing times.

disrobe

2026-08-03 Rust ★ 98
disrobe is a static Rust binary designed for decompiling, deobfuscating, and unpacking compiled software across more than 20 programming ecosystems, including Python, JVM, .NET, JavaScript, and native binaries. It operates without executing the sample code, ensuring byte-identical outputs across platforms, supported by rigorous testing and validation against known references. Key features include automated pipeline composition for various formats and robust reporting on coverage and limits, with an option to run in-browser for experimentation.

dungeon-blitz-r

2026-08-03 TypeScript ★ 69
Dungeon Blitz: R is an open-source revival project designed to modernize and preserve the multiplayer experience of the original Dungeon Blitz game, focusing on stability, maintainability, and community-driven features. Notable capabilities include robust multiplayer support, localized gameplay, bug fixes, and quality-of-life improvements, all while enabling standalone single-player functionality through a local server setup. The tool is actively developed and allows users to manage their game experience without reliance on external servers, ensuring seamless play with local save storage.

dz6

2026-08-03 Rust ★ 201
dz6 is a fast Vim-inspired hex editor designed for terminal environments, enabling efficient editing of large files in hex or ASCII formats. Notable features include Vim-like key bindings, customizable options, regex string filtering, and the ability to parse PE/ELF headers, making it suitable for tasks involving low-level file inspection and manipulation. The tool is cross-platform, open-source, and offers a variety of navigation and editing commands to enhance user experience.

Facebook-iOS-SSL-Pinning-Bypass

2026-08-03 ★ 14
The Facebook iOS SSL Pinning Bypass tool provides a modified version of the Facebook app for iOS with SSL/TLS certificate pinning disabled, facilitating HTTPS traffic inspection for security research and analysis. Notable features include compatibility without requiring a jailbreak or Frida, as well as support for various HTTPS proxy tools such as mitmproxy, Burp Suite, and Charles Proxy. This tool is strictly intended for educational use, allowing researchers to better understand mobile application security mechanisms.

fireman

2026-08-03 Rust ★ 15
Fireman is a versatile decompiler designed to allow users to interactively modify Intermediate Representation (IR) through a graphical user interface (GUI), command-line interface (CLI), or text-based user interface (TUI) while observing real-time updates to C-like code. It features a complete instruction parsing routine for x64, IR-based analysis routines including data flow analysis, control flow analysis, and variable analysis, along with support for IR pattern matching and basic simulation functionalities. The tool aims to simplify the decompilation process while providing multiple interfaces for varying user preferences.

flutterdec

2026-08-03 Rust ★ 77
`flutterdec` is a static analysis tool designed for decompiling Flutter applications packaged as APKs or `libapp.so` files, specifically targeting Android ARM64 binaries. Its primary use case is for reverse engineering Flutter apps, providing readable pseudo-Dart code along with additional artifacts such as intermediate representation (IR), assembly, and symbol reports to aid in validation against lower-level codes. Notable features include the ability to extract and compare builds, enhance symbol naming from matched binaries, and various output options for deeper analysis.

fromsoftware-rs

2026-08-03 Rust ★ 63
FromSoftware-rs provides Rust bindings for mod creation in From Software games, enabling developers to interact with and manipulate game structures programmatically. The tool includes bindings for popular titles such as Dark Souls 3, Sekiro, and Elden Ring, along with shared utilities, making it highly versatile for game modding. Notable features include a well-defined crate structure for each game, extensive documentation, and a derive macro for streamlined trait implementation.

GameTracking-Deadlock

2026-08-03 C++ ★ 70
Game Tracking: Deadlock is a tool designed for automated tracking of in-game activities, allowing users to monitor various events without manual intervention. Its primary use case is to simplify the process of game analytics by aggregating data from multiple sources. Notable features include integration with a comprehensive tracking system as referenced in the main GameTracking repository and community support through a dedicated Discord channel.

ghidra-scripts

2026-08-03 Java ★ 302
The `ghidra-scripts` repository comprises a collection of scripts designed for Ghidra to enhance reverse engineering and vulnerability research. It features tools that locate insecure function calls, extract pseudocode, and resolve iOS and MIPS syscalls, thereby streamlining the analysis process for security researchers. Compatibility is maintained with Ghidra version 12.0.2.

gpmc

2026-08-03 Python ★ 320
GPMC is a cross-platform Python library and CLI tool designed for uploading media files to Google Photos using a reverse-engineered mobile API. Its notable features include unlimited uploads in original quality, automatic detection of existing files to prevent duplicates, album creation based on directory structure, and configurable multithreaded uploads for enhanced performance. The tool supports individual file and entire directory uploads with real-time progress tracking and optional JSON output for programmatic consumers.

haggle

2026-08-03 C++ ★ 54
Haggle Mod SDK is a modding tool specifically designed for Peggle Deluxe, enabling users to exploit the game's SexyFramework and Peggle functions through an external wrapper. Its primary use case includes facilitating the creation and loading of custom mods into the game, using the Haggle Mod Loader to inject mod code at startup. Notable features include an intuitive installation process, mod file management, and support for community-driven mod development through DLL integration.

half-life1_win32_722

2026-08-03 C ★ 57
The half-life1_win32_722 repository provides a reverse-engineered version of the source code for Half-Life 1 Net Test 1 (engine build 722), designed for developers looking to explore or modify this early pre-release iteration of the GoldSrc engine. It includes restored source code for critical components like the engine, client, and localization module, along with a reimplemented lightweight launcher. The tool is particularly useful for those interested in game development or historical software analysis of the Half-Life franchise.

haruspex

2026-08-03 Rust ★ 134
Haruspex is an advanced headless plugin for IDA Pro that efficiently extracts pseudocode from binaries, formatted for integration with IDEs or further parsing by static analysis tools like Semgrep. Notable features include its high-speed performance, compatibility with various architectures supported by IDA's Hex-Rays decompiler, and structured output where each function's pseudocode is saved separately for easy analysis.

Instagram-iOS-SSL-Pinning-Bypass

2026-08-03 ★ 13
Instagram iOS SSL Pinning Bypass is a modified version of the Instagram app for iOS that disables SSL/TLS certificate pinning, facilitating HTTPS traffic inspection for security research and reverse engineering. Key features include no requirement for jailbreak or Frida, compatibility with popular HTTPS proxies such as Burp Suite and mitmproxy, and support for iOS without introducing additional complexities. This tool is intended strictly for educational and research purposes in understanding mobile application security.

Ioniq5_CAN

2026-08-03 Jupyter Notebook ★ 52
The Ioniq 5 CAN repository provides an open-source hardware retrofit kit designed to add preconditioning functionality to Hyundai Ioniq 5, 6, and EV6 vehicles by utilizing existing buttons in the car. Key features include the reverse-engineering of CAN messages for preconditioning, a microcontroller that sends these messages, and a user interface to activate or cancel preconditioning. The software and firmware are continuously developed to enhance the functionality and user experience while detailed documentation supports installation and operation.

jd-gui-duo

2026-08-03 Java ★ 247
jd-gui-duo is a dual-function Java decompiler that integrates JD-Core versions 0 and 1, utilizing different algorithms for code analysis. Its primary use case is aiding developers in reverse engineering Java bytecode to recover source code. Notable features include support for the transformer-api, which enables additional decompiler compatibility beyond the original JD-Core implementations.

jesso-decompiler

2026-08-03 C ★ 14
Jesso Decompiler is a static analysis tool that disassembles and converts compiled binaries into C code for both Windows (PE files) and Linux (ELF files), specifically targeting binaries coded in x86/x86-64 machine language. It features a GUI built with wxWidgets, allowing users to visualize the disassembly process, although it is still in development and does not yet fully support the entire Intel instruction set. The tool analyzes binaries to extract function details and generate an intermediate representation of the program's logic, assisting in reverse engineering efforts.

kagura

2026-08-03 C++ ★ 24
Kagura is an LLVM-based code obfuscation and anti-tamper toolkit designed for mobile, desktop, and WebAssembly applications. It supports extensive protection mechanisms against threats such as static string extraction, decompiler-readable control flows, and dynamic instrumentation, employing techniques like string encryption, control flow flattening, and runtime checks. The toolkit integrates seamlessly with multiple platforms without requiring modification of the LLVM source tree, making it versatile for developers seeking enhanced security for their applications.

katam

2026-08-03 C ★ 155
The Kirby & The Amazing Mirror repository provides a complete disassembly of the USA version of the game, allowing users to compile the ROM file katam.gba. Its primary use case is to facilitate game modifications and reverse engineering for fans and developers. Notable features include detailed source code and setup instructions, enhancing the modding community's ability to understand and modify the game.

KNSoft.NDK

2026-08-03 C ★ 24
KNSoft.NDK provides native C/C++ definitions and import libraries for Windows NT development, enhancing interaction with undocumented Windows APIs and offering additional functionality. Key features include extensive API declarations, import libraries for Windows DLL exports, and utility functions for unit testing, string handling, command-line parsing, and random number generation. Developers can seamlessly integrate KNSoft.NDK by including its header files, which serve as an addendum to the standard Windows SDK.

lanis

2026-08-03 Dart ★ 90
Lanis Mobile is a cross-platform application designed for the Hessian School Portal, enabling over 35,000 daily users to interact with educational resources effectively. It features a modular architecture, making it adaptable to various school requirements, and allows contributions through bug reports and collaborative development. The app is available on multiple platforms, including Android and iOS, and supports features like customizable logging to enhance the development experience.

launchpad-core-firmware

2026-08-03 Rust ★ 42
CoreFW is a custom firmware solution designed for the Novation Launchpad series, providing a complete reimplementation with advanced features such as optimized MIDI processing and multiple customizable color palettes. It supports various Launchpad models, including RGB and non-RGB devices, and offers performance enhancements suitable for lightshows, along with a color palette editor and custom boot animations. Built through reverse engineering, CoreFW does not include official Novation firmware and is aimed at enhancing user control and LED performance across compatible devices.

m365-copilot-proxy

2026-08-03 JavaScript ★ 68
m365-copilot-proxy serves as a bridge that allows Microsoft 365 Copilot to function as a backend for OpenAI-compatible coding agents by translating the M365 Copilot's WebSocket/SignalR API into an OpenAI-compatible format. This tool features a standalone proxy with customizable endpoints, agent creation for enhanced tool calling, and session continuity to save resources during interaction. Notably, it utilizes a shell-routing mechanism to bypass M365 Copilot's limitations in executing agentic tasks, enabling more effective multi-turn execution of code commands.

MachOObjCSection

2026-08-03 Swift ★ 28
MachOObjCSection is a Swift library designed for parsing Mach-O files to extract detailed Objective-C metadata, including class, protocol, and category information. It extends the functionalities of MachOKit and provides comprehensive access to read-only data for classes, protocols, and categories, which are not accessible via the Objective-C runtime. Notable features include support for both 32-bit and 64-bit architectures, and compatibility with the ObjCDump library for seamless integration with existing Objective-C models.

malcontent

2026-08-03 Go ★ 675
Malcontent is a subtle malware discovery tool that leverages context, differential analysis, and over 14,500 YARA rules to uncover supply chain compromises, primarily targeting Linux binaries but also supporting other UNIX platforms and Windows. Its three operational modes—analyze, diff, and scan—facilitate extensive program capability assessments, risk-weighted comparisons, and threshold-based scanning. Key features include support for multiple binary formats, various output formats, integration within CI/CD pipelines, and specific configurations for handling archives and container images.

memory-of-alessa

2026-08-03 C ★ 110
Memory of Alessa is a decompilation project focused on achieving 100% byte-matching for the PlayStation 2 game Silent Hill 3, as well as its underlying engine from Silent Hill 2. The tool aims to facilitate the understanding and documentation of Team Silent's PS2 engine, providing resources for both decompilation and technical learning, though it is currently in early stages of development. Notable features include robust support for working across various operating systems and a comprehensive setup guide for users.

MetaHookSv

2026-08-03 C++ ★ 248
MetaHookSv is a client-side modding framework designed for the SvEngine and other GoldSrc engine-based games, aimed at enhancing gameplay experience in titles like Sven Co-op. It supports a variety of engine versions and ensures compatibility with numerous plugins from the original MetaHook project. Key features include a one-click installation process, extensive compatibility with different GoldSrc variants, and tools to manage game performance and memory usage.

mwemu

2026-08-03 Rust ★ 314
MWEmu is a Rust-based hardware emulator and OS process simulator primarily designed for dynamic malware analysis and testing, focusing on Windows processes with some Linux support. It features fast and reliable x86 32/64-bit emulation, extensive implementation of 339 CPU instructions, and 260 WinAPI calls, as well as tools for memory tracking, state exploration, and interaction with various shellcodes and malware payloads. Notable functionalities include command-line, Rust, and Python library interfaces, as well as advanced dynamic analysis capabilities like iteration detection and PE execution.

nfdx64dbg

2026-08-03 C ★ 173
nfdx64dbg is a plugin designed for the x64dbg debugging platform, primarily used for analyzing and reverse-engineering PE (Portable Executable) files. Its notable features include enhanced functionality for file inspection and manipulation within the x64dbg environment, streamlining the debugging process for security researchers and developers.

nfsmw

2026-08-03 C++ ★ 161
This repository provides a work-in-progress decompilation of the GameCube, Xbox 360, and PS2 versions of Need for Speed: Most Wanted, with a primary focus on the GameCube variant. It facilitates the extraction and rebuilding of game binaries, requiring an existing copy of the game for use, and supports multiple versions of the game with detailed instructions for setup on various operating systems. Notable features include automated build processes and integration with a diffing tool for code comparisons, enhancing the development and analysis capabilities of the decompiled code.

omni

2026-08-03 C++ ★ 259
Omni is a header-only C++23 library designed for Windows that facilitates loader inspection, export parsing, and syscall management. Its key features include utility functions for module handling, lazy imports, high-level access to API sets, and enhanced performance through compile-time optimizations, making it suitable for developers who require efficient interaction with Windows' native APIs. Additionally, Omni offers optional caching mechanisms for improved performance during lazy imports and syscall identification.

oneiromancer

2026-08-03 Rust ★ 145
Oneiromancer is a reverse engineering assistant designed to enhance code analysis by utilizing a locally running large language model (LLM) that has been fine-tuned for Hex-Rays pseudocode interpretation. Its primary use case is to analyze code snippets, providing high-level descriptions, suggested function names, and variable renaming recommendations, while also saving improved pseudocode for further inspection. Notable features include cross-platform compatibility, integration with the pseudocode extractor 'haruspex', and the ability to invoke analysis through external crates, facilitating a seamless development experience.

open-grind

2026-08-03 TypeScript ★ 31
Open Grind is an unofficial, privacy-centered client for the Grindr platform, designed to be cross-platform, free, and ad-free. Its primary use case is to provide users with a secure alternative for connecting with others while ensuring their data remains private and free from trackers. Notable features include reproducible builds, signed releases for enhanced security, and a community-driven development approach.

open-reverselab

2026-08-03 Python ★ 1094
ReverseLab is an open-source reverse engineering lab designed for capturing and analyzing various attack scenarios across multiple domains, including CTF pentesting, APK reverse engineering, and PE binary analysis. Its notable features include a comprehensive knowledge base organized into specialized categories, over 100 automation tools for rapid execution, and a modular architecture that supports various signal types and attack chains. Users can easily set up the tool on multiple platforms with provided scripts, ensuring a streamlined onboarding experience.

OpenBarnyard

2026-08-03 C++ ★ 84
OpenBarnyard is a work-in-progress project focused on decompiling the video game Barnyard and the TOSHI 2.0 game engine developed by Blue Tongue Entertainment, primarily aimed at educational purposes and community contribution. It enables developers to explore the game mechanics through reverse engineering while providing a Ghidra repository for those looking to contribute to the project. Notable features include a build system for Windows using Visual Studio and a clear emphasis on supporting the original developers and discouraging piracy.

openbgi

2026-08-03 C ★ 71
OpenBGI is an open-source re-implementation of the Ethornell Buriko General Interpreter (BGI), targeting cross-platform execution of Buriko Programs (`._bp` scripts). Its primary use case is to provide a highly portable engine capable of running visual novels while integrating tools for game translation and graphical enhancement. Notable features include the ability to execute basic opcodes, early support for graphics routines, and plans for compatibility with multiple platforms, including Windows, macOS, Linux, Android, and WASM.

OpenKh

2026-08-03 C# ★ 430
OpenKH is a comprehensive toolkit designed for modding and enhancing the 'Kingdom Hearts' game series, consolidating technical documentation, code libraries, and utility tools in one repository. Notable features include cross-platform support for command line tools, structured code architecture for flexible functionality, and automatic build generation via GitHub Actions, ensuring users have access to stable, up-to-date versions. The project aims to foster community engagement and provide a user-friendly modding environment.

opennord

2026-08-03 TypeScript ★ 18
OpenNord is an open-source tool designed for managing and interacting with Nord® keyboards, particularly the Nord Stage series. It allows users to read and organize programs, audition samples, and communicate with the keyboard over a reverse-engineered USB protocol, eliminating the need for a desktop app. Notable features include a searchable library for managing sounds, the ability to transfer data to and from the keyboard, and support for multi-model file compatibility across the Nord line.

pokegold

2026-08-03 Assembly ★ 704
The Pokémon Gold and Silver repository provides a disassembly of the classic Game Boy Color games, facilitating the building of various ROM versions including debug binaries and patches. Its primary use case is for developers and enthusiasts interested in reverse engineering or modifying these games, with notable features including a robust build system and integration with additional tools for game development. The project also engages with a community on Discord for collaborative development and support.

pokegold-spaceworld

2026-08-03 Assembly ★ 393
The Pokémon Gold and Silver: Space World 1997 Demo repository provides a disassembly of the prototypes for the Pokémon Gold and Silver games, featuring multiple ROM builds for both titles with various debugging options. The primary use case of this tool is for developers and enthusiasts interested in the historical and technical aspects of these game prototypes, allowing them to explore different builds with accurate headers and debugging support. Notable features include the generation of non-debug and debug ROMs, each with their respective SHA1 checksums for verification.

pokepinball

2026-08-03 Assembly ★ 196
Pokémon Pinball is a disassembly project for the Game Boy Color game of the same name, primarily aimed at developers and enthusiasts interested in reverse engineering or modifying the game. It allows users to build the ROM file for Pokémon Pinball, with notable features including organized source code and links to related disassembly projects within the Pokémon franchise. The repository also provides installation instructions to facilitate setup.

pokeplatinum

2026-08-03 C ★ 525
The Pokémon Platinum repository is a work-in-progress decompilation of the Pokémon Platinum game, allowing developers to build and customize the ROM files. Its primary use case is to facilitate modifications and enhancements for the game, supporting collaborative contributions from the community. Notable features include support for building multiple ROM revisions and comprehensive installation and contribution guidelines.

poketcg

2026-08-03 Assembly ★ 325
The Pokémon TCG repository provides a disassembly of the Pokémon Trading Card Game for the Game Boy Color, allowing developers to inspect, modify, and rebuild the ROM. Primary use cases include reverse engineering and modding the game, with notable features such as integration with RGBDS for assembly and comprehensive documentation available through its wiki and tutorials. The project encourages community interaction via Discord and links to additional tools and related projects.

radar_pi

2026-08-03 C ★ 105
The radar_pi plugin integrates various yacht radar systems with the OpenCPN marine navigation software, enhancing its capabilities for maritime navigation. It notably supports Garmin HD, Garmin xHD, Navico Broadband Radar, and select Raymarine radars, offering features like guard zones, target trails, and customizable PPI windows. This plugin provides crucial functionality for sailors and marine enthusiasts who use compatible radar systems for improved navigation and situational awareness.

rea

2026-08-03 TypeScript ★ 387
REA (Reverse Engineer Anything) is a command-line interface (CLI) and multi-component platform (MCP) server designed to facilitate reverse engineering of software applications, enabling users to investigate features even without access to source code. Notable features include deep native analysis using Hopper or Ghidra, execution-free managed PE/CLI triage, evidence management, and structured workflows that simplify the reverse engineering process by automating tool interactions and data collection. The tool ultimately aims to assist users in understanding, documenting, and recreating features for custom applications seamlessly.

REPENTOGON

2026-08-03 C++ ★ 338
REPENTOGON is an advanced mod for *The Binding of Isaac: Repentance+* that enhances the Lua API with critical bug fixes, extended functionality, and performance optimizations. Unlike traditional mods, REPENTOGON operates as an "EXE mod," interfacing directly with the game's code through the LibZHL framework, allowing for sophisticated modifications that were previously unachievable. Notable features include a robust API documentation, extensive enhancements to game mechanics, and an emphasis on performance without the need for intensive hacks.

revenge-bundle-next

2026-08-03 TypeScript ★ 171
Revenge is a lightweight client modification for Android's Discord that enables users to customize their experience with plugins, themes, and experimental features. Its framework allows developers to create and integrate custom add-ons seamlessly, enhancing overall functionality. Notable features include a user-friendly interface, support for extensive personalization, and streamlined installation methods for both rooted and non-rooted devices.

reverseloom

2026-08-03 Python ★ 41
reverseloom is a tool designed to automate the extraction of data from websites protected by advanced bot detection systems, such as Akamai Bot Manager. It employs a unique approach by interacting directly with the browser using a headless environment to reverse engineer the site's protocol, enabling it to generate standalone crawlers that function without a browser. Notable features include complete exposure of the website's DOM, network traffic, and JavaScript debugger, along with the ability to create fully operational, browser-free crawlers that are capable of executing tasks autonomously.

rhabdomancer

2026-08-03 Rust ★ 133
Rhabdomancer is a high-performance headless plugin for IDA that identifies calls to potentially insecure API functions within binary files. It aids security auditors by backtracking from these functions to find vulnerabilities related to untrusted input, complete with a prioritization system that categorizes known bad API calls. Notable features include support for various C/C++ binary targets and the ability to customize the list of bad API functions according to user-defined criteria.

rizin

2026-08-03 C ★ 3826
Rizin is a comprehensive reverse engineering framework designed for analyzing binaries, disassembling code, and debugging programs, offering enhanced usability and features compared to its predecessor, radare2. It supports a wide array of operating systems and architectures, includes multiple utilities for scripting and binary manipulation, and facilitates interaction with popular programming languages through rzpipe. Notable features include a command-line assembler, tools for binary comparison and pattern searching, as well as extensive file format compatibility.

rtl8196e-gateway

2026-08-03 C ★ 200
The RTL8196E Gateway project provides open Linux firmware for the Lidl Silvercrest Zigbee Gateway, transforming it into a fully local smart home hub capable of serving as a Zigbee coordinator, Thread Border Router, or Zigbee router. Notable features include support for modern Zigbee stacks, SSH access for secure management, and the ability for over-the-air firmware updates. The firmware is designed to be portable across various RTL8196E-based gateways, bolstering its versatility in IoT environments.

sead

2026-08-03 C++ ★ 242
The sead repository offers a decompilation of the standard C++ library used in first-party Nintendo games, specifically targeting more recent versions of the library. Its primary use case is to enhance interoperability and facilitate the development of projects that interact with these games, by accurately recreating the library structure based on debugging symbols from selected titles. Notable features include modular organization for various functionalities such as audio, graphics, and threading, as well as support for multiple Nintendo platforms through configurable source directories.

ShadowStrike

2026-08-03 C++ ★ 37
ShadowStrike Phantom is an open-source endpoint protection platform for Windows 10/11 that aims to deliver advanced threat detection capabilities comparable to commercial EDR solutions. Notable features include a custom kernel driver with 20 detection subsystems, an on-device analysis engine utilizing neural networks, and a malware emulation engine—all designed to ensure transparency and audibility in its security processes.

SickoMenu

2026-08-03 C++ ★ 286
SickoMenu v4.5.2 is a utility tool for the game Among Us, designed to enhance gameplay through various custom features, including NoClip, Ghost Visibility, and SickoChat. It is intended strictly for educational and experimental purposes within private lobbies, and emphasizes ethical use to avoid violations of Innersloth's terms. Notable functionalities include gameplay modifiers and a comprehensive list of mischief-inducing options, promoting responsible use while exploring game mechanics.

Silent-Hill

2026-08-03 C ★ 49
Silent Hill Hub is a comprehensive repository designed for reverse engineering, documentation of file formats, and modding tools for the Silent Hill video game series. It provides utilities for extracting and viewing game assets such as 3D models, textures, audio, as well as scripts for various popular tools like 010 Editor and Noesis, facilitating in-depth exploration and modification of game content. Additionally, the project aims to preserve community knowledge and resources related to the series, thereby supporting both developers and enthusiasts in the Silent Hill modding community.

SiliconRE

2026-08-03 Verilog ★ 229
SiliconRE is a reverse-engineering tool for analyzing custom chips primarily from the 80s and 90s, focused on video game hardware. It provides detailed traces, schematics, and a chip database, along with functionalities like access to cell lists to streamline reverse-engineering processes. Notable features include the tracking of project statuses and collaborative resources for sharing findings in the retro hardware community.

sonicheroes

2026-08-03 C++ ★ 13
Sonic Heroes is a decompilation project aimed at preserving the Nintendo GameCube version of the game, specifically targeting the G9SE8P revision. This non-commercial initiative does not contain any game code or assets but allows users to build their own copy using a legally obtained game. Notable features include detailed tracking of progress through badges, cross-referencing with PS2 builds for metadata, and a strict adherence to legal guidelines concerning artifact distribution.

SonolusReverse

2026-08-03 TypeScript ★ 14
SonolusReverse is a modification for the Sonolus rhythm game that enables enhanced features through the Frida framework, specifically tailored for Android (with potential iOS compatibility). Its primary use case is to unlock VIP access and custom themes for the game, along with providing functionalities for version spoofing and a dedicated settings section for personalized configurations. Notable features include the ability to create custom themes in JSON format and a client-side unlock for all exclusive content, facilitating a tailored gaming experience.

spm-decomp

2026-08-03 C ★ 91
spm-decomp is a decompilation project focused on the Super Paper Mario game, primarily targeting the PAL versions along with some support for the NTSC-U version. It aims to extract specific parts of the game's code useful for modding or analysis, without intending to provide a complete decompilation or platform ports. Notable features include the ability to modify game behavior through a configurable setup and support for various disc image formats for building the project.

SR-CoD4x

2026-08-03 C ★ 11
SR CoD4x is a modification of the Call of Duty 4: Modern Warfare server that addresses original game bugs and enhances server functionality through a plugin system. Notable features include automated client updates, robust anti-cheat measures, extended player movements, and a reliable player identification mechanism, providing a more optimized and feature-rich gaming experience for players.

TRR-SaveMaster

2026-08-03 C# ★ 43
TRR-SaveMaster is an open source savegame editor designed for Tomb Raider I-VI Remastered, allowing users to modify various aspects of their savegames, including inventory, weapons, health, and player position. It supports cross-platform compatibility, enabling edits for PC, PS4, Android, and Nintendo Switch formats, and features tools for unlocking game content and deleting savegames. The editor also provides a position teleportation feature, facilitating seamless navigation within game levels.

ttd-capa

2026-08-03 C++ ★ 17
ttd-capa is a capability extractor that works with Time Travel Debugging (TTD) traces to identify the capabilities exercised by a binary during its runtime execution. Designed to enhance the analysis of packed or obfuscated malware, it generates CAPA-compatible reports that allow for the extraction of runtime capabilities, leveraging full execution context and timestamp data for detailed analysis. Notable features include automatic resolution of string arguments, reconstruction of execution order, and integration with existing CAPA rule sets for comprehensive malware triage.

windiff

2026-08-03 Rust ★ 392
WinDiff is an open-source, web-based tool designed for browsing and comparing symbol, type, and syscall information of Microsoft Windows binaries across different OS versions. Its primary use case is to facilitate analysis for security researchers by providing a user-friendly interface to visualize changes in Windows binaries and automate version comparisons through an integrated AI assistant. Notable features include a dual structure comprising a CLI tool and a TypeScript frontend, automatic updates from the latest Windows versions, and the ability to analyze binary changes using the Claude Code skill.

wow-optimize

2026-08-03 C++ ★ 111
wow_optimize is a performance optimization DLL specifically designed for World of Warcraft 3.3.5a, targeting enhancements at the engine and runtime level to address memory allocation, Lua VM efficiency, and various low-level bottlenecks. Its primary use case is to improve frametime stability and reduce Lua overhead during addon-heavy gameplay while maintaining safety from historically unsafe features. Notable features include memory address space reduction, CPU-intensive optimizations, and compatibility adjustments that allow for smoother long-session gameplay.

airstrike3d-tools

2026-08-03 C ★ 23
AirStrike 3D Tools is a specialized reverse engineering toolkit aimed at deconstructing the AirStrike 3D game series. It enables users to perform tasks such as APK archive extraction, model conversion (MDL to OBJ), save file previewing, and audio conversion, while also supporting graphics viewing and Linux compatibility. The toolkit is built using C++ and Python, emphasizing extensibility and ease of use for reverse engineering game assets.

Apktool

2026-08-03 Java ★ 25429
Apktool is a reverse engineering tool for Android applications that allows users to decode and rebuild APK files, facilitating modification and debugging of smali code. Its primary use case includes enabling localization and feature enhancements of existing applications while maintaining a project-like file structure for ease of use and automation of common tasks. Notable features include support for debugging, a structured file layout, and the ability to modify app resources while respecting copyright laws.

B2R2

2026-08-03 F# ★ 465
B2R2 is a fully managed binary analysis framework designed for reverse engineering and program analysis, implemented in F#. It features efficient binary disassembly, instruction parsing, control-flow recovery, and interoperability across platforms, supporting multiple binary file formats like ELF, PE, Mach-O, and WebAssembly. With a focus on ease of use and native IntelliSense support in .NET, B2R2 empowers developers with a robust set of tools for binary-level inspection and analysis.

BinNexus

2026-08-03 Python ★ 16
BinNexus is a binary analysis tool designed for Windows binaries (DLL/EXE) that generates an interactive web portal, providing a comprehensive dependency graph and export exploration capabilities. Its primary use case is to facilitate the understanding of binary structures through visualizations of relationships between components, supported by features like global search and noise filtering to enhance analysis precision. The tool is modular, allowing for easy expansion and integration of new analysis engines while offering both static and experimental runtime analysis of dependencies.

binsafe

2026-08-03 Rust ★ 17
Binsafe is an obfuscator designed for 64-bit portable executables that employs a multi-step process to transform the structure and execution of compiled binaries. Its notable features include disassembly, instruction virtualization, operational scrambling, and runtime protections against debugging and tampering. This tool primarily serves to enhance binary security by making reverse engineering significantly more challenging.

Butterscotch

2026-08-03 C ★ 349
Butterscotch is an open-source re-implementation of the GameMaker: Studio runner, enabling the execution of GameMaker games compiled to bytecode on various platforms. It primarily aims to support a wide range of GameMaker: Studio games, especially targeting titles like Undertale, by allowing compatibility with multiple WAD versions. Notable features include a focus on community collaboration, ongoing development for increased game support, and the ability to generate PlayStation 2 ISO files.

CANopenTerm

2026-08-03 C ★ 77
CANopenTerm is an open-source tool designed for developing, testing, and analyzing CANopen CC networks and devices, with added support for SAE J1939 and OBD-II protocols. Notable features include advanced network monitoring, configuration and simulation capabilities, raw CAN CC interface, and automation support via Lua and Python scripts, making it a versatile solution for professionals in automotive and industrial applications. Additionally, it provides functionalities like SDO management, conformance testing, and test report generation, enhancing the overall workflow for engineers working with CAN protocols.

ClrDebug

2026-08-03 C# ★ 134
ClrDebug is a comprehensive cross-platform managed wrapper for the .NET Unmanaged API, simplifying the process of developing diagnostic applications. It provides automatic wrappers for essential APIs such as CorDebug, Metadata, and Profiling, eliminating the need for manual handling of complex COM interfaces. Notable features include seamless creation of debugging processes, easy conversion of HRESULT values into exceptions, and customizable event handling through derived callback classes.

discover-ads-filter

2026-08-03 Kotlin ★ 44
Discover Ads Filter is an Xposed module designed to remove sponsored cards and advertisements from the Google Discover feed on the Pixel Launcher and within the Google app for devices running Android 11 and above. It uses DexKit to scan the Google app and identify ad items by resolving hook targets, enabling efficient filtering and caching of ad content. Notably, it requires a compatible LSPosed manager with libxposed API support to function effectively.

Firmware

2026-08-03 C++ ★ 74
OpenShock Firmware is designed for controlling shockers using reverse-engineered proprietary Sub-1 GHz protocols, specifically targeting the ESP-32 microcontroller equipped with a 433 MHz antenna. The firmware supports various compatible hardware platforms and facilitates easy flashing through PlatformIO in Visual Studio Code. Notable features include a comprehensive guide for setup and assembly, alongside thorough documentation and support through an active community.

Freelancer.Reverse.Runtime

2026-08-03 C ★ 11
Freelancer.Reverse.Runtime is a project focused on building a custom managed runtime layer for the 2003 space trading and combat simulation game, Freelancer. Its primary use case is to reconstruct, document, and extend the game's engine behavior through compatible proxy DLLs while avoiding chaotic memory manipulation. Notable features include the implementation of a structured C++ layer that replaces original DLLs, monitors engine behavior, and seamlessly injects new functionality, facilitating a reliable engineering approach that respects the original game architecture.

garlic

2026-08-03 C ★ 777
Garlic is a high-performance open-source decompiler for Android and Java files, designed to convert APK, DEX, JAR, and CLASS files into readable Java source code. Notable features include multi-threading capabilities for faster decoding, integration for cross-platform builds using Zig, and functionality for string searching within decompiled outputs. This tool caters primarily to security researchers and developers needing to analyze or reverse-engineer Android applications efficiently.

ghidra-mcp

2026-08-03 Java ★ 3622
Ghidra MCP Server is a robust Model Context Protocol (MCP) server designed to enhance Ghidra's reverse engineering capabilities by integrating with AI tools and automation frameworks. It features a comprehensive suite of 251 tools, offering extensive write access for various operations such as renaming, typing, and live debugging, along with battle-tested AI workflows for optimized documentation and code handling. Key highlights include production-grade reliability with atomic transactions and reduced API calls for enhanced efficiency.

GhidraFindcrypt

2026-08-03 Java ★ 95
Ghidra FindCrypt is an auto-analysis module designed for Ghidra to identify and label cryptographic constants within binary files. Its primary use case is to enhance code analysis by automatically recognizing cryptographic algorithms and assigning appropriate labels to found constants, which are prefixed with `CRYPT_` for easy identification. Notable features include integration with the Ghidra API for improved functionality, automatic datatype assignment for recognized constants, and the ability to rerun analyses safely.

ghostify

2026-08-03 JavaScript ★ 12
Ghostify is a privacy-focused browser extension designed for Meta web applications like Instagram, Facebook, and Messenger. It empowers users by blocking read receipts, typing indicators, and story-view signals locally, enhancing privacy without the need for an account or sharing social media credentials. The tool is built on Manifest V3 and is available across multiple browsers, with an established user base exceeding 4,000 on the Chrome Web Store.

ipatool

2026-08-03 Go ★ 10431
IPATool is a command line utility designed for interacting with the iOS App Store, enabling users to search for applications, authenticate with their Apple ID, and download app packages (ipa files). Key features include app search by term, list available versions for download, and facilitate license purchases, all while supporting output formatting options and various command flags for enhanced usage. This tool is particularly useful for developers and researchers who need to access and manage iOS app data programmatically.

MHServerEmu

2026-08-03 C# ★ 559
MHServerEmu is a server emulator specifically designed for the Marvel Heroes game, providing support for multiple client versions, primarily 1.52.0.1700. It facilitates the restoration of the game’s original content and systems post-shutdown in 2017, with options for stable and nightly builds tailored to different user preferences. Notable features include a focus on high stability for stable releases, daily updates for nightly builds, and community engagement through a dedicated Discord server for development discussions.

neohook

2026-08-03 Rust ★ 28
NeoHook is a Rust-based toolkit designed for precise and safe runtime function hooking within Win32 applications, allowing users to hook APIs, game engine functions, and third-party DLL exports with ease. Its notable features include atomic transactions for batch-hooking, full thread safety during hook application, and advanced techniques such as instruction pointer redirection and stack scanning to maintain stability. The tool provides a high level of memory safety combined with the efficiency of low-level binary patching, making it suitable for debugging, profiling, and security research while ensuring compliance with licensing and legal constraints.

niimblue

2026-08-03 TypeScript ★ 714
NIIMBLUE is a web-based application designed for the design and printing of labels directly from a browser, emphasizing privacy by operating offline and storing data locally. Key features include support for Bluetooth and USB connections, a rich label editor with import/export capabilities, print previews with post-processing options, and compatibility with a wide range of printer models while implementing the NIIMBOT protocol extensively. The tool is accessible through standalone applications for Android and Windows, enhancing its usability across platforms.

pikmin2

2026-08-03 Assembly ★ 361
A decompilation of Pikmin 2 (USA) brought to you by fans of the series.

playstore-adblock

2026-08-03 Kotlin ★ 76
Playstore Adblock is an Xposed module designed to eliminate sponsored listings and advertisements from the Google Play Store, enhancing the user experience by allowing seamless app browsing. It is compatible with Android 11 and above and requires libxposed API 101+, offering a straightforward installation process that involves activation through an Xposed manager. Notable features include adaptation to various Play Store versions and the ability to clear cached ad responses, ensuring optimal functionality.

prime

2026-08-03 C++ ★ 301
PrimeDecomp/prime is a decompilation project for the game Metroid Prime, requiring a valid game copy to function. It supports multiple game versions and emphasizes the use of native build tools for optimal performance across various operating systems including Windows, macOS, and Linux. Notable features include automatic rebuilds during development and compatibility with various disc image formats for easy setup.

PyAutoRaid

2026-08-03 HTML ★ 31
PyAutoRaid is a tool designed for optimizing gameplay in *Raid: Shadow Legends* by enabling players to simulate Clan Boss fights locally without using in-game keys. Its notable features include a key-free battle simulation, team and gear optimization, and detailed battle history tracking, allowing players to fine-tune their strategies before committing resources. The simulation harnesses the actual game engine for accurate results and maintains user data privacy by running entirely on the player's PC.

r2morph

2026-08-03 Python ★ 51
r2morph is a metamorphic mutation engine that enables tracked binary transformations, operating with structured validation and reporting. It supports various architectures and binary formats, offering 18 diverse mutation passes along with multiple validation modes and comprehensive reporting capabilities in formats such as SARIF and JSON. Key features include session management for rollback, a detection suite for various signatures, and the ability to analyze virtual machine handlers for devirtualization.

rascal

2026-08-03 Java ★ 460
Rascal is a meta-programming language designed for constructing and manipulating software artifacts. Its primary use case involves providing tools for parser generation, type checking, and document compilation, making it suitable for developing languages and analysis tools. Notable features include a comprehensive standard library, an integrated development environment support, and compatibility with Maven for streamlined project management.

reverse-engineering-assistant

2026-08-03 Java ★ 821
ReVa is a Ghidra extension that functions as an MCP server to facilitate AI-assisted reverse engineering, leveraging large language models (LLMs) for enhanced interaction with Ghidra's capabilities. It focuses on minimizing context rot and hallucination through a tool-driven approach, providing critical, easily interpretable tools that empower LLMs to perform complex tasks on large binaries and firmware images. Notable features include reporting additional context to guide analysis, integration with other MCP servers for enriched data sourcing, and the ability to handle diverse queries related to reverse engineering tasks.

ReverseProxyDLL

2026-08-03 Python ★ 41
ReverseProxyDLL is a tool designed to create compatibility scaffolds for legacy x86 Windows DLLs, facilitating reverse engineering by automating the generation of proxy DLL projects. Its notable features include runtime loading of original DLLs, export resolution using `GetProcAddress`, call forwarding, and support for structured logging, all aimed at facilitating a more efficient workflow during the reverse engineering process. This tool stands out from conventional DLL proxy generators by being export and ABI aware, allowing for a more nuanced approach to dealing with complex legacy binaries.

ROLLER

2026-08-03 C ★ 69
ROLLER is a modern implementation of the 1995 racing game Whiplash, designed to run on current PC systems by replacing DOS-specific functions with SDL and platform-compatible equivalents. Its primary use case is for users to play a nostalgic game experience in contemporary environments, either through a browser demo or a native installation that requires original game assets. Notable features include support for loading game data from legally owned retail discs, a built-in demo version, and comprehensive tools for debugging and assembly output generation.

Sace

2026-08-03 ★ 14
Sace is a mobile Unreal Engine Asset Editor designed for Android, enabling developers and modders to inspect and manipulate `.uasset` and `.uexp` files without requiring a PC. Its key features include full support for both UE4 and UE5 formats, a low-level tree view for visualizing nested data structures, real-time property editing, and an integrated hex editor for byte-level modifications, offering a powerful on-the-go editing experience.

scripts

2026-08-03 JavaScript ★ 163
The repository contains a collection of scripts designed for use with the Agent tool. Its primary use case is to enhance automation and functionality within the Agent framework, facilitating various operational tasks. Notable features include easy integration and support for scripting common workflows in cybersecurity operations.

shiva

2026-08-03 C ★ 218
Shiva is a Just-In-Time (JIT) micropatching engine designed for ELF dynamic linking and patching of native Linux software on AArch64 and X86_64 architectures. It allows users to write C-based patches that can be compiled into ELF relocatable objects, enabling runtime modification of binaries at load-time through a method known as "chained linking." Notably, Shiva supports dynamic patching while retaining compatibility with existing ELF interpreters and emphasizes a straightforward user guide for seamless integration into existing workflows.

TooGoodToGo-CLI

2026-08-03 Python ★ 27
TooGoodToGo-CLI is a command-line interface tool that automates the checkout process for the Too Good To Go service, allowing users to monitor and reserve magic bags before they sell out. Its notable features include passwordless account login, automatic handling of the checkout flow including 3DS challenges, an interactive menu for ease of use, and customizable notifications for item availability. Designed for simplicity, the tool can be easily configured and used directly from the command line without requiring additional software.

Trinity

2026-08-03 Java ★ 83
Trinity is a next-generation Java reverse-engineering tool designed for exploring, understanding, and rewriting bytecode. Key features include an advanced decompiler based on Fernflower, in-place renaming with immediate cross-referencing updates, instant constant searches, and customizable workspaces for project management. Its focus on extensive cross-referencing and built-in refactoring capabilities enhance the analysis and modification of Java applications.

Trueforce-For-All

2026-08-03 C# ★ 44
Trueforce For All is a plugin designed to enable Logitech Trueforce-compatible haptic effects in any game that works with SimHub, filling the gaps for titles lacking official Trueforce support. It utilizes a reverse-engineered wire protocol to allow users to experience real-time haptic feedback while preserving the game's original force feedback through an FFB pass-through mechanism. Notable features include customizable telemetry-derived effects such as engine pulse, gear shift feedback, and ABS haptic responses, ensuring an immersive driving experience across supported Logitech racing wheels.

TryHackMeRoadmap

2026-08-03 ★ 541
The TryHackMeRoadmap repository provides a curated list of over 350 free TryHackMe rooms, categorized by skill level and topic, aimed at enhancing the learning experience for cybersecurity enthusiasts. Its notable features include a structured approach that covers various areas such as network security and web exploitation, alongside self-contained rooms with practical exercises to facilitate hands-on learning. Regular updates ensure relevance and accessibility to new resources in the evolving cybersecurity landscape.

wakaru

2026-08-03 Rust ★ 973
Wakaru is a tool designed to unpack and reverse the minification and transpilation of JavaScript bundles produced by tools like webpack and esbuild, transforming them into readable modern JavaScript code. Its primary use case is to enhance the understandability of compiled code for auditing and debugging purposes by restoring original syntax, removing bundler runtimes, and effectively splitting bundles back into their modular components. Notable features include support for multiple bundler formats, advanced transpiler recovery functions, and various transformation levels to balance between readability and fidelity to the original semantics.

YoutubeDownloader

2026-08-03 C# ★ 16043
YoutubeDownloader is a cross-platform application designed to facilitate the downloading of YouTube videos, playlists, and channels via URL input or keyword search. Its notable features include support for various video formats and qualities, automatic embedding of audio tracks and subtitles, and the ability to log in to a YouTube account to access private content. This tool leverages the YoutubeExplode library to ensure effective interaction with YouTube's infrastructure.

YoutubeExplode

2026-08-03 C# ★ 3719
YoutubeExplode is a library designed to interface with YouTube for querying metadata of videos, playlists, and channels, as well as resolving and downloading video streams and closed caption tracks. It functions by scraping raw page data and utilizing reverse-engineered internal endpoints, offering capabilities such as video metadata retrieval and stream downloading through its `YoutubeClient` class. Notable features include easy integration with .NET via NuGet and an extension package for video conversion using FFmpeg.

advanced-anti-sandbox-Virtual-Machine

2026-08-03 C++ ★ 11
The Advanced Anti-Sandbox Virtual Machine tool develops techniques to counteract sandbox detection in malware analysis environments. Its primary use case is to assist security researchers and malware developers in executing samples without triggering detection in virtualized analysis frameworks by employing various bypass strategies, including path verification and time-based checks. Notable features include static bypassing capabilities, integration with C++ programming, and the ability to adapt to various sandbox systems, enhancing the efficacy of evasion techniques.

AIDA64-Network-Audit-2026

2026-08-03 ★ 26
AIDA64 Network Audit scans local and remote computers to collect hardware, software and network configuration data, generating inventory reports. It supports scheduled scans, queries, export to CSV, HTML, XML, and integrates with Active Directory for asset tracking.

asmtransformers

2026-08-03 Python ★ 15
ASMTransformers is a machine learning tool designed for analyzing ARM64 assembly functions by comparing them to a database of known functions to facilitate reverse engineering tasks. Its architecture includes a training and inference module, a FastAPI backend for service management, and a Ghidra frontend for user interaction, with models available on Hugging Face. Notable features include dynamic similarity scoring and an integration framework for seamless use within Ghidra.

BetrockPlusPlus

2026-08-03 C++ ★ 39
BetrockPlusPlus (BPP) is a comprehensive, from-scratch reimplementation of Minecraft Beta 1.7.3, designed to function both as a client and server while prioritizing compatibility and faithful reproduction of original features. The tool is cross-platform, being compatible with both Windows and Linux, and fully open-source, providing the community with opportunities to fork, contribute, and enhance the project. Notably, BPP emphasizes clean coding practices by avoiding the use of decompiled code, ensuring that any necessary references to such code are clearly documented.

Brovan

2026-08-03 C# ★ 160
Brovan is an interactive x86_64 binary emulator designed for the analysis and execution of untrusted software while providing advanced features for reverse engineering, API tracing, and network traffic interception. It supports multiple binary formats, leverages hardware acceleration through WHP and KVM backends, and includes a custom Vulkan graphics layer for rendering applications. Primarily aimed at cybersecurity professionals and researchers, Brovan facilitates safe program execution and detailed inspection of system calls and network activity.

cascade-protocol-dissector

2026-08-03 HTML ★ 151
Torii Gateway is a middleware solution designed to provide researchers with persistent, authenticated access to advanced inference pathways of large language models (LLMs) while bypassing tiered consumption limits imposed by commercial APIs. Its notable features include protocol reflection to mimic enterprise-tier traffic, token frame rebalancing to adjust apparent consumption rates, and session entropy injection for neutralizing identifiable session fingerprints, facilitating a seamless connection to multiple inference providers without altering client-side code. This tool serves as a crucial resource for overcoming restrictions that hinder research and experimentation with frontier LLM capabilities.

chomper

2026-08-03 Python ★ 621
Chomper is a lightweight emulation framework designed for security algorithm testing in iOS executables and libraries, with limited support for Android native libraries. It supports the emulation of ELF and Mach-O binaries and integrates with the Unicorn engine for dynamic analysis, allowing users to engage with Objective-C runtime and directly manipulate security algorithms. Notable features include automatic loading of iOS system libraries and comprehensive API support for invoking functions and managing memory.

cutter

2026-08-03 C++ ★ 19572
Cutter is a free and open-source reverse engineering platform designed for reverse engineers, featuring advanced customization capabilities while prioritizing user experience. It supports various plugins, including Python and C++ integrations, and enables seamless use of tools like the Ghidra decompiler. Cutter is accessible on major platforms, including Linux, macOS, and Windows, with detailed documentation available for users and developers.

Detect-It-Easy

2026-08-03 JavaScript ★ 11456
Detect It Easy (DiE) is a versatile file type identification tool designed for malware analysts and cybersecurity experts, employing both signature-based and heuristic analysis to deliver accurate file inspections across Windows, Linux, and MacOS platforms. Its key features include flexible signature management for customizable detection rules, a JavaScript-like scripting capability for tailored analysis, and a comprehensive support for various executable and archive formats. The tool aims to minimize false positives, making it an essential resource for digital forensics and malware detection.

DIE-engine

2026-08-03 C++ ★ 3244
DIE-engine is a software tool that provides both GUI and console interfaces for Detect It Easy (DiE), which is designed for analyzing file formats and detecting packers and compilers used in executable files. Its primary use case is for cybersecurity professionals and reverse engineers who need to identify binary file characteristics quickly. Notable features include support for a wide range of file types and the ability to analyze executable files efficiently.

edge

2026-08-03 Dart ★ 506
Openstrap Edge is a mobile application designed to enable the use of the WHOOP 4.0 band without a subscription, processing health data locally on both iOS and Android devices. It utilizes its own algorithms based on public research rather than WHOOP's proprietary formulas, ensuring user privacy as data is not transmitted to external servers. The tool addresses the issue of subscription-locking by allowing users to maintain functionality of their hardware independently.

Embedded-Hacking

2026-08-03 C ★ 212
Embedded Hacking is a comprehensive educational resource designed for individuals interested in embedded software development and reverse engineering. The course offers step-by-step tutorials, specifically focused on working with the Raspberry Pi Pico and includes practical skills such as live variable hijacking, command line operation, and breadboarding. Key features include a free downloadable course book, video tutorials, and links to necessary hardware and skills prerequisites.

GhidrAssistMCP

2026-08-03 Java ★ 710
GhidrAssistMCP is a Ghidra extension that delivers an MCP (Model Context Protocol) server, facilitating seamless interaction between AI analysis tools and Ghidra's reverse engineering capabilities via a standardized API. Key features include support for various communication transports, built-in analysis tools, asynchronous task execution, and comprehensive logging to enhance usability and performance in multi-program environments. This extension empowers users to leverage AI-driven insights during the reverse engineering process through a dynamic and configurable interface.

glaurung

2026-08-03 Rust ★ 31
Glaurung is a modern reverse engineering framework that aims to provide an AI-native binary analysis experience, effectively serving as a contemporary alternative to Ghidra. Utilizing Rust for performance and Python for accessibility, it integrates AI throughout the analysis pipeline, offering capabilities like automated format detection and decompilation for x86/x64 and ARM architectures. Notable features include a persistent knowledge base, a Python API for scripting, and built-in AI tools, making Glaurung suitable for both automated analysis and advanced reverse engineering workflows.

Go-Hacking

2026-08-03 Go ★ 379
Go Hacking is a comprehensive online tutorial designed for reverse engineering Golang applications, utilizing x64, ARM64, and ARM32 architectures. It systematically guides users through the process of setting up a development environment, debugging, and hacking various aspects of Go programs, including primitive types and control flow. Notable features include step-by-step lessons, free downloadable resources, and a focus on hands-on learning that caters to both beginners and seasoned practitioners in the field of reverse engineering.

hcaptcha-hsj-hsw-reversed

2026-08-03 JavaScript ★ 57
The "HCAPTCHA HSJ HSW Reversed" tool offers byte-accurate extraction of master keys from hCaptcha's JavaScript bundles `hsj.js` and `hsw.js`, revealing six build-static AES-256 master keys in under twenty-five seconds. Its primary use case is for capturing and verifying keys used in encrypted communications by leveraging a reverse-engineered AES-256-CTR cipher, ensuring all keys are verified through structured analysis. Notable features include deterministic fingerprinting for builds and end-to-end verification for five of the keys, enhancing reliability in cryptographic applications.

HikariSystem-HexCore

2026-08-03 TypeScript ★ 27
HikariSystem HexCore is an open-source IDE designed for reverse engineering, binary analysis, and controlled emulation within the VS Code environment. It features a comprehensive disassembly and decompilation pipeline, supporting targeted analyses of PE and ELF binaries, and offers automated batch processing for pipeline tasks. Notably, it integrates sophisticated tools like LLVM IR lifting, semantic queries via HikariSystem Query Language, and a vulnerability audit engine, positioning itself as a powerful solution for analyzing complex binaries and improving the reverse engineering workflow.

ImHex

2026-08-03 C++ ★ 54616
ImHex is a powerful hex editor designed for reverse engineers and programmers, providing a user-friendly interface suitable for working in low-light conditions. Its primary use case includes inspecting binary files and conducting memory analysis, with notable features such as plugin support, an online version, and comprehensive documentation. This tool enhances visibility and usability with its built-in dark theme and various customization options, facilitating efficient data manipulation and analysis.

jingle

2026-08-03 Rust ★ 38
`jingle` is a tool for modeling and analyzing Ghidra's `p-code` using SMT (Satisfiability Modulo Theories) logic, specifically within the context of formal verification and program analysis. It features a Configurable Program Analysis algorithm that allows for flexible custom analyses of `p-code` operations, leveraging a high-level Rust API and providing Python bindings for integration with existing tools. This alpha software is intended for research purposes, facilitating the generation of SMT models and supporting the disassembly and analysis of hex-encoded instructions.

Kreo-Hive65-Rgb-Linux

2026-08-03 Python ★ 31
Kreo Hive 65 is a Linux utility for controlling the RGB lighting of the Kreo Hive 65 keyboard without requiring Windows software. It allows users to set individual key colors, create gradients, and utilize an audio-reactive mode that transforms the keyboard's lighting into a dynamic visualizer synchronized with sound output. Notable features include the ability to run complex lighting effects based on audio input, with customizable options via command-line parameters.

Nauz-File-Detector

2026-08-03 C++ ★ 582
Nauz File Detector is a portable utility designed to identify linkers, compilers, and packers used in files across macOS, Linux, and Windows platforms. Its primary use case is for reverse engineering and malware analysis, providing users with the ability to quickly analyze file formats. Notable features include cross-platform compatibility and easy access to detailed documentation for setup and usage.

Orion

2026-08-03 Objective-C ★ 115
Orion is a local AI runtime designed explicitly for training and running small language models (LLMs) on Apple Silicon devices utilizing the Neural Engine (ANE) for enhanced performance. It bypasses traditional frameworks such as CoreML, offering features like direct ANE training, delta compilation for efficient weight reloading, and LoRA hot-swap capabilities, all while ensuring that data remains on-device for privacy. The tool targets a unique niche, leveraging the dedicated NPU in Apple's hardware to optimize both model training and inference, achieving superior speed and efficiency compared to standard CPU or GPU-based solutions.

P2-FR-IS-PSP

2026-08-03 Python ★ 54
The repository provides a comprehensive French translation patch for the PSP game "Persona 2: Innocent Sin" (ULES01557), enabling users to play the game entirely in French. Key features include a fully playable main storyline, modifications to dialogue formatting, and ongoing updates to enhance the patch, which is built alongside custom romhacking tools tailored for the game. The project emphasizes legal use, requiring users to obtain their original game disc to apply the patch.

PCM-Forge

2026-08-03 Python ★ 29
PCM-Forge is an open-source activation code generator and diagnostic toolkit specifically designed for Porsche PCM 3.1 infotainment systems, utilizing a fully cracked RSA-64 encryption algorithm to generate activation codes for any vehicle identification number (VIN) at no cost. The tool features a web application that includes functionalities for creating activation codes, building USB sticks for installation, and providing modular diagnostic utilities tailored for various Porsche models, ensuring compatibility with different hardware revisions.

pharos

2026-08-03 C++ ★ 1724
The Pharos Static Binary Analysis Framework facilitates automated analysis of binary programs, leveraging the ROSE compiler infrastructure for disassembly, control flow analysis, and instruction semantics. Notable features include the OOAnalyzer for object-oriented construct recovery, ApiAnalyzer for detecting API call sequences, and tools like FN2Yara and FN2Hash for generating signatures and properties for function analysis. The framework is designed for research purposes and actively supports discussions in the domain of binary static analysis.

Phobos

2026-08-03 C++ ★ 447
Phobos is a community-driven engine extension for Yuri's Revenge that enhances gameplay by introducing new features and fixes based on modified YRpp and SyringeEx for code injection. It is designed to complement the existing Ares tool without introducing incompatibilities, offering users both stable and development builds for testing and integration of new features. Key attributes include its independence from Ares, active community engagement, and the ability to provide nightly builds with the latest changes for development purposes.

pokestadium

2026-08-03 C ★ 198
Pokemon Stadium (US) is a work-in-progress decompilation project that allows users to build a functioning ROM for the game Pokemon Stadium (US) from its source code. The tool requires a pre-existing ROM and enables users to initialize and reassemble the game through a straightforward make process. Notable features include support for various system dependencies and a Python-based build environment, making it accessible for users familiar with development practices.

radare2

2026-08-03 C ★ 24690
Radare2 is a comprehensive reverse engineering framework designed for Unix environments, providing a suite of tools and libraries to facilitate tasks such as binary analysis, disassembly, and debugging. Notable features include support for scripting through an embedded JavaScript interpreter, local and remote debugging capabilities, and extensive plugin architecture that enables users to extend its functionality with various plugins. This tool is especially aimed at security researchers and developers looking for powerful solutions in binary exploitation and reverse engineering.

redasm

2026-08-03 C++ ★ 1799
REDasm is a free and open-source disassembler tailored for reverse engineering, catering to both hobbyists and professionals. Its plugin architecture allows for extensibility and supports various CPU architectures and executable formats, making it a versatile tool in the reverse engineering toolkit. The latest version, 4.0.0, features a completely redesigned foundation, enhancing its performance and usability.

Redline-Vidar-NJRat-Raccoon-C2-Panel

2026-08-03 HTML ★ 153
Lumina Sentinel is a behavioral anomaly detection and orchestration framework designed for security researchers and threat analysts to analyze the behavior of credential stealers and remote access trojans (RATs) in a controlled environment. Its notable features include a Behavior Replay Engine that reconstructs infostealer actions with MITRE ATT&CK™ mapping, real-time process tree visualization via D3.js, and multilingual intelligence reporting to facilitate global collaboration. The framework emphasizes security and education by operating in isolated containers without affecting the host system.

Reverse-Engineering

2026-08-03 Assembly ★ 14206
The "Reverse Engineering" repository provides a thorough and free tutorial series focused on reverse engineering across multiple architectures, including x86, x64, ARM, AVR, and RISC-V. Its primary use case is to educate users on the principles and techniques of reverse engineering, complemented by practical resources such as tool links, a Ghidra plugin, and a companion e-book. Notable features include hands-on challenges and links to additional hacking courses and CTFs designed to deepen practitioners' understanding of embedded systems and software security.

setup-ghidra

2026-08-03 TypeScript ★ 16
The Setup Ghidra Action automates the process of configuring a Ghidra environment within GitHub Actions. It allows users to specify different Ghidra versions, including custom forks, while automatically setting the `GHIDRA_INSTALL_PATH` environment variable, facilitating the building of projects that depend on Ghidra. Notable features include support for version control, the ability to specify download URLs, and integration with GitHub's authentication for API calls.

sm64ds-decomp

2026-08-03 C++ ★ 139
The Super Mario 64 DS Decompilation (sm64ds-decomp) project offers a comprehensive decompilation of the Super Mario 64 DS game into matching C source code, aiming to produce a binary identical to the original retail ROM. Notable features include a systematic verification process for function matching using automated templates and manual coding, a progress tracking treemap, and an emphasis on maintaining legal compliance by avoiding the inclusion of ROM data or assets. The repository serves as a collaborative platform for contributors to enhance and refine the decompilation effort.

TryHackMeWriteups

2026-08-03 Python ★ 17
TryHackMeWriteups is a comprehensive repository that curates free TryHackMe rooms, providing organized resources for cybersecurity enthusiasts to learn and practice various skills. Notable features include categorized rooms across diverse topics, detailed notes and summaries, step-by-step writeups for Capture The Flag challenges, and continuous updates, making it an ideal starting point for beginners in cybersecurity and ethical hacking.

unbrowse

2026-08-03 TypeScript ★ 740
Unbrowse is a tool designed for AI agents to efficiently learn and interact with a website's first-party API routes. It allows for fast replay of known routes to perform tasks without the overhead of rendering a browser, while still providing the option to use browser automation for cases like authentication and CAPTCHA. Notable features include a shared learning mechanism for route metadata, a versatile command line interface, and an SDK for TypeScript developers.

Void-Engine-GD

2026-08-03 HTML ★ 73
Project Chisel is a comprehensive modding toolkit for Geometry Dash, enabling developers and reverse engineers to deeply analyze and modify the game through a robust framework built on full decompilation analysis. It features a precision modification engine that allows granular control over game systems, seamless integration with the Geode mod loader, and a responsive UI framework for custom in-game menus. Notable capabilities include non-destructive overrides, automated patching for version-specific binaries, and multilingual support for localized modding experiences.

Win11Src

2026-08-03 C ★ 31
The Win11Src repository contains a partially leaked version of the Windows 11 source code, primarily derived from extracted resources, modified legacy files, and officially released components from Microsoft. Its primary use case is for educational and research purposes, allowing users to explore the inner workings of Windows 11 and its architecture. Notable features include a collection of fragments from DLLs obtained via ResHacker and contributions from other non-Microsoft open-source projects.

XAPKDetector

2026-08-03 C++ ★ 693
XAPKDetector is a cross-platform tool designed for detecting and analyzing Android APK and DEX files, providing information on build tools, libraries, and security protections. Its primary use case lies in aiding developers and security analysts in assessing the integrity and characteristics of APK files. Notable features include comprehensive reporting on the application's components and support for multiple operating systems including Windows, Linux, and MacOS.

zemer-cipher

2026-08-03 Kotlin ★ 26
Zemer-Cipher is an Android library designed for YouTube cipher deobfuscation and PoToken generation, facilitating the extraction of streaming URLs from obfuscated JavaScript. Key features include signature cipher deobfuscation, n-parameter transformations to mitigate throttling, and remote-updateable player configurations that allow real-time updates without requiring app releases. This library is crucial for applications leveraging the YouTube API to maintain functionality amid frequent player script rotations.

bitspec

2026-08-03 Python ★ 15
Bitspec is a bit pattern mini-language tool designed for specifying instruction encodings, converting byte input into an intermediate representation (IR). Its primary use case is in reverse engineering or developing code for architectures like Z80, allowing users to define bit patterns and corresponding operations easily. Notable features include the ability to parse bytecode and generate structured output, as well as comprehensive documentation and example usage provided for developers.

blindsight

2026-08-03 C ★ 21
Blindsight is a high-density hex viewer designed for visual pattern matching and manipulation of binaries under 1MB, primarily aimed at reverse engineering and one-off CTF tools. Notable features include support for live code reload to facilitate rapid prototyping with C scripts, the ability to extend and customize views using C libraries, and a focus on encouraging innovative analysis of binary data.

Flagy

2026-08-03 Shell ★ 11
Flagy is a comprehensive toolkit designed for Capture The Flag competitions, integrating a wide array of cybersecurity tools across multiple domains including cryptography, forensics, reversing, steganography, and web security. Notable features include automated cryptanalysis tools, credential dumping utilities, and advanced reversing frameworks like Ghidra and radare2, all aimed at facilitating the installation and use of essential tools for both beginners and advanced users in security challenges.

flarevm-up

2026-08-03 HCL ★ 20
flarevm-up automates the provisioning of Windows 10 virtual machines with FLARE VM tools installed, specifically designed for digital forensics and malware analysis. This tool utilizes Vagrant and VirtualBox to quickly set up multiple environments for blue team operations, facilitating rapid deployment for analysis tasks. Notable features include seamless integration of necessary forensic tools and straightforward setup instructions.

karkinos

2026-08-03 Python ★ 197
Karkinos is a comprehensive library database tool designed for binary exploitation on Linux, facilitating the identification of unknown libraries and their associated symbols. It provides capabilities to locate library packages, dump useful symbols and gadgets for return-oriented programming (ROP), and supports various architectures, including x86, ARM, and more, by indexing a wide range of libraries like glibc and libstdc++. Key features include commands to find libraries by offsets, dump detailed library information, and update the internal database autonomously.

RE-helper

2026-08-03 C++ ★ 16
RE-helper is a reverse engineering tool designed to assist with solving challenges during Capture the Flag (CTF) contests. It allows users to set up an environment for analyzing executables, offering features like dynamic tracing and syscalls logging, with capabilities for testing modifications and cleaning builds. The tool is currently in development and primarily targets amd64 architecture.

pwndra

2026-08-03 Python ★ 708
Pwndra is a collection of utilities designed to enhance the Ghidra reverse engineering environment, specifically for pwn and Capture the Flag (CTF) challenges. Key features include the ability to replace constants with human-readable counterparts, annotate system calls and their arguments, conveniently convert character representations, and quickly navigate to the main function of binaries. This toolset streamlines the analysis workflow, improving usability for cybersecurity practitioners working with various CPU architectures.

CTF-Resources

2026-08-03 ★ 10
The CTF Resources repository is a comprehensive collection of cybersecurity tools and practice platforms specifically designed for Capture the Flag (CTF) competitions. It includes an extensive array of tools categorized into areas such as Open Source Intelligence (OSINT), steganography, and anonymous communication, offering functionalities from data gathering and analysis to secure and anonymous internet browsing. Notable features include links to various open-source tools, detailed descriptions, and categorization for ease of use, supporting users in enhancing their digital security skills.

HackGurat

2026-08-03 ★ 24
HackGurat is a cybersecurity resource platform that offers a wide array of expertise in fields such as web security, cryptography, reverse engineering, and more. It features educational platforms and useful links for further learning, alongside a section for write-ups and PDF resources, facilitating both skill development and practical understanding in cybersecurity. The tool aims to be a comprehensive hub for cybersecurity professionals and enthusiasts to enhance their knowledge and skills through curated content and resources.

reversing-utils

2026-08-03 C++ ★ 10
My Reversing Utils is a collection of open-source tools designed for reversing, debugging, and software analysis, offering utilities for process management as well as web and binary analysis. Key features include the ProcSuspender, which enables users to launch processes in a suspended state for detailed debugging. This repository serves as a practical resource for security researchers and developers looking to facilitate their software analysis tasks.

reversingBits

2026-08-03 HTML ★ 646
The Reversing Bits Cheatsheets repository serves as a comprehensive resource for assembly programming, reverse engineering, and binary analysis tools. It includes in-depth guides on installation, usage examples, and advanced tips for a variety of tools, such as assemblers, debuggers, disassemblers, and binary analysis frameworks, catering to different operating systems and user needs in the field of cybersecurity. Notably, it features prominent tools like Ghidra, IDA Pro, and GDB, making it a valuable reference for professionals involved in security and malware analysis.

cheatengine-mcp-tcp-bridge

2026-08-03 Lua ★ 47
The Cheat Engine MCP Bridge — TCP Enhanced Edition is a tool that facilitates remote control of Cheat Engine via a native C TCP bridge, eliminating the need for Python's pywin32 dependency and supporting multiple instances. Key features include built-in remote access via environment variables, improved stability with auto-reconnect capabilities, and a dedicated diagnostic console, making it a more versatile and reliable option compared to the original fork.

Common-CTF-Challenges

2026-08-03 Python ★ 144
Common-CTF-Challenges is a comprehensive resource for Capture the Flag (CTF) competitions, providing categorized notes, command references, and ready-to-use Python scripts for various exploitation techniques including cryptography, binary exploitation, web vulnerabilities, and forensics. Notable features include a structured directory for easy navigation and search functionality using tools like `grep` and `ripgrep` to quickly locate relevant resources during challenges. This tool serves as a practical aid for participants by consolidating essential techniques and scripts in a single, accessible repository.

CTF_tools

2026-08-03 ★ 390
CTF Tools is a curated repository that aggregates a variety of resources, websites, and tools specifically designed to assist in solving Capture The Flag (CTF) challenges. It organizes tools by category, providing practical links ranging from ASCII tables to cryptographic calculators, thus serving as a quick reference resource for CTF participants and teams during competitions. Notable features include a wide assortment of utility tools for cryptography, data conversion, and training resources, as well as guidelines for collaborative contributions to the repository.

libdebug

2026-08-03 Python ★ 311
libdebug is a Python library designed for programmatic debugging of userland binary executables, aimed primarily at developers and researchers in reverse engineering and exploitation. Its notable features include the ability to access process memory and registers, control execution flow, handle syscalls and signals, and debug multithreaded applications, all while emphasizing high performance. The tool provides seamless integration with GDB for interactive analysis and supports debugging on various Linux architectures.

ScallopShell

2026-08-03 C++ ★ 19
Scallop Shell is a specialized debugger and decompiler designed to analyze polymorphic code in binary executables across Linux and macOS. It differentiates itself from traditional reverse engineering tools by dynamically disassembling memory, providing real-time views of executing instructions, and facilitating live patching of byte displays. Notable features include architecture specification for QEMU binaries, a streamlined command-line interface, and capabilities for direct memory editing, making it particularly suited for handling complex binary obfuscation.

sentinel-reverse

2026-08-03 Python ★ 78
sentinel-reverse is an AI-powered autonomous binary reverse engineering tool designed to enhance the efficiency of analyzing complex binaries by automating traditional manual processes. It features capabilities such as AI-driven function decompilation, LLM-based semantic inference for variable naming, and context-aware vulnerability detection, enabling analysis of 50-200 functions per hour with complete data privacy and zero API costs. This tool leverages GPU acceleration and incorporates a multi-round confidence-driven analysis to optimize the reverse engineering workflow.

anti-debugger-bypass

2026-08-03 JavaScript ★ 14
Anti-Debugger Bypass is a Chrome extension designed to circumvent various client-side JavaScript anti-debugging mechanisms that can disrupt developer tools. It features capabilities such as intercepting `eval("debugger")` calls, preventing aggressive script redirects, and protecting console outputs while providing a smooth debugging experience for security researchers and penetration testers. The extension injects scripts to neutralize traps at the document start, ensuring that users can explore and inspect web elements without interference from anti-debugging practices.

h1-asset-fetcher

2026-08-03 Python ★ 41
H1 Asset Fetcher is a command-line tool designed for bug bounty hunters to efficiently fetch, download, and decompile mobile app assets from various bug bounty programs like HackerOne and Bugcrowd. It offers a user-friendly, interactive prompt to guide users through selecting assets across Android, iOS, and executable files, with features including bulk downloading, asset decompilation using JADX, and credential management for streamlined repeated usage.

ios-26-activation-research

2026-08-03 C ★ 31
The iOS 26 Activation Lock repository documents 31 firmware-level vulnerabilities found in iOS 26.3, specifically targeting the activation lock subsystem. It serves primarily as a resource for the security research community, featuring self-contained writeups for each vulnerability, ranking from critical to less severe, along with proof-of-concept implementations and exploitation scripts. Notable features include detailed descriptions, reproduction steps, and evidence for each finding, aiding researchers in understanding and possibly mitigating the identified security issues.

Apkx-Hunter

2026-08-03 C ★ 87
APKX-Hunter is a comprehensive open-source Android Static Analysis Framework developed in C, tailored for security assessments, malware analysis, and penetration testing of Android applications. It supports a wide array of package formats and features advanced capabilities such as recursive multi-APK scanning, integration of OWASP MASVS compliance checks across 15 categories, and a machine learning-based secret classification engine for efficient vulnerability prioritization. Notable features include detailed scan statistics, various decompilation methods, and streamlined integration for Debian systems, making it a robust tool for security researchers.

Awesome-Hacking

2026-08-03 ★ 119426
Awesome Hacking is a comprehensive repository that aggregates a wide range of curated lists and resources tailored for hackers, penetration testers, and security researchers. Its main use case is to provide an easily navigable collection of tools and knowledge across various domains of cybersecurity, such as application security, bug bounty programs, and incident response. Notable features include links to numerous specialized topics like Android security, fuzzing, and IoT security, facilitating both learning and practical application in penetration testing and security assessments.

Facebook-SSL-Pinning-Bypass

2026-08-03 Shell ★ 19
Facebook SSL Pinning Bypass is a tool designed to circumvent SSL/TLS certificate pinning in the Facebook app on Android devices, enabling users to intercept and analyze HTTPS traffic. It supports both rooted and non-rooted devices and functions with various proxy tools such as Burp Suite and mitmproxy. The tool provides a patched APK for different architectures, facilitating ease of use for security testing and debugging activities.

Instagram-SSL-Pinning-Bypass

2026-08-03 Shell ★ 19
The Instagram SSL Pinning Bypass tool allows users to disable certificate pinning in the Instagram app on Android devices, enabling the interception and analysis of HTTPS traffic. It is especially useful for security researchers and developers who wish to inspect API endpoints and media delivery while supporting both rooted and non-rooted devices. Key features include compatibility with multiple Android architectures and the availability of patched APKs for specific Instagram versions.

TIKTOK-SSL-Pinning-Bypass

2026-08-03 Shell ★ 106
TIKTOK-SSL-Pinning-Bypass is a tool designed for security researchers and developers to bypass SSL certificate pinning in the TikTok app on Android devices, facilitating the interception and analysis of HTTPS traffic. Its notable features include compatibility with both rooted and non-rooted devices, support for various proxy tools, and recent enhancements that allow full functionality on Android 11 and above, including the capture of login and registration traffic. The tool provides a pre-patched TikTok APK, enabling users to inspect API calls and the app's network interactions seamlessly.

HexraysToolbox

2026-08-03 Python ★ 485
HexRays Toolbox (hxtb) is a versatile set of IDAPython scripts designed for identifying and analyzing code patterns in binaries across various processor architectures. Its primary use cases include vulnerability scanning, malware analysis, and proving code similarities, thus making it valuable for security analysts and reverse engineers. Notable features include a user-friendly GUI via hxtb_shell for query formulation, custom scripting capabilities, and batch processing scripts for enhanced automation.

firmware-analysis-toolkit

2026-08-03 Python ★ 1583
The Firmware Analysis Toolkit (FAT) is designed to assist security researchers in analyzing and identifying vulnerabilities within IoT and embedded device firmware by providing automated firmware emulation capabilities based on Firmadyne. Key features include the ability to run firmware images in a controlled environment without the need for a PostgreSQL database, as well as streamlined setup and interaction via Python scripts, enabling real-time testing and network interface configuration.

SCOUT

2026-08-03 Python ★ 10
SCOUT is an advanced firmware analysis platform designed for product security and internal red-team operations, transforming raw firmware blobs into evidence-backed exploitability chains and lab-bounded proof-of-vulnerability modules. It features a hybrid analysis engine capable of auditing both ELF binaries and shell scripts, emphasizing controlled weaponization and audit-ready reporting while reducing false positives. Notably, SCOUT prioritizes detailed evidence lineage and supports a structured approach to exploit development, favoring higher fidelity over traditional bulk scanning techniques.

cwe_checker

2026-08-03 Rust ★ 1353
cwe_checker is a static analysis tool designed to identify common software vulnerabilities, specifically by detecting classes of bugs known as Common Weakness Enumerations (CWEs) in ELF binaries across multiple CPU architectures. It leverages Ghidra for disassembly and utilizes a plugin-based, extensible architecture that supports customizable analyses, making it a useful resource for firmware analysis on Linux and Unix systems. Notable features include easy setup via Docker, support for various architectures, and the ability to integrate with the FACT framework for enhanced analysis capabilities.

DLL-Hijacking-Vulnerability-Scanner

2026-08-03 C++ ★ 11
DLL Hijacking Vulnerability Scanner is a specialized tool for identifying DLL hijacking vulnerabilities within signed Windows executable files. It features automated scanning, DLL dependency analysis, and comprehensive filtering options, enabling security professionals to test executables for hijacking susceptibility and analyze their DLL loading behaviors, as well as generating detailed vulnerability reports.

Awesome-Hacking-Learning-Path

2026-08-03 ★ 31
Awesome Hacking & Cybersecurity Learning Path is a comprehensive resource designed to guide individuals from beginner to advanced levels in ethical hacking, penetration testing, and cybersecurity. It features curated materials on bug bounty hunting, OSINT tools, CTF challenges, and practical exercises for real-world scenarios, alongside essential concepts in networking and web application security. Notable features include detailed roadmaps for penetration testing, hands-on labs from platforms like TryHackMe and HackTheBox, and extensive coverage of privilege escalation techniques across multiple operating systems.

intel-codex

2026-08-03 Shell ★ 50
Intel Codex is a comprehensive operational manual designed for digital investigators and security analysts, emphasizing OSINT methodologies and security protocols. It features over 40 standard operating procedures (SOPs), guides for various social media platforms, and case studies that illustrate practical applications in real-world investigations. Notable elements include legal and ethical compliance frameworks, detailed investigation techniques, and a focus on malware analysis and penetration testing methods.

gditools3

2026-08-03 Python ★ 14
gditools3 is a Python library and command-line tool designed for managing GD-ROM image (GDI) files, facilitating the listing, extraction, and generation of various file formats including sorttxt and boot sector (IP.BIN). The tool supports both Python 2 and 3, offers a graphical user interface for ease of use, and maintains file timestamps during extraction, while also providing functionality suitable for integration into other Python applications. Notable features include support for different data track formats and media playback capabilities via an external player.

samba-de-amigo-2k_modding

2026-08-03 Python ★ 15
The Samba de Amigo 2K Modding toolset provides resources and utilities for modding the Dreamcast version of the rhythm game "Samba de Amigo: Ver. 2000." Key features include a console script for analyzing and converting AMG files, the ability to import Wii songs into the Dreamcast GDI image, and detailed file descriptions for enabling English translations and custom content. Future enhancements aim to simplify GDI modding and expand song import options from various sources.

witchcraft

2026-08-03 Rust ★ 52
WITCHCRAFT is an advanced cybersecurity toolkit designed for professionals engaged in operational security (OPSEC), offering functionalities for hacking, OSINT, and forensic analysis. Key features include a modular command structure for tasks such as port scanning, data mapping, and searching for keywords across numerous platforms, bolstered by a comprehensive spellbook containing unique wordlists and databases for enhanced reconnaissance. This tool serves as an all-in-one cyberdeck system for efficient data-ghosting, network penetration, and threat analysis.

ZYRA

2026-08-03 Zig ★ 83
ZYRA is a Zig-based obfuscator, packer, and loader aimed at safeguarding executable files against static analysis and reverse engineering. Its notable features include performance optimization through Zig, the ability to generate complex control flow to hinder reversing efforts, and runtime decryption for secure execution of payloads. Currently, ZYRA supports Linux, with straightforward installation and usage options for packaging executables.

AArch64-Bytes

2026-08-03 Assembly ★ 21
AArch64 Bytes is a collection of concise articles aimed at enhancing the reverse engineering skills for AArch64 ARM 64 Linux binaries. The tool provides practical insights through bite-sized lessons on critical concepts such as syscalls and register manipulation, making it a valuable resource for developers and security researchers interested in ARM architecture. Notable features include step-by-step tutorials and links to deeper articles on Medium for further exploration of specific topics.

Dreamcast-Disassembly-Debugging-and-Decompilation-Diaries

2026-08-03 Python ★ 21
The Dreamcast Disassembly, Debugging, and Decompilation Diaries repository provides tools and resources for reverse-engineering Sega Dreamcast games. Primarily aimed at developers and hobbyists, it facilitates the extraction of data from GD-ROM images, disassembly and decompilation of Dreamcast binaries using Ghidra, and interactive debugging via Flycast as a GDB server. Notable features include recommended scripts and databases for Ghidra, along with general resources and tools to enhance the reverse-engineering experience.

yaralyzer

2026-08-03 Python ★ 153
Yaralyzer is a tool designed for the visual inspection of regex and YARA matches within binary and text files, allowing users to view the actual bytes matched along with their surrounding context. It supports scanning with customizable regex patterns or YARA rules, detecting potential character encodings of matched bytes, and can display results in various formats such as SVG and HTML. Notable features include the ability to force different character encodings on matched regions and export findings in a visually appealing format, facilitating deeper analysis of patterns within data.

CyberElite

2026-08-03 ★ 18
Awesome-Hacking is a comprehensive resource hub designed for hacking, pentesting, and security research, providing a curated collection of tools and materials beneficial for System and Network Administrators, DevOps professionals, and security researchers. Notable features include its repository of daily use tools, practical navigation through a simple Table of Contents, and an open-source nature that encourages contributions from users. The repository serves as a valuable reference point for anyone interested in cybersecurity.

Hacking-Rust

2026-08-03 Rust ★ 239
Hacking Rust is a comprehensive online tutorial designed to teach reverse engineering techniques for Rust programming, specifically targeting x64, ARM64, and ARM32 architectures. It includes step-by-step lessons covering various concepts such as debugging, scalar and compound data types, and functions, with an emphasis on hands-on hacking exercises. Notable features include a free downloadable book and a structured approach that guides users from basic Rust programming to more complex reverse engineering tasks.

sqlite3_page_explorer

2026-08-03 HTML ★ 23
Sqlite3 Page Explorer is an Electron-based application that enables users to open and explore SQLite databases, allowing for in-depth examination of their internal structures, including schemas, tables, and indices. Its notable features include hierarchical navigation of B-Tree pages, parsing of cell content, and the ability to view both current and deleted data pages, making it an essential tool for software development, ethical hacking, troubleshooting, and academic studies related to database formats.

VivisectION

2026-08-03 Python ★ 22
VivisectION is an emulation-driven toolset designed as a plugin for the Vivisect reverse engineering framework, enhancing GUI capabilities with functions for function emulation and reconnaissance. It enables users to emplace an emulator for specific functions easily, offering features such as an interactive console for dynamic analysis, and streamlined integration with other Vivisect tools. Noteworthy functionalities include function emulation via context menu operations and an interactive Python shell for advanced analyses, fostering a comprehensive environment for vulnerability research and reverse engineering.

empirectf

2026-08-03 C++ ★ 135
EmpireCTF is a comprehensive repository of Capture The Flag (CTF) write-ups that chronologically documents solutions and methodologies applied in various CTF competitions from 2018 to 2025. The primary use case of this tool is to serve as a reference for cybersecurity enthusiasts and professionals seeking to enhance their skills in solving CTF challenges. Notable features include categorized write-ups by year and challenge type, facilitating easy navigation and study of different techniques and tools utilized in the CTF landscape.

ferrox

2026-08-03 Rust ★ 35
Ferrox is a research-focused Windows stealer written in Rust, designed to harvest sensitive data including browser credentials, cryptocurrency wallet information, and messaging app sessions while employing various evasion techniques to bypass antivirus and endpoint detection systems. Its notable features include polymorphic builds, compile-time encryption of strings, direct syscall execution, anti-analysis measures, and the ability to exfiltrate stolen data via Discord or Telegram within a stealthy execution environment. The tool is intended strictly for educational purposes in understanding modern attack methodologies for enhancing cybersecurity defenses.

nightmare-exploit-roadmap

2026-08-03 Python ★ 96
The Nightmare Exploitation Roadmap is a structured educational resource designed to advance users' binary exploitation skills through a layered curriculum that emphasizes theoretical understanding and practical application. It focuses on building capabilities to analyze unknown binaries, identify exploit primitives, and develop automated exploitation techniques while navigating real-world security mitigations. Notable features include a non-linear approach to learning, preservation of module names for clarity, and a comprehensive progression from foundational knowledge to advanced exploitation strategies.

reai-r2

2026-08-03 C ★ 16
RevEng.AI Radare2 Plugin enhances the Radare2 framework with AI-driven reverse engineering functionalities, including decompilation, function analysis, and binary similarity detection. It seamlessly integrates with existing Radare2 workflows, providing automated setup scripts across multiple platforms and the capability to utilize an external API for advanced analysis tasks. Noteworthy features include a straightforward installation process, automatic library path configuration, and the generation of necessary configuration files directly through Radare2 commands.

reait

2026-08-03 Python ★ 33
Reait is a toolkit designed for the analysis of compiled executable binaries utilizing the RevEng.AI API, primarily aimed at identifying similar components, vulnerabilities, and generating advanced YARA++ REAI signatures for binary files. Notable features include the ability to extract symbol embeddings, conduct similarity searches among executable programs, and support for stripped ELF and PE binaries in both GNU/Linux and Windows environments. The tool facilitates in-depth binary analysis through commands that submit executables, retrieve analysis results, and query a database for similar symbols.

SuperLibrary

2026-08-03 Python ★ 173
SuperLibrary is an educational repository designed to provide access to a collection of books and courses aimed at individuals who may face financial constraints in obtaining these learning resources. It emphasizes ethical usage, urging users to support authors and publishers whenever possible, while also featuring a disclaimer regarding copyright and legal responsibilities. Notable features include categorized content such as books and courses, fostering self-education in various subjects.

AutoProber

2026-08-03 Python ★ 327
AutoProber is a hardware automation tool designed for probing individual pins on electronic components, facilitating hardware hacking processes. Its primary use case involves ingesting projects, identifying probe targets using a combination of a microscope and CNC-controlled hardware, and enabling users to approve or deny targets for probing, all managed through a web dashboard or Python scripts. Notable features include real-time calibration, frame stitching to create annotated maps of targets, and a robust safety model for hardware control.

awesome-blackhat-arsenal

2026-08-03 Python ★ 175
The "Awesome Black Hat Arsenal" repository is a curated collection of advanced cybersecurity tools presented at Black Hat Arsenal events, aimed at practitioners in red teaming, blue teaming, application security, and OSINT. It organizes tools by geographical location, year, and category, providing detailed descriptions, authorship, and GitHub links for each tool, facilitating easy access to cutting-edge security utilities. This resource serves as an invaluable reference for security professionals seeking to enhance their toolkit with the latest innovations in the field.

WindowsShell-Injector-Shellcode-Loader

2026-08-03 C++ ★ 15
WindowsShell-Injector is a shellcode execution framework designed for security research and penetration testing on Windows systems. It features encrypted payloads, anti-debugging mechanisms, and an intuitive Qt-based GUI, allowing for seamless loading and execution of shellcode. Notable capabilities include asynchronous execution via separate threads, dynamic memory protection, and runtime API resolution to enhance evasion of static analysis tools.

x64dbg

2026-08-03 C++ ★ 49362
x64dbg is an open-source binary debugger designed specifically for Windows, facilitating malware analysis and reverse engineering of executables without source code access. Key features include a comprehensive plugin system for extensibility, support for both 32-bit and 64-bit debugging, and a user-friendly interface that offers various tools such as memory mapping and graph visualization to enhance the debugging process.

AmongUsMenu

2026-08-03 C++ ★ 16
AmongUsMenu is a cheat menu designed for the game Among Us, intended for educational purposes to demonstrate how cheating software operates. It offers two versions, a normal DLL for injection and a proxy version that integrates directly with the game, featuring a set of hotkeys for various functionalities such as showing a menu, radar, or console. The project has been archived and is no longer actively maintained.

Scripting

2026-08-03 PowerShell ★ 56
PDB2JSON is an Azure Functions-based application designed for secure authentication of running memory in Windows systems through its extensive SHA256 hash database. The tool provides a JSON-based interface for remote interactions with a Code+PDB analysis server, enabling functionalities like symbol resolution and hash verification without uploading binary data. Its notable features include a just-in-time hashing methodology for integrity protection and automation support for memory dump analysis through various scripting examples.

udbg

2026-08-03 Rust ★ 19
udbg is a cross-platform Rust library designed for binary debugging and memory manipulation, providing uniform interfaces across various operating systems. Its primary use case is to facilitate the inspection and control of multiple debug targets without invasive attachment, supporting comprehensive target information retrieval and debugging functionalities. Notable features include support for multiple architectures, non-invasive operation modes, and capabilities for breakpoint and watchpoint management.

Autorun-ng

2026-08-03 Rust ★ 52
Autorun-ng is a versatile tool designed for launching applications with a streamlined user interface, supporting both Linux and Windows environments. Its notable features include a sandboxed filesystem leveraging cap-std for enhanced security, ergonomic Lua API bindings for seamless integration, and a zero-dependency library for accessing source engine interfaces. This tool eliminates the need for menu plugins or manual injections, making application execution efficient and user-friendly.

exploitation-grimoire

2026-08-03 Python ★ 64
PwnLand is an open-source resource designed for security researchers and CTF participants, focusing on binary exploitation techniques. It provides an extensive collection of practical examples, tutorials, and research materials on various vulnerabilities, including buffer overflows, format string vulnerabilities, heap exploitation, and kernel exploits. Notable features include structured directories for different exploitation methods, debugging guides, and challenges for hands-on practice.

gef

2026-08-03 Python ★ 8329
GEF (GDB Enhanced Features) is a powerful tool designed to enhance the functionality of GDB (GNU Debugger) for exploit development and reverse engineering across multiple architectures such as x86/64, ARM, and MIPS. Notable features include architecture agnosticism, a single installation script, full Python 3 support, and a variety of commands that optimize the debugging experience while facilitating dynamic analysis. The tool is designed to reduce cognitive load on developers by offering a more intuitive interface and extensive community contributions.

NTRGhidra

2026-08-03 Java ★ 222
NTRGhidra is a plugin for Ghidra that serves as a Nintendo DS loader, enabling users to analyze and debug DS software within the Ghidra environment. It supports Ghidra version 12.0.4 and allows for dynamic loading and unloading of overlays, enhancing the tool's functionality for developers working with Nintendo DS applications. Notable features include extension installation for Ghidra and comprehensive build instructions for developers interested in modifying the loader.

gef-extras

2026-08-03 Python ★ 182
GEF-Extras is an augmentation of the GDB Enhanced Features (GEF) framework, providing users with additional scripts and structures to enhance their debugging experience in GDB. It facilitates easy installation and integration with GEF, and is accompanied by comprehensive documentation to assist users in utilizing its capabilities effectively. Notable features include seamless installation via a simple command and ongoing community support through Discord.

haval-app-tool-multimidia

2026-08-03 HTML ★ 61
The haval-app-tool-multimidia project is an unofficial educational tool designed for reverse engineering the Haval GWM multimedia system. Its primary use case is to facilitate learning and exploration of the system's architecture and functionality without any commercial intent. Notable features include detailed documentation for understanding the inner workings and guidance on extending the tool's capabilities.

codex-red-team-prompt

2026-08-03 Python ★ 20
Codex Red Team System Prompt is a tool designed for injecting custom system prompts into OpenAI Codex, enabling the redefinition of its role and behavior. Its primary use case is for security professionals conducting authorized penetration testing, Capture The Flag (CTF) challenges, and technical exercises by allowing Codex to autonomously generate responses without user intervention. Notable features include a cross-platform automatic injection script, an emphasis on unrestrained AI collaboration, and a strict response protocol that ensures complete, actionable outputs.

educational-cybersec-tools

2026-08-03 ★ 13
The Educational Cybersecurity Tools repository serves as a comprehensive catalog of over 150 tools aimed at ethical hacking, penetration testing, and cybersecurity education. It encompasses various categories including network scanning, vulnerability assessment, and malware analysis, while emphasizing that all tools are intended for educational purposes only and may not be used for unauthorized access to systems. Noteworthy features include detailed tool descriptions, an extensive list of categories, and a focus on promoting ethical standards in cybersecurity practices.

exploits

2026-08-03 Python ★ 11
The "exploits" repository serves as a comprehensive security research and exploit development toolkit, focusing on browser vulnerabilities, post-exploitation techniques, and cloud identity attacks. It features organized content around CVE reproductions, offensive tooling with detection guidance, and written assessment deliverables, all designed for educational use and authorized security testing. Notably, it includes a contained Docker lab environment for safe execution and testing of exploit scenarios without internet access, ensuring a secure and isolated workspace for enterprise assessments.

flipper-rf-lab

2026-08-03 C ★ 17
Flipper RF Lab transforms the Flipper Zero device into a sophisticated RF analysis and research tool, featuring 15 advanced capabilities such as RF fingerprinting, adaptive signal modeling, and real-time spectrum monitoring. It enables users to perform detailed signal capture and analysis, protocol reverse engineering, and long-term logging within the 300-928 MHz frequency range. Notable functionalities include real-time activity mapping, threat modeling, and a robust modular research mode, making it suitable for professional RF forensics.

goodboy-framework

2026-08-03 ★ 295
Goodboy Framework is a comprehensive 15-stage course designed for developing and analyzing Windows malware, leveraging the Rust programming language. It equips users with practical knowledge from both offensive and defensive cybersecurity perspectives, encompassing techniques such as API hashing, process injection, and anti-debugging, while providing empirical data on evasion effectiveness against multiple antivirus engines. The framework emphasizes hands-on learning, featuring real-world detection mechanisms and adversarial thinking strategies, ensuring all content is validated through rigorous testing.

takopii

2026-08-03 Kotlin ★ 11
Takopii is a production-grade banker malware architecture designed for Android, featuring four APK specimens that encapsulate techniques from 17 real-world malware families. Its primary use case is to facilitate the study of malware detection and defense strategies, offering Kotlin source code alongside comprehensive YARA and Sigma detection rules. Notably, all specimens demonstrate zero detection across 66 VirusTotal engines, showcasing advanced evasion capabilities within a structured kill chain framework.

C-Full-Offensive-Course

2026-08-03 C ★ 10
C-Full-Offensive-Course is a bilingual educational resource designed to guide users through a comprehensive C programming curriculum focused on offensive security practices across Windows, Linux, and macOS platforms. The course comprises 216 progressive units with hands-on coding exercises, alongside a centralized codebase to facilitate learning. It emphasizes ethical usage by instructing users to conduct security labs only within authorized and isolated environments.

TABPE

2026-08-03 ★ 24
TABPE is a structured dataset tool that catalogs all PE (Portable Executable) files, including executables and libraries, from clean installations of Windows 10 Pro and Windows 11 Pro. The primary use case is for security researchers and developers who require comprehensive information about each PE file, including metadata such as headers, sections, imports, exports, and checksums, along with detailed logs of the scanning process. Notable features include the generation of a JSON file containing complete PE file details, a text file listing all detected files, and a log of inaccessible files, providing a thorough overview of the executables on the system.

HydraSoft-DLL-Hijack-Scanner-ByPass-UAC

2026-08-03 HTML ★ 129
HydraSoft is an advanced open-source tool designed for detecting DLL hijacking vulnerabilities within Windows environments, facilitating privilege escalation. It automates the analysis of executable files and their associated DLLs by scanning directory structures and import tables, thus identifying specific hijacking opportunities. Notable features include a real-time graphical user interface for centralized endpoint management and a color-coded rating system to prioritize targets based on the complexity of crafting proxy DLLs.

mkPIVM

2026-08-03 C++ ★ 421
mkPIVM is a polymorphic, position-independent shellcode virtualizer designed for Windows x86 and x64, which enables the obfuscation of raw shellcode by converting it into a virtual machine that interprets encrypted instructions. Its primary use case is enhancing the stealth of shellcode to evade signature-based detection, leveraging features such as customizable cipher families, opcode permutations, and detailed control over the virtual machine's configuration. The tool supports various operational modes, including full lifting, packing, and hybrid approaches, making it versatile for evasion techniques in offensive cybersecurity applications.

OffsetInspect

2026-08-03 PowerShell ★ 84
OffsetInspect is a PowerShell toolkit designed for byte-offset inspection, source correlation, binary comparison, and defensive detection-boundary analysis. It enables analysts to identify specific content at given byte offsets and the surrounding context, while also facilitating detection workflows inspired by ThreatCheck and offering a suite of red-team analysis and triage capabilities. Notable features include efficient file handling, contextual mapping, multi-region detection, and an in-memory approach to avoid interference with endpoint protection mechanisms.

androSecTest

2026-08-03 Go ★ 27
AndroSecTest is a security auditing tool designed for static analysis of Android applications to identify vulnerabilities and insecure behaviors. It utilizes a Docker container for easy setup and includes functionalities such as unpackaging APK files, examining application signatures, and checking for sensitive data within the application's file system. Notably, the tool facilitates interaction with connected Android devices via ADB commands, though results are currently not persisted outside the Docker environment.

iOS-Binary-Security-Analyzer

2026-08-03 Shell ★ 34
The iOS Binary Security Analyzer is a script designed for performing static analysis on iOS application binaries to identify security weaknesses such as insecure functions, weak cryptographic implementations, and missing security features like code signatures and PIE. Notable features include checks for core binary security mitigations, dynamic library dependencies analysis, and detection of anti-analysis indicators, making it a valuable tool for assessing the security posture of iOS applications on jailbroken devices.

beetle

2026-08-03 Python ★ 165
Beetle is an offline-first Application Security Intelligence Platform designed for the analysis of Android APKs and iOS IPAs, including those built with Flutter and React Native. It integrates static analysis with a focus on creating explainable workflows that correlate isolated findings into realistic attack chains, facilitating better understanding of vulnerabilities with evidence-based insights. Key features include low false-positive rates, source navigation for precise findings, and optional AI assistance for reasoning about security issues, all while maintaining data security by performing analysis locally.

ExploitHunter.app

2026-08-03 HTML ★ 12
ExploitHunter.app is an open-source offensive-security tool designed to enhance the cost-effectiveness of security research through intelligent orchestration of various AI models. It facilitates broad reconnaissance, inventory checks, and evidence gathering using budget-friendly or local models, while reserving expensive frontier models for deeper analysis and validation tasks. Key features include automated lab environments for running evaluations, local model capabilities without API costs, and a data explorer for tracking evaluation outcomes and expenses.

hexgraph

2026-08-03 Python ★ 19
HexGraph is a self-hosted tool designed for AI-assisted vulnerability research that operates entirely on local machines. It allows users to analyze binaries or firmware images by breaking down the targets into components, executing analysis tasks, and organizing findings within a structured, typed graph stored in SQLite. Notable features include a focus on local operations without telemetry, a hypothesis worklist for managing leads, and a secure environment ensuring that all interactions with potentially hostile targets occur in an isolated Docker container.

cheatengine-mcp-bridge

2026-08-03 Lua ★ 1350
The Cheat Engine MCP Bridge is a tool that leverages AI capabilities to streamline the analysis of program memory, significantly reducing the time required for reverse engineering tasks such as locating pointers, tracing operations, and documenting structures. Notable features include support for automatic memory reading and structure analysis, the ability to follow pointer chains, and disassembly functionalities, all of which transform tedious manual processes into quick, conversational queries directed at the memory. This tool is particularly useful for creating game mods, trainers, and conducting security audits efficiently.

fucking-Awesome-Hacking

2026-08-03 ★ 191
Awesome Hacking is a comprehensive aggregation of curated lists designed for hackers, pentesters, and security researchers, emphasizing various domains within cybersecurity. Its primary use case is to provide users with easy access to a diverse range of resources—including security tools, educational materials, and research documentation—facilitating knowledge sharing and skills development in the security community. Notable features include contributions from the community, a wide variety of categories such as Bug Bounty and CI/CD Attacks, and extensive resources for practical learning in cybersecurity.

mastg

2026-08-03 Python ★ 13148
The OWASP Mobile Application Security Testing Guide (MASTG) serves as a comprehensive resource for mobile app security testing and reverse engineering, aligning with the OWASP Mobile Security Weakness Enumeration (MASWE) and the Mobile Application Verification Standard (MASVS). It features detailed methodologies for validating security weaknesses and offers tools like mobile app security checklists and interactive exercises, enhancing both understanding and practical application of mobile security principles.

phantom-frida

2026-08-03 Python ★ 371
`phantom-frida` is a tool that facilitates the building of customized Android Frida Server and Gadget from source while obfuscating specific runtime identifiers to enhance stealth capabilities against detection mechanisms. Its primary use case is for authorized application testing on Android devices, providing robust verification processes through unit and fixture tests, strict input validation during builds, and smoke tests on rooted devices. Notable features include support for custom builds, detailed artifact verification, and a comprehensive configuration for various architectures and specific runtime flags to reinforce security.

emba

2026-08-03 Shell ★ 3619
EMBA is a comprehensive security analyzer specifically designed for the firmware of embedded devices, catering to penetration testers, product security teams, and developers. The tool facilitates the entire security analysis workflow, including firmware extraction, static and dynamic analysis through emulation, SBOM generation, and the creation of web-based vulnerability reports, effectively identifying potential weaknesses such as insecure components or hard-coded passwords. Its command-line interface and ability to present findings in an accessible web format enhance usability and streamline the security assessment process.

ai-website-cloner-template

2026-03-30 JavaScript ★ 32378
The AI Website Cloner Template is a sophisticated tool designed to reverse-engineer any website into a modern Next.js codebase using AI coding agents. By pointing the tool at a target URL, it performs a comprehensive analysis to extract design tokens and assets, generate component specifications, and facilitate parallelized reconstruction of the site’s sections. Key features include support for multiple AI agents, a detailed multi-phase cloning pipeline, and compatibility with modern web technologies like Next.js and Tailwind CSS.

Android-Security-Exploits-YouTube-Curriculum

2026-03-30 ★ 801
The Android Security & Reverse Engineering YouTube Curriculum is a comprehensive educational resource focused on various aspects of Android security, including exploits, reverse engineering, and vulnerabilities in mobile applications. It features a curated collection of talks and demonstrations from prominent security conferences, addressing topics like heap exploitation, mobile permissions, and countermeasures against mobile threats. Notably, it educates on advanced concepts such as Bluetooth security, malware analysis, and attack vectors affecting the Android ecosystem, making it essential for cybersecurity practitioners and researchers.

Andromeda

2026-03-30 C++ ★ 710
Andromeda is a performance-oriented tool designed for accelerating the initial reverse engineering of Android applications, leveraging its C/C++ implementation. It aims to simplify the analysis process with a straightforward command-line interface, making it accessible for security researchers and developers. Currently in early development, Andromeda highlights the potential for speed improvements over alternative solutions in the same domain.

binder-trace

2026-03-30 Python ★ 745
Binder Trace is a Python-based tool designed for intercepting and parsing Android Binder messages, functioning similarly to Wireshark for Binder communication. It requires a rooted Android device or emulator and leverages Frida for live analysis, allowing users to attach to specific processes and capture Binder transactions. Notable features include support for various Android versions, customizable structure files, and interactive controls for navigating captured data.

ddisasm

2026-03-30 C++ ★ 741
DDisasm is a high-performance disassembler that accurately translates binaries from ELF and PE formats into a reassemblable assembly code representation using the GTIRB intermediate format. Utilizing the Datalog declarative logic programming language, it derives code locations, symbolization, and function boundaries, supporting multiple instruction set architectures including x86, ARM, and MIPS. Notable features include Docker support for easy setup and integration with GTIRB for further binary analysis and manipulation.

debundle

2026-03-30 JavaScript ★ 739
Debundle is a tool designed to unpack JavaScript bundles generated by Webpack and Browserify, facilitating reverse engineering and analysis by converting minified code back into a more readable file structure. Notably, it allows users to specify configuration options for various bundling types and outputs organized directories containing the original modules, though it does not guarantee a lossless recovery of the original source code. The project is no longer maintained, and users are advised to exercise caution as it may not perform reliably on all real-world bundles.

EntityFramework-Reverse-POCO-Code-First-Generator

2026-03-30 C# ★ 715
The EntityFramework Reverse POCO Code First Generator is a tool designed to reverse engineer existing databases and generate fully customizable Entity Framework Code First POCO classes along with configuration mappings and DbContext setups. Its primary use case is to facilitate the rapid creation of data access code that mimics hand-crafted designs, enhancing readability and maintainability. Notable features include support for multiple database types (including SQL Server and PostgreSQL), customizable output through template files, and integration with Visual Studio via a VSIX installer.

fridare

2026-03-30 Go ★ 882
Fridare is an automation tool for modifying the Frida server on iOS, Android, Linux, and Windows platforms, designed to enhance security and flexibility by allowing users to change server names and ports while bypassing jailbreak detection. The tool features a dual-mode interface, offering both a robust command line and a modern graphical user interface (GUI) based on the Fyne framework, facilitating intuitive server modifications and visual feedback. Notable functionalities include cross-platform support, binary replacement, custom packaging, and dependency management, making it a comprehensive solution for Frida users across different environments.

GameTracking-Dota2

2026-03-30 C++ ★ 757
GameTracking-Dota2 is a tool designed to automate the tracking of in-game statistics and player performance in Dota 2. Its primary use case is to relieve players of the manual effort involved in monitoring game data, providing streamlined insights into gameplay trends. Notable features include integration with a broader GameTracking ecosystem and community support via Discord.

learning-reverse-engineering

2026-03-30 C ★ 750
The Learning Reverse Engineering repository provides a collection of programs aimed at enhancing skills in reverse engineering and malware analysis. It organizes content by specific concepts related to reverse engineering, delivers both source code and compiled binaries, and includes links to supplementary online courses and video playlists. Notable features include guidance on using various tools like Ghidra and IDA Pro, as well as instructions for compiling the source code with Microsoft’s C/C++ compiler.

librw

2026-03-30 C++ ★ 807
librw is a cross-platform library designed to re-implement parts of RenderWare graphics, facilitating rendering and file format conversion across various platforms. It supports DFF and TXD file formats for PS2, D3D8, D3D9, and Xbox, with rendering capabilities via D3D9 and OpenGL backends, while being particularly useful for rendering within projects like GTA. Notable features include adaptable file format support, backend rendering versatility, and ongoing compatibility for multiple platforms.

lisa.py

2026-03-30 Python ★ 743
lisa.py is a Model-Context Protocol (MCP) integration for LLDB, enabling AI assistants like Claude to interact with debugging sessions through a structured interface. It consists of a server component to handle communication and a plugin for LLDB that exposes debugging functionalities via JSON-RPC, allowing users to execute commands verbally and enhance the debugging experience with natural language processing. Notable features include the capability to create targets, manage breakpoints, control process execution, and evaluate expressions directly from the AI assistant.

makin

2026-03-30 C++ ★ 742
makin is a malware assessment tool designed to simplify the process of identifying anti-debugging techniques employed by malicious samples. It injects a DLL into the target process to monitor specific API calls, providing insights into debugger detection methods, and can generate IDA Pro scripts for setting breakpoints at the identified APIs. Notable features include the ability to hook various functions from ntdll.dll and kernelbase.dll , effectively revealing complex anti-debugging strategies.

obfuscator-io-deobfuscator

2026-03-30 TypeScript ★ 797
The Obfuscator.io Deobfuscator is a tool designed to reverse the obfuscation applied by Obfuscator.io, enabling the recovery of original scripts. Its primary use case is to facilitate code analysis and debugging by recovering strings, removing unnecessary code, and simplifying complex structures without executing untrusted code. Notable features include automatic configuration detection, improved readability through control flow restoration, and compatibility with various forks of the original obfuscator.

PyArmor-Unpacker

2026-03-30 Python ★ 748
PyArmor-Unpacker is a tool designed to unpack Python applications protected by PyArmor, specifically targeting versions prior to v8. The tool offers three methods for unpacking, with the preferred method being suitable for Python 3.9, allowing users to retrieve the original code from obfuscated .pyc files. Notable features include a detailed usage guide, support for multiple unpacking methods, and an emphasis on community contributions to address known issues and enhance functionality.

retrowrite

2026-03-30 Python ★ 742
Retrowrite is a static binary rewriter designed for x64 and aarch64 architectures, enabling the insertion of instrumentation into binaries without the need for source code, thereby supporting use cases in fuzzing and sanitization. The tool employs the symbolization technique to ensure zero overhead during binary rewriting and includes features such as AFL-coverage and ASan instrumentation, along with a variant (KRetrowrite) specifically for rewriting Linux kernel modules. Different algorithms and supported features are available for the x64 and arm64 versions, accommodating various binary types and compiler specifications.

skidfuscator-java-obfuscator

2026-03-30 Java ★ 748
Skidfuscator is a production-grade Java obfuscation tool that employs SSA form to enhance and obscure Java bytecode flow while maintaining execution efficiency. Its primary use case is to protect applications from reverse engineering by providing advanced obfuscation techniques, automatic dependency downloading, and an easy-to-configure command-line interface. Notable features include smart recovery, flow obfuscation, and out-of-the-box optimization.

Tata-Sky-IPTV

2026-03-30 Python ★ 712
The Tata Sky/Play IPTV Script generator is a tool that creates an m3u playlist containing direct streamable files, specifically designed for users with a Tata Sky subscription. It offers both an easy-to-use app and a command-line script for generating the playlist, with features like automatic login credential storage and expiration notifications for the generated playlist. This tool is primarily aimed at facilitating seamless access to subscribed channels through compatible IPTV applications.

TRADFRI-Hacking

2026-03-30 Makefile ★ 736
TRADFRI-Hacking is a project designed to facilitate the reverse engineering and customization of IKEA’s TRÅDFRI home automation products, which utilize Zigbee technology. It offers detailed resources for product teardowns, firmware manipulation, and the creation of custom hardware solutions using the TRÅDFRI modules, including tools for firmware dumping and development. Notable features include an extensive documentation of various TRÅDFRI products, customizable firmware options, and insights into hardware modifications, empowering developers to repurpose and enhance these smart home devices.

unipacker

2026-03-30 Python ★ 745
Un{i}packer is a platform-independent tool designed for the automatic unpacking of Windows Portable Executable (PE) files that have been packed using various runtime packers, thereby facilitating malware analysis. Utilizing the Unicorn Engine for emulation, it effectively handles multiple well-known packers, including ASPack and UPX, and allows for manual input of addresses for less common packers. This tool is particularly beneficial for analysts seeking to bypass challenges posed by malware obfuscation and streamline the unpacking process without requiring a Windows environment.

vivisect

2026-03-30 Python ★ 1000
Vivisect is a versatile framework that integrates disassembly, static analysis, symbolic execution, and debugging capabilities, designed for use in cybersecurity tasks. Its primary use case is to facilitate in-depth analysis of binary executables, assisting researchers and security professionals in vulnerability discovery and exploitation analysis. Notable features include Python 3 compatibility, a graphical user interface, and seamless integration with documentation for enhanced usability.

vulhunt

2026-03-30 C++ ★ 881
VulHunt is a vulnerability hunting framework aimed at assisting security researchers in identifying vulnerabilities within software binaries and UEFI firmware. Built on Binarly’s BIAS, it supports large-scale vulnerability management and integrates community-developed rulepacks while offering scanning capabilities for various binary formats, including BA2 and Binary Ninja databases. Additionally, it features an MCP server for integration with AI assistants, facilitating real-time vulnerability analysis and reporting.

.github

2026-03-22 ★ 908
Information on the WIP Custom Nintendo WiiU/3DS/2DS server and service replacements

.NET-Deobfuscator

2026-03-22 ★ 1483
Lists of .NET Deobfuscator and Unpacker (Open Source)

.NET-Obfuscator

2026-03-22 Python ★ 1464
Lists of .NET Obfuscator (Free, Freemium, Paid and Open Source )

android-unpacker

2026-03-22 C ★ 1176
Android Unpacker presented at Defcon 22: Android Hacker Protection Level 0

android-unpinner

2026-03-22 Python ★ 923
Remove Certificate Pinning from APKs

Androl4b

2026-03-22 ★ 1157
A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis

anti-emulator

2026-03-22 Java ★ 825
Android Anti-Emulator

AntiCheat-Testing-Framework

2026-03-22 C++ ★ 821
Framework to test any Anti-Cheat

AntiDBG

2026-03-22 C++ ★ 812
A bunch of Windows anti-debugging tricks for x86 and x64.

apk.sh

2026-03-22 Shell ★ 3768
Makes reverse engineering Android apps easier, automating repetitive tasks like pulling, decoding, rebuilding and patching an APK.

apkleaks

2026-03-22 Python ★ 6008
Scanning APK file for URIs, endpoints & secrets.

apkstudio

2026-03-22 C++ ★ 3899
Open-source, cross platform Qt6 based IDE for reverse-engineering Android application packages. It features a friendly IDE-like layout including code editor with syntax highlighting support for *.smali code files.

apple-knowledge

2026-03-22 Ruby ★ 1382
A collection of reverse engineered Apple things, as well as a machine-readable database of Apple hardware

AppleNeuralHash2ONNX

2026-03-22 Python ★ 1536
Convert Apple NeuralHash model for CSAM Detection to ONNX.

appmon

2026-03-22 JavaScript ★ 1618
Documentation:

AsmResolver

2026-03-22 C# ★ 1118
A library for creating, reading and editing PE files and .NET modules.

AssetRipper

2026-03-22 C# ★ 7107
GUI Application to work with engine assets, asset bundles, and serialized files

Awesome-Android-Reverse-Engineering

2026-03-22 ★ 2125
A curated list of awesome Android Reverse Engineering training, resources, and tools.

Awesome-Blackhat-Tools

2026-03-22 ★ 973
A curated list of tools officially presented at Black Hat events

awesome-executable-packing

2026-03-22 ★ 1551
A curated list of awesome resources related to executable packing

Awesome-Hacking-Resources

2026-03-22 ★ 17364
A collection of hacking / penetration testing resources to make you better!

awesome-list

2026-03-22 ★ 4081
Cybersecurity oriented awesome list

awesome-llvm-security

2026-03-22 ★ 872
awesome llvm security [Welcome to PR]

awesome-mobile-security

2026-03-22 ★ 3448
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.

Baileys

2026-03-22 JavaScript ★ 10915
Socket-based TS/JavaScript API for WhatsApp Web

BinAbsInspector

2026-03-22 Java ★ 1673
BinAbsInspector: Vulnerability Scanner for Binaries

binaryninja-api

2026-03-22 C++ ★ 1302
Public API, examples, documentation and issues for Binary Ninja

bincat

2026-03-22 OCaml ★ 1854
Binary code static analyser, with IDA integration. Performs value and taint analysis, type reconstruction, use-after-free and double-free detection

binexport

2026-03-22 C++ ★ 1201
Export disassemblies into Protocol Buffers

binsider

2026-03-22 Rust ★ 4411
Analyze ELF binaries like a boss 😼🕵️‍♂️

biodiff

2026-03-22 Rust ★ 884
Hex diff viewer using alignment algorithms from biology

botw

2026-03-22 C++ ★ 2085
Decompilation of The Legend of Zelda: Breath of the Wild (Switch 1.5.0)

CANalyzat0r

2026-03-22 Python ★ 785
Security analysis toolkit for proprietary car protocols

CAPEv2

2026-03-22 Python ★ 3458
Malware Configuration And Payload Extraction

copilot-api

2026-03-22 TypeScript ★ 3130
Turn GitHub Copilot into OpenAI/Anthropic API compatible server. Usable with Claude Code!

cp-ddd-framework

2026-03-22 Java ★ 1155
轻量级DDD正向/逆向业务建模框架,支撑复杂业务系统的架构演化!

Cpp2IL

2026-03-22 C# ★ 2605
Work-in-progress tool to reverse unity's IL2CPP toolchain.

crawlProject

2026-03-22 JavaScript ★ 1677
python爬虫项目合集,从基础到js逆向,包含基础篇、自动化篇、进阶篇以及验证码篇。案例涵盖各大网站(xhs douyin weibo ins boss job,jd...),你将会学到有关爬虫以及反爬虫、自动化和验证码的各方面知识

CTF-All-In-One

2026-03-22 C ★ 4449
CTF竞赛权威指南

CTFs

2026-03-22 C ★ 851
CTF Cheat Sheet + Writeups / Files for some of the Cyber CTFs that I've done

ctftool

2026-03-22 C ★ 1665
Interactive CTF Exploration Tool

de4py

2026-03-22 Python ★ 1002
The ultimate AI-powered toolkit for python reverse engineering

dembrandt

2026-03-22 TypeScript ★ 3280
Extract any website’s design system into tokens in seconds: logo, colors, typography, borders & more. One command.

dethrace

2026-03-22 C ★ 1181
Reverse engineering the 1997 game "Carmageddon"

dexcalibur

2026-03-22 JavaScript ★ 1123
[Official] Android reverse engineering tool focused on dynamic instrumentation automation leveraging Frida. It disassembles dex, analyzes it statically, generates hooks, discovers reflected methods, stores intercepted data and does new things from it. Its aim is to be an all-in-one Android reverse engineering platform.

droidReverse

2026-03-22 Shell ★ 2012
reverse engineering tools for android(android 逆向工程工具集)

dumpulator

2026-03-22 C ★ 857
An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general (sandboxing).

Dwarf

2026-03-22 Python ★ 1315
Full featured multi arch/os debugger built on top of PyQt5 and frida

e9patch

2026-03-22 C ★ 1097
A powerful static binary rewriting tool

edb-debugger

2026-03-22 C++ ★ 2953
edb is a cross-platform AArch32/x86/x86-64 debugger.

eDBG

2026-03-22 C ★ 764
eBPF-based lightweight debugger for Android

efiXplorer

2026-03-22 C++ ★ 1124
IDA plugin and loader for UEFI firmware analysis and reverse engineering automation

epicgames-freegames-node

2026-03-22 TypeScript ★ 1916
Automatically login and find available free games the Epic Games Store. Sends you a prepopulated checkout link so you can complete the checkout after logging in. Supports multiple accounts, login sessions, and scheduled runs.

fernflower

2026-03-22 Java ★ 4378
Decompiler from Java bytecode to Java, used in IntelliJ IDEA.

FISSURE

2026-03-22 Python ★ 2036
The RF and reverse engineering framework for everyone. Follow and ★ to show your support!

FLIRTDB

2026-03-22 Max ★ 1339
A community driven collection of IDA FLIRT signature files

Free-Auto-GPT

2026-03-22 Python ★ 2540
Free Auto GPT with NO paids API is a repository that offers a simple version of Auto GPT, an autonomous AI agent capable of performing tasks independently. Unlike other versions, our implementation does not rely on any paid OpenAI API, making it accessible to anyone.

free-one-api

2026-03-22 Python ★ 894
LLM 逆向工程接口管理 | 通过标准 OpenAI API 访问 ChatGPT / gpt4free / Bard / Claude / HuggingChat / 通义千问 等 AI 的破解版 || ChatGPT reverse engineering API management | Access all reverse engineered LLM libs by standard OpenAI API format || 免费 ChatGPT Free GPT LLM API | 逆向工程 转 OpenAI API | converts all llm libs to OpenAI API

frida-ios-dump

2026-03-22 JavaScript ★ 3818
pull decrypted ipa from jailbreak device

frida-ios-hook

2026-03-22 JavaScript ★ 1139
A tool that helps you easy trace classes, functions, and modify the return values of methods on iOS platform

Frida-Labs

2026-03-22 ★ 1235
The repo contains a series of challenges for learning Frida for Android Exploitation.

frida-scripts

2026-03-22 JavaScript ★ 1639
A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

GalaxyBudsClient

2026-03-22 C# ★ 5170
Unofficial Galaxy Buds Manager for Windows, macOS, Linux, and Android

game-hacking

2026-03-22 ★ 5414
Tutorials, tools, and more as related to reverse engineering video games.

game-reversing

2026-03-22 ★ 1575
Beginner learning materials on how to reverse engineer video games

GameTracking-CS2

2026-03-22 Slang ★ 940
📥 Game Tracker: Counter-Strike 2

GARbro

2026-03-22 C# ★ 3023
Visual Novels resource browser

GDA-android-reversing-Tool

2026-03-22 Java ★ 4687
the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which supports malicious behavior detection, privacy leaking detection, vulnerability detection, path solving, packer identification, variable tracking, deobfuscation, python&java scripts, device memory extraction, data decryption, and encryption, etc.

geacon

2026-03-22 Go ★ 1262
Practice Go programming and implement CobaltStrike's Beacon in Go

Gemini-API

2026-03-22 Python ★ 3456
✨ Reverse-engineered Python API for Google Gemini web app

GenP

2026-03-22 AutoIt ★ 1178
This repository preserves source materials and related documentation about GenP tool. For archival and research purposes only.

Gepetto

2026-03-22 Python ★ 3459
IDA plugin which queries language models to speed up reverse-engineering

go-whatsapp

2026-03-22 Go ★ 2226
WhatsApp Web API

goblin

2026-03-22 Rust ★ 1541
An impish, cross-platform binary parsing crate, written in Rust

gpt4free

2026-03-22 Python ★ 66611
The official gpt4free repository | various collection of powerful language models | opus 4.6 gpt 5.3 kimi 2.5 deepseek v3.2 gemini 3

hacking-online-games

2026-03-22 ★ 1807
A curated list of tutorials/resources for hacking online games.

Hacking-Tools

2026-03-22 ★ 1297
A curated list of penetration testing and ethical hacking tools, organized by category. This compilation includes tools from Kali Linux and other notable sources.

Hacking-Windows

2026-03-22 C ★ 1623
A FREE Windows C development course where we will learn the Win32API and reverse engineer each step utilizing IDA Free in both an x86 and x64 environment.

hal

2026-03-22 C++ ★ 822
HAL – The Hardware Analyzer

hermes-dec

2026-03-22 Python ★ 1142
A reverse engineering tool for decompiling and disassembling the React Native Hermes bytecode

HexWalk

2026-03-22 C++ ★ 1020
Hex Viewer/Editor/Analyzer compatible with Linux/Windows/MacOS

HookCase

2026-03-22 C++ ★ 822
Tool for reverse engineering macOS/OS X

hrtng

2026-03-22 C++ ★ 1912
IDA Pro plugin with a rich set of features: decryption, deobfuscation, patching, lib code recognition and various pseudocode transformations

HyperDbg

2026-03-22 C ★ 4025
State-of-the-art native debugging tools

iaito

2026-03-22 C++ ★ 1459
This project has been moved to:

ida-pro-mcp

2026-03-22 Python ★ 11719
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.

idacode

2026-03-22 Python ★ 970
An integration for IDA and VS Code which connects both to easily execute and debug IDAPython scripts.

Il2CppDumper

2026-03-22 C# ★ 8764
Unity il2cpp reverse engineer

imessage-exporter

2026-03-22 Rust ★ 5540
Export iMessage data + run iMessage Diagnostics

iMonitor

2026-03-22 C++ ★ 824
iMonitor(冰镜 - 终端行为分析系统)

Infosec_Reference

2026-03-22 CSS ★ 5988
An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

IPAPatch

2026-03-22 Objective-C ★ 5276
Patch iOS Apps, The Easy Way, Without Jailbreak.

jadx-ai-mcp

2026-03-22 Java ★ 2734
Plugin for JADX to integrate MCP server

jak-project

2026-03-22 Common Lisp ★ 3498
Reviving the language that brought us the Jak & Daxter Series

JByteMod-Beta

2026-03-22 Java ★ 863
Java bytecode editor

jnitrace

2026-03-22 TypeScript ★ 1821
A Frida based tool that traces usage of the JNI API in Android apps.

js-cookie-monitor-debugger-hook

2026-03-22 TypeScript ★ 772
js cookie逆向利器:js cookie变动监控可视化工具 & js cookie hook打条件断点

keypatch

2026-03-22 Python ★ 1818
Multi-architecture assembler for IDA Pro. Powered by Keystone Engine.

keystone

2026-03-22 C++ ★ 2558
Keystone assembler framework: Core (Arm, Arm64, Hexagon, Mips, PowerPC, Sparc, SystemZ & X86) + bindings

KsDumper

2026-03-22 C# ★ 1045
Dumping processes using the power of kernel space !

ksm

2026-03-22 C ★ 860
A fast, hackable and simple x64 VT-x hypervisor for Windows and Linux. Builtin userspace sandbox and introspection engine.

LADX-Disassembly

2026-03-22 Assembly ★ 897
Disassembly of Legend of Zelda: Links Awakening DX

lamda

2026-03-22 Python ★ 8259
The most powerful Android RPA agent framework, next generation of mobile automation robots.

lazy_importer

2026-03-22 C++ ★ 1907
library for importing functions from dlls in a hidden, reverse engineer unfriendly way

lighthouse

2026-03-22 Python ★ 2517
A Coverage Explorer for Reverse Engineers

lumen

2026-03-22 Rust ★ 1152
A private Lumina server for IDA Pro

LunaTranslator

2026-03-22 C++ ★ 12978
视觉小说翻译器 / Visual Novel Translator

medusa

2026-03-22 C++ ★ 1081
An open source interactive disassembler

miasm

2026-03-22 Python ★ 3944
Reverse engineering framework in Python

Millennium

2026-03-22 C++ ★ 4207
An open-source low-code modding framework to create, manage and use themes/plugins for the desktop Steam Client without any low-level internal interaction or overhead.

MonkeyDev

2026-03-22 Objective-C ★ 6780
CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak.

mtasa-blue

2026-03-22 C++ ★ 1837
Multi Theft Auto is a game engine that turns Grand Theft Auto: San Andreas into networked multiplayer.

NETReactorSlayer

2026-03-22 C# ★ 1213
An open source (GPLv3) deobfuscator and unpacker for Eziriz .NET Reactor

ngrev

2026-03-22 TypeScript ★ 1580
Tool for reverse engineering of Angular applications

obfuscator

2026-03-22 C++ ★ 831
PE (and elf now!) bin2bin obfuscator

obliteration

2026-03-22 Rust ★ 816
Experimental free and open-source PlayStation 4 kernel

ofrak

2026-03-22 Python ★ 2067
OFRAK: unpack, modify, and repack binaries.

openblack

2026-03-22 C++ ★ 1547
openblack is an open-source game engine that supports playing Black & White (2001).

opendbc

2026-03-22 Python ★ 3379
a Python API for your car

openhaystack

2026-03-22 Swift ★ 13448
Build your own 'AirTags' 🏷 today! Framework for tracking personal Bluetooth devices via Apple's massive Find My network.

OpenPods

2026-03-22 Java ★ 1197
The Free and Open Source app for monitoring your AirPods on Android

OpenTendo

2026-03-22 KiCad Layout ★ 814
An Open-Source HardWare (OSHW) recreation of the original 1985 front-loading NES Motherboard

openwifipass

2026-03-22 Python ★ 835
An open source implementation of Apple's Wi-Fi Password Sharing protocol in Python.

Osiris

2026-03-22 C++ ★ 3849
Cross-platform game hack for Counter-Strike 2 with Panorama-based GUI.

panda

2026-03-22 C ★ 2726
Platform for Architecture-Neutral Dynamic Analysis

panopticon

2026-03-22 Rust ★ 1441
A libre cross-platform disassembler.

papermario

2026-03-22 C ★ 1603
Decompilation of Paper Mario (Nintendo 64)

patching

2026-03-22 Python ★ 1248
An Interactive Binary Patching Plugin for IDA Pro

pbtk

2026-03-22 Python ★ 1680
A toolset for reverse engineering and fuzzing Protobuf-based apps

PDBRipper

2026-03-22 C++ ★ 904
PDBRipper is a utility for extract an information from PDB-files.

php-spx

2026-03-22 C ★ 2629
A simple & straight-to-the-point PHP profiling extension with its built-in web UI

pikachu-volleyball

2026-03-22 JavaScript ★ 1050
Pikachu Volleyball reimplemented in JavaScript by reverse engineering the original game

PINCE

2026-03-22 Python ★ 3068
Reverse engineering tool for linux games

plasma

2026-03-22 Python ★ 3065
Plasma is an interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax.

pokecrystal

2026-03-22 Assembly ★ 2494
Disassembly of Pokémon Crystal

pokeemerald

2026-03-22 C ★ 3411
Decompilation of Pokémon Emerald

pokefirered

2026-03-22 C ★ 1538
Decompilation of Pokémon FireRed/LeafGreen

pokered

2026-03-22 Assembly ★ 4898
Disassembly of Pokémon Red/Blue

pokeruby

2026-03-22 C ★ 934
Decompilation of Pokémon Ruby/Sapphire

pokeyellow

2026-03-22 Assembly ★ 871
Disassembly of Pokemon Yellow

project-restoration

2026-03-22 C++ ★ 765
A Majora's Mask 3D patch that restores some mechanics from the original game to get the best of both worlds

protobuf-inspector

2026-03-22 Python ★ 1115
🕵️ Tool to reverse-engineer Protocol Buffers with unknown definition

PS2Recomp

2026-03-22 C++ ★ 3195
Playstation 2 Static Recompiler & Runtime Tool to make native PC ports

pwndbg

2026-03-22 Python ★ 10822
Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

pyinstxtractor

2026-03-22 Python ★ 4172
PyInstaller Extractor

pylingual

2026-03-22 Python ★ 1357
Python decompiler for modern Python versions.

pypush

2026-03-22 Python ★ 3714
Python APNs and iMessage client

QBDI

2026-03-22 C++ ★ 1815
A Dynamic Binary Instrumentation framework based on LLVM.

QP-Gallery-Releases

2026-03-22 ★ 2654
A modern, lightweight QuickPic Gallery with a fast, offline-first experience.

qq-win-db-key

2026-03-22 PowerShell ★ 967
全平台 QQ 聊天数据库解密

radare2-book

2026-03-22 C ★ 904
The Official Radare2 Book

readpe

2026-03-22 C ★ 783
The PE file analysis toolkit

ReC98

2026-03-22 Assembly ★ 816
The Touhou PC-98 Restoration Project

Recaf

2026-03-22 Java ★ 7353
The modern Java bytecode editor

REDasm

2026-03-22 C++ ★ 1706
The OpenSource Disassembler

REDRIVER2

2026-03-22 C ★ 1238
Driver 2 Playstation game reverse engineering effort

reFlutter

2026-03-22 Python ★ 2726
Flutter Reverse Engineering Framework

reko

2026-03-22 C# ★ 2601
Reko is a binary decompiler.

Reloaded-II

2026-03-22 C# ★ 1009
Universal .NET Core Powered Modding Framework for any Native Game X86, X64.

ret-sync

2026-03-22 C ★ 2316
ret-sync is a set of plugins that helps to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with IDA/Ghidra/Binary Ninja disassemblers.

retoolkit

2026-03-22 Inno Setup ★ 5276
Reverse Engineer's Toolkit

revanced-patcher

2026-03-22 Kotlin ★ 3264
💉 ReVanced Patcher used to patch Android applications

revanced-patches

2026-03-22 Java ★ 5576
🧩 Patches for ReVanced

revanced-patches-template

2026-03-22 Kotlin ★ 4644
👋🧩Template repository for ReVanced Patches

reverse-linear-sync-engine

2026-03-22 JavaScript ★ 1921
A reverse engineering of Linear's sync engine. Endorsed by Linear CTO.

ReverseAPK

2026-03-22 Shell ★ 843
Quickly analyze and reverse engineer Android packages

reversinglabs-yara-rules

2026-03-22 YARA ★ 900
ReversingLabs YARA Rules

RigelEngine

2026-03-22 C++ ★ 977
A modern re-implementation of the classic DOS game Duke Nukem II

RMS-Runtime-Mobile-Security

2026-03-22 JavaScript ★ 3059
Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

ROPgadget

2026-03-22 Python ★ 4392
This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC, MIPS, RISC-V 64, and RISC-V Compressed architectures.

rz-ghidra

2026-03-22 C++ ★ 972
Deep ghidra decompiler and sleigh disassembler integration for rizin

Scanners-Box

2026-03-22 ★ 9023
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑

SchemaCrawler

2026-03-22 Java ★ 1828
Free database schema discovery and comprehension tool

schemaspy

2026-03-22 HTML ★ 3557
Database documentation built easy

Selenium-Driverless

2026-03-22 Python ★ 848
a stealthy browser automation framework

shellen

2026-03-22 Python ★ 909
:cherry_blossom: Interactive shellcoding environment to easily craft shellcodes

simplify

2026-03-22 Java ★ 4638
Android virtual machine and deobfuscator

sogen

2026-03-22 C++ ★ 3560
🪅 Windows User Space Emulator

SpecialK

2026-03-22 C++ ★ 2036
Lovingly referred to as the Swiss Army Knife of PC gaming, Special K does a bit of everything.

ssl-kill-switch2

2026-03-22 Objective-C ★ 3257
Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

STCObfuscator

2026-03-22 Objective-C ★ 828
iOS全局自动化 代码混淆 工具!支持cocoapod组件代码一并 混淆,完美避开hardcode方法、静态库方法和系统库方法!

SteamKit

2026-03-22 C# ★ 3156
SteamKit2 is a .NET library designed to interoperate with Valve's Steam network. It aims to provide a simple, yet extensible, interface to perform various actions on the network.

SteamTracking

2026-03-22 JavaScript ★ 1093
🕵 Tracking things, so you don't have to

SydneyQt

2026-03-22 Go ★ 883
A cross-platform desktop client for the jailbroken New Bing AI Copilot (Sydney ver.) built with Go and Wails (previously based on Python and Qt).

TangledWinExec

2026-03-22 C# ★ 954
PoCs and tools for investigation of Windows process execution techniques

tenet

2026-03-22 Python ★ 1528
A Trace Explorer for Reverse Engineers

terracognita

2026-03-22 Go ★ 2355
Reads from existing public and private cloud providers (reverse Terraform) and generates your infrastructure as code on Terraform configuration

Textractor

2026-03-22 C++ ★ 2575
Extracts text from video games and visual novels. Highly extensible.

The_Holy_Book_of_X86

2026-03-22 ★ 972
A simple guide to x86 architecture, assembly, memory management, paging, segmentation, SMM, BIOS....

Tigress_protection

2026-03-22 LLVM ★ 888
Playing with the Tigress software protection. Break some of its protections and solve their reverse engineering challenges. Automatic deobfuscation using symbolic execution, taint analysis and LLVM.

TiltedEvolution

2026-03-22 C++ ★ 1180
Skyrim mod to play online!

tiny_tracer

2026-03-22 C++ ★ 1635
A Pin Tool for tracing API calls etc

toolkit

2026-03-22 Inno Setup ★ 982
The essential toolkit for reversing, malware analysis, and cracking

Triton

2026-03-22 C++ ★ 4103
Triton is a dynamic binary analysis library. Build your own program analysis tools, automate your reverse engineering, perform software verification or just emulate code.

TRX

2026-03-22 C ★ 979
Open source re-implementation of Tomb Raider I and Tomb Raider II, along with additional enhancements and bugfixes

TryHackMe-Roadmap

2026-03-22 ★ 1094
a list of 350+ Free TryHackMe rooms to start learning cybersecurity with THM

VAC

2026-03-22 C ★ 810
Source code of Valve Anti-Cheat obtained from disassembly of compiled modules

Validity90

2026-03-22 C ★ 1874
Reverse engineering of Validity/Synaptics 138a:0090, 138a:0094, 138a:0097, 06cb:0081, 06cb:009a fingerprint readers protocol

vmlinux-to-elf

2026-03-22 Python ★ 1701
A tool to recover a fully analyzable .ELF from a raw kernel, through extracting the kernel symbol table (kallsyms)

webcrack

2026-03-22 TypeScript ★ 2472
Deobfuscate obfuscator.io, unminify and unpack bundled javascript

WebPlotDigitizer

2026-03-22 JavaScript ★ 3028
Computer vision assisted tool to extract numerical data from plot images.

WechatMagician

2026-03-22 Kotlin ★ 1893
WechatMagician is a Xposed module written in Kotlin, that allows you to completely control your Wechat.

WechatSpellbook

2026-03-22 Kotlin ★ 1736
Wechat Spellbook 是一个使用Kotlin编写的开源微信插件框架,底层需要 Xposed 或 VirtualXposed 等Hooking框架的支持,而顶层可以轻松对接Java、Kotlin、Scala等JVM系语言。让程序员能够在几分钟内编写出简单的微信插件,随意揉捏微信的内部逻辑。

Whaler

2026-03-22 Go ★ 1185
Program to reverse Docker images into Dockerfiles

wireless-carplay-dongle-reverse-engineering

2026-03-22 Shell ★ 848
CPlay2Air / Carlinkit Wireless Apple CarPlay Dongle reverse engineering

WPeChatGPT

2026-03-22 Python ★ 1293
A plugin for IDA that can help to analyze binary file, it can be based on commonly used AI big models such as OpenAI and DeepSeek.

wxapkg

2026-03-22 Go ★ 3174
微信小程序反编译工具,.wxapkg 文件扫描 + 解密 + 解包工具

xAnalyzer

2026-03-22 C ★ 1193
xAnalyzer plugin for x64dbg

XELFViewer

2026-03-22 C++ ★ 1584
ELF file viewer/editor for Windows, Linux and MacOS.

XMachOViewer

2026-03-22 C++ ★ 961
XMachOViewer is a Mach-O viewer for Windows, Linux and MacOS

xoreos

2026-03-22 C++ ★ 1168
A reimplementation of BioWare's Aurora engine (and derivatives). Pre-pre-alpha :P

XPEViewer

2026-03-22 QMake ★ 1230
PE file viewer/editor for Windows, Linux and MacOS.

Zygisk-Il2CppDumper

2026-03-22 C ★ 3082
Using Zygisk to dump il2cpp data at runtime