C++
2026-08-31
C++
★ 19
WrappEm is a Windows tool designed for adversarial payload execution by utilizing three distinct methods of subverting the Windows Image Loader through byte-based manipulation of a binary file’s Import Directory and Import Section. Its primary use case involves inserting an additional executable binary into a host process's virtual address space, serving as an alternative to traditional export forwarding techniques. Notable features include support for multiple methods of import manipulation and compatibility with various build systems, all implemented without external dependencies.
2026-08-31
C++
★ 30
The GTA5 DMA Control Console provides an external interface for Direct Memory Access (DMA) manipulation in Grand Theft Auto V, supporting both the original and Enhanced versions of the game. It features dynamic offset resolution for seamless updates, real-time player and vehicle monitoring, and comprehensive control options such as teleportation, vehicle editing, and weapon functionality. Built with C++23 and utilizing Dear ImGui for its UI, it allows users to modify game states efficiently while ensuring automatic detection of critical game parameters.
2026-08-31
C++
★ 16
The TH095 project aims to reconstruct the original Japanese version 1.02a of the game "Shoot the Bullet" by providing a framework for precise byte-level comparison against an authenticated executable. Notable features include the support for exact function restoration, semantic analysis using IDA Pro, and tracking of source presence and validation for various game components, with an aspirational reconstruction target of 99.5% accuracy. Users can import their legal copy of the game executable to verify against established criteria, facilitating a comprehensive understanding of the game's architecture.
2026-08-30
C++
★ 16
SimTower native Windows port is a function-by-function x86-64 implementation of the original Windows 3.1 version of *SimTower*, aimed at preserving and facilitating interoperability of the game. Notable features include comprehensive code analysis, exact native mapping of game routines, and a thorough validation process that ensures fidelity to the original gameplay experience. The tool requires specific resources from a legally owned copy of the game for successful local builds and emphasizes strict adherence to the original game's architecture and resource management.
2026-08-29
C++
★ 14
The Berbel Remote is an ESP32-based emulator for the Berbel BFB 6bT remote control, designed to integrate seamlessly with Home Assistant through MQTT. It enables full emulation of the original remote features, including real-time status updates and supports over-the-air firmware updates, making it compatible with various Berbel kitchen hoods manufactured after November 2020. Key features include automatic entity creation via MQTT auto-discovery, efficient memory usage with the NimBLE stack, and flexible configuration options for different hood models.
2026-08-29
C++
★ 15
Spyglass is a packet capture tool designed to run within the Minecraft: Bedrock client, providing visibility into every packet sent and received by the client, along with details on decoding failures. It facilitates debugging for server software and proxies by presenting a structured overlay that displays packet details, error information, and hex data, allowing users to filter, search, and analyze communication with ease. Notable features include an interactive packet list, detailed breakdowns of failed packets, various data export options, and customizable filtering capabilities.
2026-08-28
C++
★ 80
xoreos-tools is a collection of utilities designed for the reverse-engineering of BioWare's Aurora engine games. Its primary use case includes converting various proprietary game file formats to XML and back, extracting and creating archives, and decompiling scripts, offering extensive support for BioWare and Nintendo file types. Notable features include support for multiple file conversions and the ability to repair or extract data from damaged or proprietary archives.
2026-08-28
C++
★ 11
UnityResolve-V3 is a development tool designed to enhance Unity game development through assembly manipulation and runtime field access. Its primary use case includes modifying player attributes and handling method calls dynamically in the Unity engine, notably with functionality for accessing and manipulating class properties and methods. Key features include inline static fields and methods for streamlined access to Unity's runtime classes, providing developers with powerful capabilities for gameplay dynamics.
2026-08-26
C++
★ 54
The GTIRB Pretty Printer is a tool designed to convert the GTIRB intermediate representation of binary files into gas-syntax assembly code, primarily for the purposes of binary analysis and reverse engineering. Notable features include the ability to generate reassembleable assembly files, create new binaries directly, and generate dummy shared object files to facilitate linking without actual libraries. The tool requires a C++17 compliant compiler and dependencies such as GTIRB and Capstone for its functionality.
2026-08-26
C++
★ 44
WinSecRuntime is a Windows runtime security library implemented in C++20, designed to enhance application integrity by providing defensive mechanisms against tampering, debugging, and injection attacks. It features a modular architecture that supports header-only usage, static libraries, and hardened DLLs, allowing developers to configure anti-debugging, anti-hooking, and memory safety checks tailored to their security needs. The library emphasizes redundancy and safe detection methods rather than deceptive techniques, making it suitable for production environments focused on security hardening.
2026-08-23
C++
★ 75
VanBus is an Arduino library designed for reading and writing packets on the VAN bus of Peugeot and Citroën vehicles, which communicates using a protocol similar to CAN bus. It supports ESP8266 and ESP32 platforms, facilitating interactions with comfort-related equipment in vehicles manufactured by PSA up until around 2009. Notable features include compatibility with various hardware setups and comprehensive schematics for implementation, ensuring ease of use for developers working on automotive applications.
2026-08-22
C++
★ 51
Chaos Zero Nightmare ASSet Ripper is a specialized asset extraction tool designed to retrieve encrypted game assets from the Yuna engine and specific anime games. It features support for exporting various formats, including SCT images as PNG, encrypted databases as JSON, and SCSP Spine format, with an integrated viewer for the latter. The tool allows users to navigate a file tree for asset management and enables batch exports of selected files and folders, enhancing usability for game modding and asset repurposing.
2026-08-22
C++
★ 136
Creation Kit Platform Extended (CKPE) is an enhanced editing platform for Bethesda's Creation Kit, providing a collection of modifications and reverse-engineered resources aimed at improving the user experience for titles like Skyrim Special Edition, Fallout 4, and Starfield. Notable features include various fixes, editor enhancements, and additional support for Unicode, aimed at streamlining game modding workflows. This platform serves as a comprehensive successor to previous projects focused on improving the Creation Kit's functionality.
2026-08-22
C++
★ 18
The CSS-MultiHack-Internal is an internal multihack designed for Counter-Strike: Source, featuring functionalities such as aimbot, triggerbot, bunnyhop hack, and anti-flash capabilities. It requires a DLL injector for installation and operation, allowing the user to toggle features via an in-game menu. Notable features include precise aimbot functionality, automatic jumping through the bunnyhop hack, and the capability to negate flashbang effects.
2026-08-21
C++
★ 93
NotDec is a WebAssembly decompiler and static analysis framework that focuses on enhancing decompiler techniques through variable recovery and structural analysis. Its primary use case is to facilitate detailed type recovery experiments, allowing developers to gain insights into the inner workings of decompilation processes while improving their algorithms iteratively. Notable features include customizable environment variables for debugging type recovery and a robust setup for experimenting with LLVM and C code generation.
2026-08-21
C++
★ 733
Metaforce is a reverse-engineered reimplementation of the video game Metroid Prime, currently in alpha state and focused on providing a native, cross-platform gaming experience on Windows, macOS, and Linux. Its notable features include support for multiple graphics APIs (D3D12, Vulkan, OpenGL, Metal), a console logging option, and developer functionalities such as world/area warping, enabling users to explore and debug the game more effectively. The project is supported by ongoing contributions from its decompilation counterpart, enhancing bug fixes and new implementations.
2026-08-21
C++
★ 11
Onyx External ESP is a tool designed for emulation on Android x86_64 architecture, specifically for the MuMu Player, providing users with external ESP (Extra Sensory Perception) features such as skeletons, snaplines, bounding boxes, health indicators, and off-screen markers. Primarily aimed at educational purposes, it serves as a foundational codebase for understanding and modifying ESP implementations in games, though it currently lacks support for physical ARM devices and certain advanced features due to game obfuscation. The tool includes automated batch scripts for straightforward building and deployment, enhancing the user experience for developers and researchers.
2026-08-19
C++
★ 70
ReHitman is a reverse engineering project aimed at modifying the game "Hitman: Blood Money" to create a multiplayer experience similar to Mafia 2's multiplayer. The tool focuses on developing an open-source SDK for the Glacier 1 Engine, reversing its rendering and input APIs, and building an associated toolset for game enhancements. Notable features include the integration of an ImGUI backend and current work on the game's scene format and GUI API.
2026-08-19
C++
★ 38
KX Trainer Free is an open-source utility for Guild Wars 2 that injects itself as a DLL to provide an in-game overlay menu, enhancing gameplay functionality. Its primary use case is to assist players with various game tools while ensuring compatibility with updates through community contributions. Notable features include modular maintainability, user-configurable hotkeys, and a commitment to transparency and educational use.
2026-08-18
C++
★ 12
DarkDex is a powerful tool designed to extract and reconstruct the real dex file from packed Android applications, including those protected by advanced packers like ijiami 4th generation. It operates in two modes: a host script that leverages memory reading from outside the Android sandbox, and an APK that runs directly on the device, facilitating full memory dumps in root mode or disk dex pulls without root. Notable features include an event-driven capture system that captures decrypted dex in real-time, as well as utilities for validating, deduplicating, and testing the output disassemblies.
2026-08-18
C++
★ 122
KeyDot is a high-performance command-line tool that extracts encryption keys and detects engine versions from compiled Godot Engine games, specifically targeting Windows x64 executables and WebAssembly (`.wasm`) files. Its primary use case is static analysis of game files without requiring runtime execution, which enhances safety and efficiency. Notable features include optimized C++ code for rapid extraction, memory-mapped file usage for low memory consumption, and unique support for WASM files, making it an essential tool for developers working with Godot Engine games.
2026-08-18
C++
★ 265
newserv is a comprehensive game server and proxy tool specifically designed for the Phantasy Star Online (PSO) community, facilitating reverse-engineering and custom gameplay experiences. It supports features such as user accounts, server-side saves, cross-version play, and a REST API, while also allowing users to connect through a proxy to mitigate command vulnerabilities that could disrupt gameplay. Additionally, newserv incorporates community-driven reverse-engineering efforts, making it a stable and dynamic platform for both players and developers.
2026-08-16
C++
★ 34
WinGuard is a user-mode Windows threat detection tool designed to monitor and log suspicious activities on PCs, employing techniques inspired by Endpoint Detection and Response (EDR) frameworks. Its primary use case is for educational and experimental purposes, featuring advanced capabilities such as process and execution monitoring, file system analysis, persistence detection, and memory scans for malicious patterns, along with comprehensive logging functionalities. Notable features include the ability to analyze command line buffers for malicious intent, detect abnormal process behaviors, and whitelist benign applications to mitigate false positives.
2026-08-15
C++
★ 35
DeMuxUSB is a C++20 tool suite designed for capturing, demultiplexing, and analyzing USB sessions involving Apple iDevices, focusing particularly on reverse engineering recovery and restore protocols. It enables forensic analysis by allowing users to examine device restores against known baselines to identify deviations or unauthorized modifications, with features such as detailed USB transaction tracking, protocol demultiplexing, and support for various input capture formats like PCAPNG. Noteworthy capabilities also include reconstructing USB device states and extracting TCP streams and plist data, making it a valuable resource for cybersecurity analysis and digital forensics in the Apple ecosystem.
2026-08-15
C++
★ 153
Dll Proxy Generator is a tool designed to create a proxy DLL that intercepts calls between a game and its original DLL, allowing for the inspection and modification of DLL interactions. Its primary use case is for game developers and researchers seeking to debug or enhance game functionality through DLL manipulation. Notable features include the automatic generation of proxy DLL source code and the capability to handle specific public Windows DLLs effectively, although some limitations exist with game-specific DLLs that have mangled function names.
2026-08-14
C++
★ 388
Maskromtool is a CAD tool designed for photographing mask ROMs and extracting their bit contents for recovery purposes. Its primary use case is in the analysis and decoding of ROM data, particularly for vintage microcontrollers and gaming systems. Notable features include support for handling ambiguous or damaged bits, a user-friendly GUI with keyboard shortcuts, and integration with GoodASM for assembly tasks, alongside various enhancements for efficient bit extraction and analysis.
2026-08-14
C++
★ 18
The CS 1.6 Steam GoldSrc Client is an open-source replacement for the `client.dll` in Counter-Strike 1.6, specifically designed for the original 32-bit Steam GoldSrc engine. This experimental tool maintains the native client ABI while reviving essential features such as the original VGUI, weapon prediction, and spectator interface, offering enhanced user experience without reliance on non-native APIs. Notable features include integration with original HUD sprites, correct widescreen rendering, and support for Steam Rich Presence and Discord RPC.
2026-08-14
C++
★ 430
R.E.L.I.V.E. is an open-source engine replacement for Oddworld: Abe's Oddysee and Oddworld: Abe's Exoddus, designed to fix bugs and enhance the original gameplay experience. It aims to provide a modding and level creation interface, allowing users to study and modify the engine for new projects. Notable features include quick save/load functions and customizable display options such as aspect ratio and fullscreen toggling.
2026-08-14
C++
★ 32
SonyBridge is an open-source desktop application designed for managing various functionalities of Sony headphones, including noise cancelling, ambient sound control, equalization, and battery monitoring, without the need for a mobile device. This tool leverages a reverse-engineered protocol to support both first and second-generation Sony headphone models, offering features like real-time battery status, adaptive sound management, and a modern UI across macOS, Windows, and Linux platforms. Notable capabilities include codec information retrieval, live button sync, and a high degree of customization in audio settings.
2026-08-13
C++
★ 74
The TH105 project is a reverse engineering initiative aimed at reconstructing the source code of the Japanese game "東方緋想天 ~ Scarlet Weather Rhapsody" version 1.06a, with a focus on achieving reproducible binary comparisons. The tool utilizes Ghidra and IDA Pro for semantic analysis, and incorporates a structured workflow that emphasizes exact matching and function byte comparisons, ensuring the integrity of the reconstructed code. Notable features include the generation of a machine-readable function ledger and project-scoped tools for streamlined analysis and verification.
2026-08-13
C++
★ 10
PS1Recomp is a static recompilation tool that transforms PlayStation 1 game binaries from MIPS R3000A machine code into native C++ executables for PC, enabling them to run at full CPU speed without runtime interpretation. Its architecture includes a dedicated analyzer for game binary parsing, a recompilation component that accurately emits C++ code, and a full hardware simulation runtime facilitating various PlayStation functionalities. Notable features include a GUI studio for exploring and editing configurations, comprehensive unit tests, and support for hardware simulation via SDL2 and OpenGL, promoting both performance and ease of use in game development and emulation.
2026-08-13
C++
★ 28
The th07 project focuses on the reverse engineering and reconstruction of the original Japanese executable for `東方妖々夢 ~ Perfect Cherry Blossom` version 1.00b. Its primary use case is to achieve reproducible binary comparisons through an extensive function-by-function analysis, employing tools like IDA Pro for semantic analysis. Notable features include a structured workflow integrating knowledge from related projects, strict validation gates for function verification, and a comprehensive inventory and progress tracking system.
2026-08-13
C++
★ 129
The th08 project is focused on reverse-engineering and reconstructing the source code of the original Japanese game "東方永夜抄 ~ Imperishable Night" (version 1.00d). Its primary use case allows for reproducible binary comparisons against the original executable, while facilitating the build process in multi-platform environments. Notable features include a detailed analysis workflow, dependency management, and documentation of progress and architecture, with components built upon contributions from previous related projects.
2026-08-12
C++
★ 11
A dynamic Wii U mod loader.
2026-08-12
C++
★ 23
ALPC Enumerator is a Windows userland tool designed to enumerate and classify Advanced Local Procedure Call (ALPC) ports, including those associated with Protected Process Light (PPL) processes that evade standard enumeration techniques. It dynamically resolves ALPC Port types and employs `NtQueryInformationProcess` for classification, addressing blind spots in conventional tools, thereby benefiting threat hunters and vulnerability researchers by accurately mapping high-privilege targets and identifying potentially malicious activity. Notably, it has been validated against kernel debugger output for precision and reliability.
2026-08-12
C++
★ 328
CoBRA is a Mixed Boolean-Arithmetic expression simplifier designed to deobfuscate complex arithmetic expressions that interleave arithmetic, bitwise, and shift operators, often used in software obfuscation. It employs a worklist-based orchestrator and features various techniques such as signature-based analysis, semilinear processing, and decomposition to simplify expressions efficiently. Notable functionalities include verification via spot-checking or Z3 proofs and the ability to handle weighted sums of bitwise atoms, making it a robust tool for analyzing obfuscated code.
2026-08-12
C++
★ 28
CoD4 DM1 is a tool designed for the reverse engineering of CoD4 and CoD4X `.DM_1` demo files, facilitating the parsing of snapshot information, gamestate, frames, entities, clients, and server messages. Notable features include support for CoD4 & CoD4X protocols, Huffman coding for CoD4 and Q3, and a demo reader API, enabling extensive analysis of game data. The tool is accessible as a command-line interface and a library, and is available for integration via vcpkg.
2026-08-12
C++
★ 13
IzEngine is a cross-platform engine framework designed for creating modded game clients with flexibility and adaptability across various platforms and backends. It features a robust plugin system enabling dynamic module reloading at runtime and incorporates a just-in-time assembler for efficient code generation. This makes IzEngine particularly suitable for developers looking to enhance the gameplay experience through custom modifications.
2026-08-11
C++
★ 213
idaxex is a native loader plugin for IDA Pro 9.4 that facilitates the loading of Xbox 360 XEX and XBE executables, enhancing reverse engineering capabilities for these formats. It provides extensive support for various Xbox executable versions, handles both compressed and uncompressed images, and automatically names known imports, improving analysis efficiency. Notable features include AES-NI support for faster loading, integration of exception handling information, and the ability to apply patches directly back to input files.
2026-08-11
C++
★ 31
RatDecomp is a decompilation tool for the Ratatouille game, targeted primarily at developers and modders who require insight into the game's code structure. The tool allows users to compile and modify the game's source code without containing any game assets, requiring a legitimate copy of the game for usage. Notable features include support for various game versions, a build system via Python and Ninja, and an object diffing capability for tracking changes in the code during development.
2026-08-10
C++
★ 87
Malware2.0Database is a repository designed to catalog and archive various malware samples for educational purposes. Its primary use case is to provide researchers and security professionals with access to an up-to-date collection of malware, facilitating the study of malware behavior and trends. Notable features include an organized system for uploading new malware strains while archiving older versions.
2026-08-10
C++
★ 10
OpenDW is an open-source reimplementation of the online game Deepworld, originally designed for MacOS and iOS. Its primary use case is to allow users to build and run the game on different platforms using the Axmol Engine, although it does not aim for 100% accuracy compared to the original due to engine and platform differences. Notable features include compatibility with a separate server, build instructions for Windows, and a customizable asset framework, requiring users to provide their own game assets.
2026-08-10
C++
★ 14
Openswx is a cross-platform toolkit designed to read SolidWorks files (.SLDPRT, .SLDASM, .SLDDRW) without requiring a SolidWorks installation or any Windows dependencies. It features a C++20 library for file parsing and BOM (Bill of Materials) generation, alongside an HTTP server and CLI tools for metadata browsing and JSON output, making it suitable for applications needing SolidWorks data access in non-Windows environments. Notable features include comprehensive document property extraction, component path resolution, and a user-friendly web interface for metadata interaction.
2026-08-10
C++
★ 49
SBA (Scalable Binary Analysis Framework) is a comprehensive binary analysis tool designed to perform high-fidelity static analysis on ELF, PE, and Mach-O executable formats through a robust, architecture-agnostic disassembler. Its notable features include a ControlFlowGraphAPI for diverse graph construction, an efficient AnalysisAPI incorporating forward and backward dataflow analysis, and a pre-disassembly method that processes raw binary data efficiently, allowing for scalable analysis without the limitations of traditional disassembly. The framework's applications encompass advanced jump table analysis and function property checks, enhancing the robustness and accuracy of binary analysis tasks.
2026-08-09
C++
★ 20
MK7-Memory is a collection of data structures specifically designed for reverse engineering Mario Kart 7. It streamlines the process of generating these data structures from template files using a specialized syntax, facilitating easier modifications and enhancements by developers. Key features include automated header file generation and compatibility with C++23 for project integration.
2026-08-07
C++
★ 36
reSL is a reverse-engineered version of the DOS game ShortLine v1.1, adapted for modern mobile and touch-controlled devices. Its primary use case is to provide an accessible way to play a classic game in a browser while maintaining the original experience, featuring improvements such as enhanced UI for touch interaction, fixed bugs from the original game, and cross-platform compatibility. Notable features include mouse/touch controls for menus, error handling enhancements, and visual updates, all aimed at recreating the game closely to its original form while ensuring a smoother gameplay experience.
2026-08-06
C++
★ 31
Fripack-inject is a payload injection tool designed to work with the Fripack framework, facilitating the manipulation of packaged applications. Its primary use case is to provide a seamless injection mechanism that enhances the functionality of the Fripack environment. Notable features include compatibility with the Fripack ecosystem and the ability to customize payload injections for various scenarios.
2026-08-06
C++
★ 92
The M2TW Engine Overhaul Project (M2TWEOP) enhances the gameplay capabilities of *Medieval 2: Total War* by modifying the game's in-memory code using C++ and Assembly, accessible through a comprehensive Lua scripting API. Key features include extensive customization options, removal of engine limitations, robust debugging tools, and support for custom sounds and mod integration. The tool also fixes several engine bugs and allows users to create unique gameplay experiences with capabilities such as online Hotseat battles and strategic map viewing.
2026-08-06
C++
★ 37
th07 is a reimplementation and decompilation of the game "Perfect Cherry Blossom" (version 1.00b) by Team Shanghai Alice, designed to be functionally identical to the original executable while achieving a high accuracy rate. It provides a fully playable main game executable (th07.exe) alongside a configuration tool (custom.exe), both of which currently require the original game files for certain features like icon extraction. Notable features include the handling of integrity checks and options for non-matching builds, with ongoing improvements aimed at enhancing accuracy and usability across platforms.
2026-08-06
C++
★ 105
FlutterTap is a Zygisk module designed for intercepting network traffic from Flutter applications by redirecting it to a configurable proxy, effectively bypassing BoringSSL's TLS certificate verification without the need for a certificate installation or app repackaging. Its primary use case focuses on persistent traffic interception during mobile application analysis, providing an easy-to-use manager app for selecting target applications and configuring proxy settings. Notable features include automatic operation on device boot, minimal impact on non-selected apps, and the ability to capture native traffic without the drawbacks associated with traditional methods such as Frida or LSPosed.
2026-08-05
C++
★ 546
The GensokyoClub/th06 repository focuses on reverse engineering and reconstructing the source code of the Touhou game "Embodiment of Scarlet Devil" version 1.02h. Its primary use case is to allow for the game's reimplementation and porting to platforms like Linux and modern Windows, utilizing a customized build system with dependencies such as Python and Wine. Notable features include automated dependency management, integration with Ghidra for reverse engineering, and tools for object file comparison through objdiff, facilitating contributions to the reimplementation effort.
2026-08-05
C++
★ 48
The tpp-server-emulator is a reimplementation of the backend server for *Metal Gear Solid V: The Phantom Pain*, designed primarily for academic research purposes. It allows players to experience the game's online features in a controlled environment, featuring comprehensive installation instructions, scripting capabilities, and support for multiple platforms. The tool emphasizes responsible usage and provides build customization options for developers.
2026-08-05
C++
★ 216
HexCtrl is a versatile hex control library designed for Windows applications, facilitating the display and manipulation of binary data in hexadecimal format. Its primary use case is in software that requires a user interface component for editing binary files, with notable features including virtual data mode, customizable colors, support for bookmarks, and various methods for data management and interaction. The library also allows for the integration of classic and dialog-based controls, making it adaptable for different development environments.
2026-08-05
C++
★ 153
resource_dasm is a comprehensive suite of reverse-engineering tools primarily aimed at classic Mac OS applications and games, with additional support for Nintendo GameCube formats. Notable features include the ability to read and convert resource files, disassemble binaries, and generate game maps, making it a versatile solution for analyzing and modifying legacy software and media. The project includes specialized utilities for handling various resource formats, image rendering, and music sequence synthesis, enhancing its utility for developers and researchers in the field of software preservation and analysis.
2026-08-05
C++
★ 187
TinyLoad is a PE crypter and packer for 64-bit Windows executables, designed to protect input binaries against reverse engineering by appending a payload to itself and employing various layers of encryption and compression. It features a custom VM encryption method with obfuscated opcodes, a unique LZ77 compression algorithm, and Veh page fault decryption to keep most of the payload encrypted in memory during execution. Additionally, it includes anti-dumping techniques to safeguard critical APIs and prevent reconstruction of the import table.
2026-08-05
C++
★ 769
VxLang is a cybersecurity tool designed to protect Windows executables, dynamic link libraries, kernel drivers, and .NET binaries from reverse engineering and unauthorized access. Its notable features include virtualization, code obfuscation, and packing functionality to thwart static and dynamic analysis attempts. The tool supports x86-64 architectures and is expanding to include additional file formats and functionalities in future releases.
2026-08-05
C++
★ 293
Xenon is an experimental Xbox 360 emulator developed in C++ for Windows and Linux, primarily designed to run low-level programs such as XeLL, Linux, and LK. As an early-stage project, it currently supports only limited functionality, making it suitable for developers and testers interested in Xbox 360 architecture and emulation. Key features include native support for multiple operating systems and a focus on community contributions to advance the emulator's capabilities.
2026-08-04
C++
★ 540
KittyMemory is a C++ library designed for runtime memory manipulation and analysis on Android and iOS platforms, featuring capabilities such as memory patching, dumping, scanning, and module introspection for ELF and Mach-O formats. Notable features include comprehensive pattern scanning methods, detailed ELF and Mach-O introspection tools, memory mapping and region enumeration, alongside support for instruction decoding and memory dump utilities. This tool is particularly valuable for developers and researchers involved in reverse engineering and low-level binary analysis on mobile platforms.
2026-08-04
C++
★ 178
KittyMemoryEx is an advanced memory manipulation toolkit designed for remote memory patching, scanning, and ELF introspection on Android and Linux platforms. Its notable features include dual remote memory backends, comprehensive pattern scanning, various ptrace utilities for process control, and the ability to perform remote function and syscall calls, making it an essential tool for security researchers and developers focused on reverse engineering and debugging applications in remote environments.
2026-08-04
C++
★ 359
AndKittyInjector is a ptrace-based library injector designed for Android that facilitates the injection of shared libraries into running processes or newly launched applications across multiple Android versions and CPU architectures. Notable features include support for injecting multiple libraries simultaneously, bypassing Android linker namespace restrictions, and advanced injection triggers such as breakpoints on library loading or specific symbols. This tool is especially useful for debugging and modifying the behavior of Android applications in a stealthy manner.
2026-08-04
C++
★ 459
AndUEDumper is a tool designed to extract SDK and function scripts from Unreal Engine games on Android. It supports multiple architectures (ARM64, ARM, x86, x86_64) and automates the discovery of critical game components such as GUObjectArray and GNames, while generating usable JSON scripts for reverse engineering tools like IDA and Ghidra. Noteworthy features include memory dumping capabilities, extensive logging options, and compatibility with a variety of popular Unreal Engine titles.
2026-08-04
C++
★ 334
Class Informer is a Hex-Rays IDA Pro plug-in that scans Microsoft Visual C++ binaries for virtual function tables (vftables) utilizing Run-Time Type Identification (RTTI) data. It enhances reverse engineering capabilities by labeling and commenting on vftables, defining associated data structures, and providing a browsable list of class objects. Noteworthy features include the identification of class hierarchies and the processing of static initializers, aimed at streamlining analyses of MSVC-compiled binaries.
2026-08-04
C++
★ 146
Bypass-SetWindowDisplayAffinity is a kernel-level tool designed to bypass Windows' screen capture protections enforced by the SetWindowDisplayAffinity API. Its primary use case is for educational and research purposes, demonstrating how display affinity can be neutralized at the kernel level without relying on user-mode APIs or DLL injection techniques. Noteworthy features include its functionality in a virtualized environment and the emphasis on thorough documentation for kernel modifications and driver installation considerations.
2026-08-04
C++
★ 90
GTA2 RE is an open-source tool designed for reverse engineering and building modifications for the classic game Grand Theft Auto 2. It allows users to set up and run patched versions of the game through a straightforward build process using Python, with notable features including automatic setup of the game's executable and the option to run standalone or patched versions directly after building. The project encourages community contributions and provides a dedicated hub for collaboration and additional resources.
2026-08-04
C++
★ 79
LibreShockwave is a C++20 library designed for parsing Macromedia/Adobe Director and Shockwave files, aiming to create a comprehensive software suite that includes a Director player and a replacement for Director MX. The tool features a Lingo bytecode virtual machine and player for executing Director movies, along with a Qt-based editor for inspecting projects. It supports various file formats and incorporates options for native C++ use as well as browser/WASM deployment, although the development is ongoing and not yet production-ready.
2026-08-03
C++
★ 39
The rewolf-pcausa-exploit is a Windows local privilege escalation tool targeting the PCAUSA Rawether vulnerability. Its primary use case is to enable users to gain elevated permissions within a Windows environment, exploiting specific weaknesses in the PCAUSA driver. Notable features include its focus on local escalation and detailed documentation linked for further information.
2026-08-03
C++
★ 77
adduser-dll is a straightforward dynamic-link library (DLL) that facilitates the creation and addition of users to the local Administrators group on Windows systems. Its primary use case is for administrative automation in user management tasks, allowing customization of usernames, passwords, and group permissions through code modifications. Notable features include its standalone execution via `rundll32.exe` and the ability to be injected or called from other scripts or tools, enhancing flexibility in usage.
2026-08-03
C++
★ 22
Anyelevate is a Windows x64 privilege escalation tool that leverages the anycall technique to elevate the privileges of a specified process by copying the system process token into the target process's context. The tool operates by manipulating physical memory to enable the execution of tasks with NT AUTHORITY\SYSTEM privileges, making it particularly useful for security researchers and penetration testers looking to demonstrate or exploit privilege escalation vulnerabilities. Notable features include its simplicity of use and the ability to specify a process ID for targeted elevation.
2026-08-03
C++
★ 15
ByeIntegrity Lite is a tool designed to exploit a shell protocol handler hijack to bypass Windows User Account Control (UAC) and achieve elevated privileges for executing programs at a higher integrity level. It specifically alters the handler for the `ms-settings` protocol to redirect it to `cmd.exe`, allowing execution of `fodhelper.exe`, which inherits elevated tokens. Notable features include its simplicity and compatibility with all versions of Windows 10; however, there are no precompiled binaries available to prevent misuse.
2026-08-03
C++
★ 211
ByeIntegrity is a tool designed to bypass Windows User Account Control (UAC) in order to gain elevated Administrator privileges for executing programs at a high integrity level. Its notable features include the ability to hijack DLLs in the Native Image Cache (NIC) without relying on existing native images and the use of an auxiliary file generator (AUXGen) to facilitate the loading of shellcode without direct dependency on system resources. The latest update enhances its speed, reliability, and usability by streamlining the hijacking process and minimizing the initial configuration overhead.
2026-08-03
C++
★ 57
ByeIntegrity 2.0 is a tool designed for bypassing Windows User Account Control (UAC) to gain elevated administrator privileges by leveraging a specific elevated COM interface associated with the Internet Explorer Add-on Installer. It features a methodical approach utilizing the `COMAutoApprovalList` registry key to execute arbitrary programs via an elevated instance of `cmd.exe`, thereby circumventing UAC restrictions. This iteration builds on previous designs, sharing core functionality with the UACMe project while incorporating unique lolbin usage for execution.
2026-08-03
C++
★ 31
ByeIntegrity 3.0 is a tool designed to bypass Windows User Account Control (UAC) to achieve elevated privileges for executing arbitrary programs. It employs an elevated COM interface alongside a shell protocol handler hijack, allowing seamless execution of commands like `cmd.exe` with admin rights. Notable features include the use of the `IWscAdmin` interface and the ability to manipulate URL protocol associations to facilitate the UAC bypass in various Windows versions.
2026-08-03
C++
★ 18
ByeIntegrity 4.0 is a cybersecurity tool designed to exploit User Account Control (UAC) vulnerabilities in Windows for bypassing security mechanisms and achieving elevated privileges. It modifies the `windir` environment variable and utilizes a custom URL protocol to launch `cmd.exe` as an administrator, successfully circumventing UAC protections. Key features include the leveraging of COM interface methods and environment variable manipulation, making it an effective tool for demonstrating UAC bypass techniques in Windows environments.
2026-08-03
C++
★ 36
ByeIntegrity V is an advanced tool designed to bypass User Account Control (UAC) across all notification levels, granting elevated Administrator privileges to execute any program. Utilizing a combination of DLL hijacking, environment variable manipulation, and the Task Scheduler, it effectively circumvents UAC prompts by launching tasks with the "Run with highest privileges" setting enabled. This tool is particularly notable for its ability to operate without requiring administrator access initially or modifying critical system components, making it a stealthy approach for privilege escalation in Windows environments.
2026-08-03
C++
★ 125
This repository provides a proof-of-concept (PoC) for exploiting the CVE-2020-1034 vulnerability, which allows for privilege escalation on unpatched Windows 10 systems. It is primarily used for security research and understanding the exploitability of this specific vulnerability, with notable features including documentation links for deeper insight into exploitation techniques and the context of the vulnerability's discovery and remediation.
2026-08-03
C++
★ 49
The cve-2022-21882-poc repository provides a proof of concept (PoC) for the local privilege escalation vulnerability identified as CVE-2022-21882. Its primary use case is to demonstrate the exploitability of this vulnerability in a controlled environment, facilitating security research and testing. Notable features may include detailed instructions for replication of the exploit and potential impacts of the vulnerability.
2026-08-03
C++
★ 21
The Disable Ctrl+Alt+Del tool is designed to disable the Ctrl+Alt+Del hotkey on Windows 10 x64 systems, requiring administrative privileges for operation. It provides a simple compilation method using g++ or other compilers, making it accessible for users needing to restrict this key combination for security or user interface purposes. Notably, it has been tested and confirmed to work on the specified Windows version.
2026-08-03
C++
★ 546
DLLSpy is a DLL hijacking detection tool designed for Windows environments that identifies vulnerabilities in running processes and services by scanning their binaries for potential hijacking threats. It features three modes of operation: dynamic scanning of loaded modules, static search for DLL references in binaries, and recursive scanning of DLLs to uncover further hijack potential. The tool requires administrative privileges for comprehensive scanning and outputs results in CSV format by default.
2026-08-03
C++
★ 12
libinject is a static library designed for DLL injection into Windows x64 processes, featuring handle elevation capabilities to bypass certain protections. It enables users to obtain a process handle with higher privileges using elevated access, facilitating interaction with protected processes for debugging or analysis purposes. Notable features include process handle acquisition, memory allocation in target processes, and remote thread creation to execute the injected DLL.
2026-08-03
C++
★ 61
WinSudo is a tool designed to execute commands with local system privileges on Windows. It allows users to create access tokens and processes while enabling various privileges and group configurations. Notable features include strict parameter checking to mitigate memory violations, the ability to inherit the current console window, and user-friendly LPCSTR submissions for user and group names.
2026-08-03
C++
★ 27
CVE-2022-27502 is a DLL hijacking exploit targeting RealVNC Server versions up to 6.9.0, allowing for arbitrary command execution by leveraging a vulnerable installation process. The tool enables users to execute any command through a crafted DLL that captures the output in a specified output file. Notable features include the ability to modify the executed command by editing specific code lines and recompiling the DLL.
2026-08-03
C++
★ 386
Elevation Station is a privilege escalation tool that facilitates the duplication and manipulation of system tokens to gain higher privileges on Windows systems. Its primary use case includes bypassing User Account Control (UAC) and achieving SYSTEM-level access, with notable features such as becoming a TrustedInstaller and utilizing various escalation methods like process and thread duplication, along with named pipes and remote thread injection. This tool aims to avoid antivirus detection while providing users with a deeper understanding of token management and escalation techniques.
2026-08-03
C++
★ 21
Flanders-Trojan is a Windows-based trojan developed for academic purposes that employs C++ and consists of three main components: a Loader for initial setup and privilege escalation, a Payload for executing various malicious actions (such as file encryption, keylogging, and DDoS attacks), and a Server that functions as the command and control center for managing infected devices. Notable features include VM detection, UAC bypass, and real-time communication with a C2 server, highlighting its capabilities in orchestrating cyberattacks and gathering sensitive information.
2026-08-03
C++
★ 20
WindowsPrivilegeEscalationVulnerabilityDisplayBox is a Windows executable designed for detecting and demonstrating privilege escalation vulnerabilities for security research and educational purposes. Key features include the ability to modify PowerShell execution policies, take ownership of files, elevate privileges to SYSTEM or TrustedInstaller, and display current permissions of the program. This tool is strictly for demonstration and is best utilized in controlled environments.
2026-08-03
C++
★ 207
DNS-Persist is a post-exploitation agent utilizing DNS for command and control, primarily designed for persistence in compromised systems. It features multiple persistence mechanisms including LogonScript, RunKey, and Excel Addin persistence, as well as the ability to execute commands via a pseudo-interactive shell and inject 32-bit shellcode. The tool is built with a Python server-side and a C++ agent, with plans for future enhancements including additional persistence options and encryption capabilities.
2026-08-03
C++
★ 37
LinPwn is an interactive post-exploitation tool designed for enumerating information and facilitating privilege escalation on compromised Linux machines. Key features include executing shells, reading files, running scripts like LinEnum.sh for enumeration, downloading files, and extracting system password hashes and saved Wi-Fi credentials. This tool is essential for security professionals conducting penetration tests to assess vulnerabilities post-exploitation.
2026-08-03
C++
★ 300
TokenPlayer is a tool designed for manipulating and abusing Windows access tokens, focusing on the Win32 API. Its primary use case includes stealing and impersonating tokens, bypassing User Account Control (UAC) via token duplication, and creating new tokens for network authentication without elevated privileges. Notable features include the ability to execute applications under an impersonated context, spoof parent process IDs, and operate within non-interactive environments, making it suitable for various privilege escalation and security testing scenarios.
2026-08-03
C++
★ 50
HVNC is a remote administration toolkit designed for red-team operators, enabling covert access to an invisible Windows desktop without user awareness. Its primary use case is to facilitate stealthy remote operations by creating a hidden session that processes actions off-screen and communicates with the operator via VNC-like commands, supporting functionalities such as file transfers, keylogging, and launching applications. Notable features include simultaneous session handling in separate console windows and a clean-up script for system hygiene post-usage.
2026-08-03
C++
★ 35
MagikIndex is an advanced keylogger designed for stealthy data capture, boasting a low detection rate and various persistence mechanisms. It retrieves logged information via email, supports clipboard monitoring, and can capture screenshots with configurable modes while encrypting logs for security. Notable features include an auto-update capability, extensive system information logging, and a customizable architecture for tailored functionality.
2026-08-03
C++
★ 10
ShellCode Elevator is a sophisticated tool for bypassing User Account Control (UAC) and injecting shellcode into processes on x64 systems while maintaining stealth and undetectability. Its primary features include fully undetectable operation, privilege escalation, memory-only execution, and anti-debugging mechanisms to prevent detection by security tools. This makes it a potent option for executing malicious payloads without alerts on target systems.
2026-08-03
C++
★ 5551
LIEF is a cross-platform library designed for parsing, modifying, and abstracting executable formats such as ELF, PE, and Mach-O, along with others like COFF, OAT, and DEX. Notable features include a user-friendly API for accessing format internals, support for runtime information, debugging data, and disassembler functionality for multiple architectures. The library provides interfaces for various programming languages including C++, Python, Rust, C, and Node.js, making it highly versatile for developers in the cybersecurity domain.
2026-08-03
C++
★ 22
PE Library is a modern C++ library focused on parsing and manipulating Windows Portable Executable (PE) files, supporting both PE32 and PE32+ formats. Key features include comprehensive access to PE file headers and sections, utilities for address conversions, and specific structures like import/export tables and resource directories. The library emphasizes performance and simplicity, and it includes a fuzzer that has been utilized to enhance its robustness by identifying and resolving parsing edge cases.
2026-08-03
C++
★ 329
The Binary Ninja Debugger is a C++ plugin designed for the Binary Ninja reverse engineering platform, facilitating debugging across multiple operating systems and target environments. It supports local and remote debugging for macOS, Linux, and Windows, as well as compatibility with various debugging protocols such as GDB and LLDB. Notable features include support for iOS debugging, Windows kernel debugging, and integration with virtualization tools like QEMU and VMware.
2026-08-03
C++
★ 31
eblenix_csgo_public is a hacking tool for Counter-Strike: Global Offensive, designed primarily for educational purposes in game hacking. It enables users to inject custom functionalities into the game by compiling the source code with Visual Studio, utilizing dependencies such as Minhook and Lua. Notable features include an injector executable that facilitates the integration of modifications during gameplay.
2026-08-03
C++
★ 39
F.E.A.R. VR is an open-source virtual reality mod designed for the single-player base version of F.E.A.R. 1.08, offering immersive gameplay features such as native stereo world rendering, headtracking, and comprehensive controller support through OpenXR. Notable capabilities include a world-locked menu, a VR-optimized HUD, and flexible first-person perspective options, allowing for enhanced player interaction within the game environment. The mod can be installed easily alongside the existing F.E.A.R. files, catering to users with compatible VR setups on Windows 10/11.
2026-08-03
C++
★ 24
GBFRUltrawide is an x64 ASI plugin designed to enhance the gameplay experience of Granblue Fantasy: Relink v2.0.3 by providing custom resolution and aspect ratio fixes specifically for ultrawide displays (21:9 / 32:9). Notable features include a corrected HUD layout, full-screen visual effects, and various settings for adjusting the field of view and camera distances, ensuring optimal display performance without distortion. Additionally, it offers detailed logging for troubleshooting and maintaining compatibility with future game updates.
2026-08-03
C++
★ 461
Half-Life 2 SDK Mirrors
2026-08-03
C++
★ 18
IW3SR is a client modification for Call of Duty 4 that enhances gaming performance and experience through features such as an in-game GUI, a runtime plugin system, and advanced movement physics. Notable functionalities include support for various movement styles, offline shader playback, and integrated video playback capabilities. This tool aims to provide players with improved gameplay mechanics and customization options while maintaining compatibility with existing game environments.
2026-08-03
C++
★ 23
Multivoid is a standalone mod designed to introduce drop-in co-op functionality to the single-player game Voices of the Void without modifying original game files. It supports up to four players via LAN or Internet and offers features such as seamless mid-game joining, 3D positional voice chat, and a comprehensive synchronization system for various game mechanics. The project is currently in its alpha phase, focusing on establishing a solid multiplayer foundation and ensuring game systems are accurately synced.
2026-08-03
C++
★ 52
The Native Predicate Solver is a C++ plugin for Binary Ninja that efficiently removes opaque predicates from binary functions, thereby optimizing decompilation and analysis. It leverages multi-threading for parallel function processing and conducts iterative analysis to ensure comprehensive removal of constant conditional branches. The tool is designed for speed and performance, making it particularly effective for managing large binaries.
2026-08-03
C++
★ 416
OpenFusion is a reverse-engineered server for the online game FusionFall, enabling players to access and play versions `beta-20100104` and `beta-20111013`. The tool supports easy installation via a launcher or standalone zip file and allows users to host their own servers with customizable options for IP and game version. Notable features include automatic progress saving and support for Linux through Wine, making it accessible to a wider range of users.
2026-08-03
C++
★ 29
Reach is a decompilation project for Halo Reach that enables developers to examine and modify the game's code structure. Its primary use case is to facilitate reverse engineering for educational and modding purposes, although it requires a legitimate copy of the game to function. Notable features include detailed progress tracking for both code and data decompilation, alongside support for specific debug tag versions.
2026-08-03
C++
★ 32
Tsuru is a platform designed for modders of New Super Mario Bros. U, providing a comprehensive toolset and API for custom code development. It includes numerous code examples and pre-made patches to assist new modders while aiming to unify various coding projects for easier access. The tool supports the standalone version 1.3.0 of the game and offers a patch installer for seamless integration.
2026-08-03
C++
★ 15
Bullseye is a reverse engineering tool specifically designed for the game Resident Evil: Dead Aim, facilitating the extraction of game assets such as audio files, model data, and textures, with ambitions of achieving full decompilation. It supports meticulous matching of the original executable by reconstructing the binary byte-for-byte, ensuring that every loadable portion is accurate, a characteristic vital for developers and modders aiming to analyze or modify the game's code. Key features include a structured build process utilizing an EE binutils toolchain and compatibility with original game dumps, allowing users to verify the integrity of their builds against the original release.
2026-08-03
C++
★ 29
The Geometry Dash (1.710) decompilation project aims to recreate the core functionality of the game using an older version of the cocos2d-x framework to address limitations present in later versions, such as broken screen orientations and lack of slope features. Currently in a work-in-progress state, it supports multiple platforms, including iOS, Android, macOS, Windows, and Linux, while facilitating community contributions and providing SHA-1 file hashes for various builds.
2026-08-03
C++
★ 110
Open Test Drive Unlimited (OpenTDU) is a source port for the PC version of Test Drive Unlimited, aimed at enhancing compatibility with modern systems by addressing issues related to AI, rendering, and security while providing cross-platform support. This tool allows users to run the game on Windows, Linux, and macOS, necessitating a legal copy of the original game assets. Notable features include a debug menu, command line options for various game modes, and a structured approach to ongoing project development status.
2026-08-03
C++
★ 28
Yet Another Packer (YAP) is a tool designed for the obfuscation and protection of x86_64 Windows PE applications, such as executables and DLLs, specifically excluding C# files. Its primary use case focuses on enhancing application security through a packer that encapsulates the original application to hinder static and dynamic analysis, as well as a reassembler that mutates and reassembles code to further obscure its functionality. Notable features include anti-debugging and anti-dumping mechanisms, alongside an SDK for seamless integration within protected applications.
2026-08-03
C++
★ 38
Aidyn is a decompilation project for the Nintendo 64 game Aidyn Chronicles: the First Mage, aimed at analyzing the game's internal mechanics and potentially porting it to modern platforms. The repository includes symbolic tables, pseudocode of source files, and headers, enabling insights into the game's structure and functionality. Despite challenges in producing usable code due to compiler limitations and the nature of the original programming, the project explores various porting avenues to enhance performance and modernize gameplay.
2026-08-03
C++
★ 70
Game Tracking: Deadlock is a tool designed for automated tracking of in-game activities, allowing users to monitor various events without manual intervention. Its primary use case is to simplify the process of game analytics by aggregating data from multiple sources. Notable features include integration with a comprehensive tracking system as referenced in the main GameTracking repository and community support through a dedicated Discord channel.
2026-08-03
C++
★ 54
Haggle Mod SDK is a modding tool specifically designed for Peggle Deluxe, enabling users to exploit the game's SexyFramework and Peggle functions through an external wrapper. Its primary use case includes facilitating the creation and loading of custom mods into the game, using the Haggle Mod Loader to inject mod code at startup. Notable features include an intuitive installation process, mod file management, and support for community-driven mod development through DLL integration.
2026-08-03
C++
★ 24
Kagura is an LLVM-based code obfuscation and anti-tamper toolkit designed for mobile, desktop, and WebAssembly applications. It supports extensive protection mechanisms against threats such as static string extraction, decompiler-readable control flows, and dynamic instrumentation, employing techniques like string encryption, control flow flattening, and runtime checks. The toolkit integrates seamlessly with multiple platforms without requiring modification of the LLVM source tree, making it versatile for developers seeking enhanced security for their applications.
2026-08-03
C++
★ 248
MetaHookSv is a client-side modding framework designed for the SvEngine and other GoldSrc engine-based games, aimed at enhancing gameplay experience in titles like Sven Co-op. It supports a variety of engine versions and ensures compatibility with numerous plugins from the original MetaHook project. Key features include a one-click installation process, extensive compatibility with different GoldSrc variants, and tools to manage game performance and memory usage.
2026-08-03
C++
★ 161
This repository provides a work-in-progress decompilation of the GameCube, Xbox 360, and PS2 versions of Need for Speed: Most Wanted, with a primary focus on the GameCube variant. It facilitates the extraction and rebuilding of game binaries, requiring an existing copy of the game for use, and supports multiple versions of the game with detailed instructions for setup on various operating systems. Notable features include automated build processes and integration with a diffing tool for code comparisons, enhancing the development and analysis capabilities of the decompiled code.
2026-08-03
C++
★ 259
Omni is a header-only C++23 library designed for Windows that facilitates loader inspection, export parsing, and syscall management. Its key features include utility functions for module handling, lazy imports, high-level access to API sets, and enhanced performance through compile-time optimizations, making it suitable for developers who require efficient interaction with Windows' native APIs. Additionally, Omni offers optional caching mechanisms for improved performance during lazy imports and syscall identification.
2026-08-03
C++
★ 84
OpenBarnyard is a work-in-progress project focused on decompiling the video game Barnyard and the TOSHI 2.0 game engine developed by Blue Tongue Entertainment, primarily aimed at educational purposes and community contribution. It enables developers to explore the game mechanics through reverse engineering while providing a Ghidra repository for those looking to contribute to the project. Notable features include a build system for Windows using Visual Studio and a clear emphasis on supporting the original developers and discouraging piracy.
2026-08-03
C++
★ 338
REPENTOGON is an advanced mod for *The Binding of Isaac: Repentance+* that enhances the Lua API with critical bug fixes, extended functionality, and performance optimizations. Unlike traditional mods, REPENTOGON operates as an "EXE mod," interfacing directly with the game's code through the LibZHL framework, allowing for sophisticated modifications that were previously unachievable. Notable features include a robust API documentation, extensive enhancements to game mechanics, and an emphasis on performance without the need for intensive hacks.
2026-08-03
C++
★ 242
The sead repository offers a decompilation of the standard C++ library used in first-party Nintendo games, specifically targeting more recent versions of the library. Its primary use case is to enhance interoperability and facilitate the development of projects that interact with these games, by accurately recreating the library structure based on debugging symbols from selected titles. Notable features include modular organization for various functionalities such as audio, graphics, and threading, as well as support for multiple Nintendo platforms through configurable source directories.
2026-08-03
C++
★ 37
ShadowStrike Phantom is an open-source endpoint protection platform for Windows 10/11 that aims to deliver advanced threat detection capabilities comparable to commercial EDR solutions. Notable features include a custom kernel driver with 20 detection subsystems, an on-device analysis engine utilizing neural networks, and a malware emulation engine—all designed to ensure transparency and audibility in its security processes.
2026-08-03
C++
★ 286
SickoMenu v4.5.2 is a utility tool for the game Among Us, designed to enhance gameplay through various custom features, including NoClip, Ghost Visibility, and SickoChat. It is intended strictly for educational and experimental purposes within private lobbies, and emphasizes ethical use to avoid violations of Innersloth's terms. Notable functionalities include gameplay modifiers and a comprehensive list of mischief-inducing options, promoting responsible use while exploring game mechanics.
2026-08-03
C++
★ 13
Sonic Heroes is a decompilation project aimed at preserving the Nintendo GameCube version of the game, specifically targeting the G9SE8P revision. This non-commercial initiative does not contain any game code or assets but allows users to build their own copy using a legally obtained game. Notable features include detailed tracking of progress through badges, cross-referencing with PS2 builds for metadata, and a strict adherence to legal guidelines concerning artifact distribution.
2026-08-03
C++
★ 17
ttd-capa is a capability extractor that works with Time Travel Debugging (TTD) traces to identify the capabilities exercised by a binary during its runtime execution. Designed to enhance the analysis of packed or obfuscated malware, it generates CAPA-compatible reports that allow for the extraction of runtime capabilities, leveraging full execution context and timestamp data for detailed analysis. Notable features include automatic resolution of string arguments, reconstruction of execution order, and integration with existing CAPA rule sets for comprehensive malware triage.
2026-08-03
C++
★ 111
wow_optimize is a performance optimization DLL specifically designed for World of Warcraft 3.3.5a, targeting enhancements at the engine and runtime level to address memory allocation, Lua VM efficiency, and various low-level bottlenecks. Its primary use case is to improve frametime stability and reduce Lua overhead during addon-heavy gameplay while maintaining safety from historically unsafe features. Notable features include memory address space reduction, CPU-intensive optimizations, and compatibility adjustments that allow for smoother long-session gameplay.
2026-08-03
C++
★ 74
OpenShock Firmware is designed for controlling shockers using reverse-engineered proprietary Sub-1 GHz protocols, specifically targeting the ESP-32 microcontroller equipped with a 433 MHz antenna. The firmware supports various compatible hardware platforms and facilitates easy flashing through PlatformIO in Visual Studio Code. Notable features include a comprehensive guide for setup and assembly, alongside thorough documentation and support through an active community.
2026-08-03
C++
★ 301
PrimeDecomp/prime is a decompilation project for the game Metroid Prime, requiring a valid game copy to function. It supports multiple game versions and emphasizes the use of native build tools for optimal performance across various operating systems including Windows, macOS, and Linux. Notable features include automatic rebuilds during development and compatibility with various disc image formats for easy setup.
2026-08-03
C++
★ 11
The Advanced Anti-Sandbox Virtual Machine tool develops techniques to counteract sandbox detection in malware analysis environments. Its primary use case is to assist security researchers and malware developers in executing samples without triggering detection in virtualized analysis frameworks by employing various bypass strategies, including path verification and time-based checks. Notable features include static bypassing capabilities, integration with C++ programming, and the ability to adapt to various sandbox systems, enhancing the efficacy of evasion techniques.
2026-08-03
C++
★ 39
BetrockPlusPlus (BPP) is a comprehensive, from-scratch reimplementation of Minecraft Beta 1.7.3, designed to function both as a client and server while prioritizing compatibility and faithful reproduction of original features. The tool is cross-platform, being compatible with both Windows and Linux, and fully open-source, providing the community with opportunities to fork, contribute, and enhance the project. Notably, BPP emphasizes clean coding practices by avoiding the use of decompiled code, ensuring that any necessary references to such code are clearly documented.
2026-08-03
C++
★ 19572
Cutter is a free and open-source reverse engineering platform designed for reverse engineers, featuring advanced customization capabilities while prioritizing user experience. It supports various plugins, including Python and C++ integrations, and enables seamless use of tools like the Ghidra decompiler. Cutter is accessible on major platforms, including Linux, macOS, and Windows, with detailed documentation available for users and developers.
2026-08-03
C++
★ 3244
DIE-engine is a software tool that provides both GUI and console interfaces for Detect It Easy (DiE), which is designed for analyzing file formats and detecting packers and compilers used in executable files. Its primary use case is for cybersecurity professionals and reverse engineers who need to identify binary file characteristics quickly. Notable features include support for a wide range of file types and the ability to analyze executable files efficiently.
2026-08-03
C++
★ 54616
ImHex is a powerful hex editor designed for reverse engineers and programmers, providing a user-friendly interface suitable for working in low-light conditions. Its primary use case includes inspecting binary files and conducting memory analysis, with notable features such as plugin support, an online version, and comprehensive documentation. This tool enhances visibility and usability with its built-in dark theme and various customization options, facilitating efficient data manipulation and analysis.
2026-08-03
C++
★ 582
Nauz File Detector is a portable utility designed to identify linkers, compilers, and packers used in files across macOS, Linux, and Windows platforms. Its primary use case is for reverse engineering and malware analysis, providing users with the ability to quickly analyze file formats. Notable features include cross-platform compatibility and easy access to detailed documentation for setup and usage.
2026-08-03
C++
★ 1724
The Pharos Static Binary Analysis Framework facilitates automated analysis of binary programs, leveraging the ROSE compiler infrastructure for disassembly, control flow analysis, and instruction semantics. Notable features include the OOAnalyzer for object-oriented construct recovery, ApiAnalyzer for detecting API call sequences, and tools like FN2Yara and FN2Hash for generating signatures and properties for function analysis. The framework is designed for research purposes and actively supports discussions in the domain of binary static analysis.
2026-08-03
C++
★ 447
Phobos is a community-driven engine extension for Yuri's Revenge that enhances gameplay by introducing new features and fixes based on modified YRpp and SyringeEx for code injection. It is designed to complement the existing Ares tool without introducing incompatibilities, offering users both stable and development builds for testing and integration of new features. Key attributes include its independence from Ares, active community engagement, and the ability to provide nightly builds with the latest changes for development purposes.
2026-08-03
C++
★ 1799
REDasm is a free and open-source disassembler tailored for reverse engineering, catering to both hobbyists and professionals. Its plugin architecture allows for extensibility and supports various CPU architectures and executable formats, making it a versatile tool in the reverse engineering toolkit. The latest version, 4.0.0, features a completely redesigned foundation, enhancing its performance and usability.
2026-08-03
C++
★ 139
The Super Mario 64 DS Decompilation (sm64ds-decomp) project offers a comprehensive decompilation of the Super Mario 64 DS game into matching C source code, aiming to produce a binary identical to the original retail ROM. Notable features include a systematic verification process for function matching using automated templates and manual coding, a progress tracking treemap, and an emphasis on maintaining legal compliance by avoiding the inclusion of ROM data or assets. The repository serves as a collaborative platform for contributors to enhance and refine the decompilation effort.
2026-08-03
C++
★ 693
XAPKDetector is a cross-platform tool designed for detecting and analyzing Android APK and DEX files, providing information on build tools, libraries, and security protections. Its primary use case lies in aiding developers and security analysts in assessing the integrity and characteristics of APK files. Notable features include comprehensive reporting on the application's components and support for multiple operating systems including Windows, Linux, and MacOS.
2026-08-03
C++
★ 16
RE-helper is a reverse engineering tool designed to assist with solving challenges during Capture the Flag (CTF) contests. It allows users to set up an environment for analyzing executables, offering features like dynamic tracing and syscalls logging, with capabilities for testing modifications and cleaning builds. The tool is currently in development and primarily targets amd64 architecture.
2026-08-03
C++
★ 29
Stegreg is a C++ based steganography tool that enables users to encrypt and conceal data within image files, specifically supporting JPG and PNG formats. Its primary use case is to hide messages within images through byte manipulation, while also allowing for easy extraction of the hidden data. Notable features include command-line options for encoding and decoding messages, as well as a straightforward installation process.
2026-08-03
C++
★ 10
My Reversing Utils is a collection of open-source tools designed for reversing, debugging, and software analysis, offering utilities for process management as well as web and binary analysis. Key features include the ProcSuspender, which enables users to launch processes in a suspended state for detailed debugging. This repository serves as a practical resource for security researchers and developers looking to facilitate their software analysis tasks.
2026-08-03
C++
★ 19
Scallop Shell is a specialized debugger and decompiler designed to analyze polymorphic code in binary executables across Linux and macOS. It differentiates itself from traditional reverse engineering tools by dynamically disassembling memory, providing real-time views of executing instructions, and facilitating live patching of byte displays. Notable features include architecture specification for QEMU binaries, a streamlined command-line interface, and capabilities for direct memory editing, making it particularly suited for handling complex binary obfuscation.
2026-08-03
C++
★ 29
Worm GPT Core is an advanced adversarial prompt delivery framework designed for AI researchers and cybersecurity professionals to evaluate and exploit vulnerabilities in large language models (LLMs). It automates the delivery of jailbreak prompts and features innovative mechanisms for alignment evasion, multi-threaded prompt execution, and seamless integration with both commercial and local LLMs. The tool aims to enhance penetration testing capabilities within AI systems while ensuring zero telemetry and optimized performance.
2026-08-03
C++
★ 11
DLL Hijacking Vulnerability Scanner is a specialized tool for identifying DLL hijacking vulnerabilities within signed Windows executable files. It features automated scanning, DLL dependency analysis, and comprehensive filtering options, enabling security professionals to test executables for hijacking susceptibility and analyze their DLL loading behaviors, as well as generating detailed vulnerability reports.
2026-08-03
C++
★ 17
OsintgramCXX is an advanced OSINT tool designed for collecting and analyzing publicly available information from Instagram with a focus on ethical use. Notable features include modding support for custom hooks and commands, device spoofing capabilities for network calls, manual interaction for user control, support for multiple proxies, and the ability to engage with multiple Instagram profiles simultaneously. Currently in active development, it aims to enhance user experience while adhering to legal and ethical standards.
2026-08-03
C++
★ 210
RunAs-Stealer is a credential harvesting tool designed to exploit Windows systems by implementing three techniques: hooking `CreateProcessWithLogonW`, smart keylogging, and remote debugging. Its primary use case is to stealthily capture user credentials and store them in an alternate data stream of a desktop.ini file for later retrieval. Notable features include continuous operation in the background and the ability to eliminate captured credentials directly via command-line instructions.
2026-08-03
C++
★ 138
SpyAI is an intelligent malware designed to capture screenshots of entire monitors and exfiltrate the data via a secure channel to a Command and Control (C2) server. Utilizing GPT-4 Vision, it analyzes the images frame by frame to construct daily activity reports. Key features include integration with Slack for secure communication and customizable operational parameters for timing and monitoring.
2026-08-03
C++
★ 31
The WiFi Handshake Capture Tool is designed for security researchers and penetration testers to passively capture WPA/WPA2 EAPOL 4-way handshakes using an ESP32 development board. Key features include compatibility with standard network analysis tools like Wireshark and Aircrack-ng, a web interface for data retrieval, and the ability to save captures in PCAP format, facilitating further analysis. Users must adhere to legal and ethical standards when utilizing this tool for authorized network testing.
2026-08-03
C++
★ 403
PhiSiFi is a dual-function cybersecurity tool designed to exploit WiFi networks using an ESP8266 microcontroller, implementing both Deauthentication and Evil-Twin access point (AP) attacks simultaneously. It allows users to disconnect devices from a target WiFi network while also setting up a fake AP to capture passwords from unsuspecting users, verifying them against the original access point. Notable features include a user-friendly interface for managing attacks and the ability to execute both methods without manual toggling.
2026-08-03
C++
★ 38
Echo433 is an Arduino-based tool designed for sniffing, logging, and replaying signals in the 433MHz frequency range, primarily used for auditing home automation systems and testing RF remotes. Notable features include automatic signal logging to an SD card, the ability to clone and retransmit captured signals, and a straightforward setup utilizing the RHSwitch library for ease of use.
2026-08-03
C++
★ 18
OpenDoorSim is an open-source tool designed to simulate Physical Access Control Systems (PACS) for hands-on experimentation and research. It supports integration with both Wiegand and OSDP readers, featuring a web UI, on-device menu, and various operating modes for enhanced functionality. The tool is highly portable, powered via USB-C, and optimized for creating engaging demos and workshops in the field of RFID security.
2026-08-03
C++
★ 135
EmpireCTF is a comprehensive repository of Capture The Flag (CTF) write-ups that chronologically documents solutions and methodologies applied in various CTF competitions from 2018 to 2025. The primary use case of this tool is to serve as a reference for cybersecurity enthusiasts and professionals seeking to enhance their skills in solving CTF challenges. Notable features include categorized write-ups by year and challenge type, facilitating easy navigation and study of different techniques and tools utilized in the CTF landscape.
2026-08-03
C++
★ 90
HTTPWorker is a Flask-based command and control (C2) framework designed for security competitions, utilizing custom Windows implants written in C++. Its primary use case involves coordinating and managing remote Windows clients with capabilities such as command execution, file management, system information retrieval, and user interface access through an authentication-protected web app. Notable features include Docker support for deployment, integration with Pwnboard for beacon tracking, and customizable implant configurations to evade detection.
2026-08-03
C++
★ 416
IconJector is a Windows Explorer DLL injection tool that uses the change icon dialog to trick users into loading a malicious DLL into the explorer process. The tool allows for both user-driven DLL loading disguised as an icon and programmatic DLL injection into the explorer, leveraging the properties of DLLs and their optional DllMain functions to execute arbitrary code within the explorer's memory. Key features include the ability to create an icon representation of a DLL and various injection techniques, providing significant potential for exploitation.
2026-08-03
C++
★ 268
KittyLoader is an advanced evasive loader developed in C and Assembly, primarily designed for educational purposes in the realm of defensive cybersecurity. Its capabilities include early execution hijacking, module hiding through unlinking from various lists, and a range of sophisticated anti-analysis techniques like multilayer scoring and jittered operational delays to evade detection. Additionally, it employs encryption for embedded payloads using high-entropy randomness, allowing for stealthy API resolution and library loading, which significantly enhances its evasion tactics against static and dynamic analyses.
2026-08-03
C++
★ 57
Stealth Keylogger is a discreet Windows keylogger that utilizes low-level keyboard hooks to capture all keystrokes across the system, including special characters and unicode, while tracking the active window. Its notable features include a thread-safe buffer, immediate data flush upon right-click or enter, mechanisms for evading detection such as indirect syscalls and API hashing, and configurable logging to a file or transmission to a command and control server. The tool is designed for educational and authorized security research purposes.
2026-08-03
C++
★ 10
SyscallInjector is a stealthy DLL injector designed to execute direct syscalls on Windows, effectively bypassing endpoint detection and antivirus hooks. Its notable features include dynamic resolution of System Service Numbers, manual PE mapping, and the use of RWX memory allocation to circumvent commonly hooked functions. Additionally, it incorporates a mechanism to wipe shellcode after execution to further evade detection.
2026-08-03
C++
★ 21
UFSC OFFSEC PwnBase is an academic initiative aimed at enhancing practical knowledge in offensive security and ethical hacking through research and educational development. The project focuses on vulnerability studies, exploit development, and creating training materials while promoting participation in Capture The Flag (CTF) events, all adhering to ethical standards. Notable features include hands-on learning opportunities and a collaborative approach to cybersecurity education.
2026-08-03
C++
★ 37
Project Scorpio is a sophisticated Windows process injection loader that utilizes techniques such as PPID spoofing, manual DLL mapping, and direct NT syscall execution to stealthily execute staged shellcode within a targeted remote process. Notable features include its ability to fetch payloads from a command and control server using HTTP, spawn a decoy process with a masqueraded parent process, and replace the text section of a mapped DLL without registering it in system tools, thereby minimizing detection risk.
2026-08-03
C++
★ 15
WindowsShell-Injector is a shellcode execution framework designed for security research and penetration testing on Windows systems. It features encrypted payloads, anti-debugging mechanisms, and an intuitive Qt-based GUI, allowing for seamless loading and execution of shellcode. Notable capabilities include asynchronous execution via separate threads, dynamic memory protection, and runtime API resolution to enhance evasion of static analysis tools.
2026-08-03
C++
★ 49362
x64dbg is an open-source binary debugger designed specifically for Windows, facilitating malware analysis and reverse engineering of executables without source code access. Key features include a comprehensive plugin system for extensibility, support for both 32-bit and 64-bit debugging, and a user-friendly interface that offers various tools such as memory mapping and graph visualization to enhance the debugging process.
2026-08-03
C++
★ 16
AmongUsMenu is a cheat menu designed for the game Among Us, intended for educational purposes to demonstrate how cheating software operates. It offers two versions, a normal DLL for injection and a proxy version that integrates directly with the game, featuring a set of hotkeys for various functionalities such as showing a menu, radar, or console. The project has been archived and is no longer actively maintained.
2026-08-03
C++
★ 132
This tool is an exploit for the vulnerable Windows kernel driver eneio64.sys, enabling the mapping of physical memory read/write operations to virtual memory read/write. It demonstrates how to leverage this vulnerability for privilege escalation via token theft, targeting Windows 11 versions, specifically builds 22H2, 23H2, and 24H2. The exploit also outlines the necessary offsets for different Windows versions and serves as an educational resource.
2026-08-03
C++
★ 26
TokenElevation is a Windows utility that facilitates privilege escalation by enabling the SeImpersonatePrivilege, allowing the user to impersonate a logged-on user and duplicate the token of a specified target process. This tool is primarily used in administrative and debugging scenarios, enabling users with local Administrator access to execute new processes under the context of a target process to perform elevated tasks. Notable features include process token manipulation and the capability to spawn a new command prompt with the privileges of the target process specified by its PID.
2026-08-03
C++
★ 11
End-To-End-SOC-Home-Lab is a comprehensive project designed to construct a Security Operations Center (SOC) lab on a personal computer, utilizing Splunk for monitoring and detection of cybersecurity threats. It enables users to simulate various attack scenarios, analyze the resultant logs and telemetry, and develop effective detection mechanisms, thereby fostering skills pertinent to both red team attack simulations and blue team defensive strategies. Notable features include detailed guidance on setting up infrastructure, practical use cases for threat detection, and a focus on hands-on learning through real-world attack techniques.
2026-08-03
C++
★ 12
The external-process framework provides mechanisms for interacting with external Win32 processes, enabling operations such as reading and writing process memory, allocating memory, calling functions with various calling conventions, and performing code injection. It is primarily used for creating trainers or utilities that modify the behavior of running applications. Notable features include the ability to search for byte sequences in memory and a built-in external process simulator for testing purposes.
2026-08-03
C++
★ 195
The NmiCallbackBlocker is a driver concept that modifies kernel memory to prevent Non-Maskable Interrupts (NMIs) from executing by altering processor affinity masks. Its primary use case is to aid in bypassing anti-cheat mechanisms within gaming environments, leveraging techniques like signature scanning and structure manipulation for stealth operations. Notable features include the ability to evade detection through spoofing techniques and encrypted signatures, though it is important to note that the project includes no built-in anti-cheat protections.
2026-08-03
C++
★ 312
Sni5Gect is a comprehensive framework designed for sniffing unencrypted 5G NR messages and injecting custom packets during over-the-air communication between base stations and User Equipment (UE). It is primarily used for security research to conduct various attacks, such as crashing UE modems, downgrading network technologies, and implementing device fingerprinting and authentication bypass tactics. Notable features include the ability to capture MAC-NR messages and send arbitrary messages to target devices during specific communication states, enabling detailed exploitation of 5G networks.
2026-08-03
C++
★ 20
TowerOfFlaws is a proof-of-concept tool that demonstrates vulnerabilities in the anti-cheat driver (`GameDriverX64.sys`) of the game Tower of Fantasy, specifically related to arbitrary process protection and termination. The tool allows users to bypass protections and terminate processes like `notepad.exe`, showcasing the vulnerabilities in a controlled environment. It requires a C++20 compiler and CMake for building, and emphasizes responsible usage in authorized contexts.
2026-08-03
C++
★ 42
CVE-2026-PoCs is a curated repository providing a centralized collection of verified proof-of-concept exploits for vulnerabilities disclosed in the year 2026. Its primary use case is to serve security researchers and practitioners by offering a well-organized index of CVEs, complete with consistent metadata and a clear contribution process. Notable features include detailed listings of specific CVEs, affected products, and statuses of exploits, addressing the common issue of fragmented information across various platforms.
2026-08-03
C++
★ 222
The EAC Bypass + CR3 Ready IOCTL tool is a specialized driver designed to facilitate undetected communication and callback handling through IOCTL, primarily aimed at circumventing anti-cheat mechanisms. It serves as a foundational framework, allowing users to control CR3 and IOCTL communication between driver and user mode, while leaving advanced functionalities, such as handle randomization and user mode hiding, to the user's discretion. Notable features include a basis for EPROCESS bypass and miscellaneous system manipulations, emphasizing the need for user customization to complete the implementation.
2026-08-03
C++
★ 34
The poc-archive is a structured repository for security research proof-of-concepts (POCs), organized by categories such as web, network, binary, and more. It features detailed metadata, reproduction steps, and references for each POC, facilitating knowledge sharing and education within authorized security research contexts. Notable features include automated indexing, interactive POC scaffolding scripts, and a template system for contributing new entries.
2026-08-03
C++
★ 39
The CET Spoofing Detection tool is a proof of concept designed to identify stack spoofing vulnerabilities in CET (Control-flow Enforcement Technology) processes by comparing the shadow stack to the user stack to detect missing frames. Its primary use case is for security professionals assessing the integrity of CET implementations, and it features a straightforward terminal interface for running vulnerability checks on specific processes. However, users should note that the tool may produce false positives, particularly when analyzing .NET applications.
2026-08-03
C++
★ 18
Evil Goat is a Wi-Fi security education tool that simulates an Evil Twin attack by creating a fake access point with a captive portal to demonstrate phishing techniques and enhance user awareness. Key features include automatic DNS redirection, a simulated login portal, local data storage for educational labs, and a web-based configuration panel. The project is intended exclusively for educational and laboratory purposes, emphasizing responsible use and ethical practices in cybersecurity training.
2026-08-03
C++
★ 532
HVNC is a standalone client-server tool designed to create a hidden virtual desktop on the operator's side, allowing remote control over a target machine akin to the HVNC module of the TinyNuke banking trojan. Notable features include customizable process launching via a command menu, browser launchers for multiple web browsers, and a hidden client console. It serves primarily for educational and research purposes regarding remote access techniques.
2026-08-03
C++
★ 41
ModuleStomped is a proof-of-concept tool designed to detect module-stomped DLLs by analyzing the pdata section of various processes, which remains unchanged and thus provides a more reliable detection mechanism than analyzing the .text section. It features two primary modes: a process scanner that inspects all accessible processes for anomalies, and an ETW mode that monitors image load events for specified DLLs. Notably, the tool emphasizes the correlation of stack frames with pdata as a potential detection strategy, while acknowledging potential evasion techniques.
2026-08-03
C++
★ 59
PH4NTØM ROOTKIT is a Windows usermode rootkit designed for educational research, featuring techniques for stealth, privilege escalation, and command-and-control (C2) infrastructure. Notable features include token stealing and named pipe impersonation for privilege escalation, inline hooking for process and file hiding, and a comprehensive C2 setup allowing for real-time keylogging and remote execution commands. It emphasizes defensive learning while providing extensive evasion mechanisms against analysis and detection.
2026-08-03
C++
★ 57
ASHIRT is a Qt-based tray application designed for capturing screenshots and codeblocks associated with a specific ASHIRT instance. Its primary use case involves enabling users to take screenshots through a user-defined key or tray menu selection, while managing submissions to a remote ASHIRT backend. Notably, it supports multiple Linux distributions and provides flexibility for configuration and usage within various desktop environments.
2026-08-03
C++
★ 727
The Red-Team-Exercises repository serves as a compilation of educational posts focusing on various red team tactics and techniques. This resource is primarily designed for cybersecurity professionals seeking to enhance their skills in areas such as shellcode execution, evasion techniques, and phishing campaigns. Notable features include detailed descriptions of each exercise, covering advanced topics like AMSI bypass, process injection, and Active Directory enumeration.
2026-08-03
C++
★ 421
mkPIVM is a polymorphic, position-independent shellcode virtualizer designed for Windows x86 and x64, which enables the obfuscation of raw shellcode by converting it into a virtual machine that interprets encrypted instructions. Its primary use case is enhancing the stealth of shellcode to evade signature-based detection, leveraging features such as customizable cipher families, opcode permutations, and detailed control over the virtual machine's configuration. The tool supports various operational modes, including full lifting, packing, and hybrid approaches, making it versatile for evasion techniques in offensive cybersecurity applications.
2026-08-03
C++
★ 123
NocturneLdr is a research-oriented Windows x64 shellcode loader designed to produce clean, fully backed call stacks that evade detection by modern EDR solutions and forensic analysis tools. By injecting code into a legitimate module's `.text` section and utilizing genuine unwind metadata, it maintains call stack integrity while eliminating C runtime dependencies. Notable features include compile-time API hash resolution to obscure function names and IAT camouflage with benign imports, enhancing stealth against static analysis.
2026-08-03
C++
★ 157
PolyEngine is an evasive PE packer designed for research purposes, particularly in CTF challenges and low-level Windows security education. It employs advanced techniques such as in-memory execution, obfuscation, and various evasion options (like process name spoofing and API- hammering) to bypass EDR and AV detection mechanisms. This tool is intended for authorized security testing and educational use only, with comprehensive features for embedding payloads and managing execution context.
2026-08-03
C++
★ 16
This repository contains a collection of scripts designed for the Digispark Attiny85, enabling various pranks and system manipulation tasks on Windows systems. Notable features include the ability to execute fake updates, system crashes, information gathering, and reverse shells through Metasploit and Netcat. The scripts serve educational purposes and require specific dependencies for operation.
2026-08-03
C++
★ 23
Hydrangea-C2 Payloads is a command and control (C2) payload generator designed for creating and managing agents within a client-server communication framework. Its primary use case lies in facilitating the control of remote agents for task execution, file manipulation, and process management, with capabilities for advanced operations like DLL injection and keylogging. Notable features include a versatile command interface for both Windows and Linux systems, as well as support for various agent commands encapsulated in a structured communication protocol.
2026-08-03
C++
★ 45
Maliketh is a multi-user, customizable command and control (C2) framework designed to be flexible for operators. It features cross-platform support through its initial C++ and Golang implants, allowing for behavior modification based on server configurations, file operations, command execution, and self-destruct capabilities, among others. Notable functionalities include basic anti-debugging measures and a range of file management operations, making it suitable for diverse operational scenarios.
2026-08-03
C++
★ 14
Dark Nexus is a modular and multi-threaded C++17 framework designed for comprehensive network reconnaissance and infrastructure analysis. It consolidates various tools into a single executable, offering powerful features including subdomain scanning, OSINT gathering, and advanced asset mapping through a user-friendly hybrid CLI. Its aggressive multi-threading capabilities and intuitive architecture ensure efficient operations across 12 distinct modules, catering to a wide range of reconnaissance needs without the burden of complex setups.
2026-08-03
C++
★ 125
POSEIDON is a keyboard-driven pentesting firmware designed for the M5Stack Cardputer-Advance, enabling users to perform 163 types of attacks across various wireless protocols including WiFi, BLE, and IR. This tool simplifies pentesting by allowing direct input for network navigation and management without the need for a PC or complicated coding. Notable features include the integration of an autonomous WiFi handshake hunter named Argus, customizable interface themes, and ongoing development towards FIDO2 hardware security key functionality.
2026-08-03
C++
★ 12
Pwning OpenEDR is a vulnerability research tool that identifies and showcases high-severity flaws in OpenEDR version 2.5.1, emphasizing reproducible exploits for security assessments. Notable features include detailed CVSS scoring for various vulnerabilities, comprehensive runtime proof evidence, and a structured approach for reproducing each advisory in a controlled environment. This tool is particularly useful for security researchers evaluating endpoint detection and response (EDR) solutions for potential weaknesses.
2026-08-03
C++
★ 81
UniGeek is a versatile multi-tool firmware designed for a wide range of ESP32-based handheld devices, enabling functionalities such as Wi-Fi and Bluetooth attacks, RF signal manipulation, and various diagnostic utilities. It offers an extensive feature set including network attacks, sub-GHz communication, NFC capabilities, and a suite of utility tools and games, all integrated into a user-friendly interface. Notable aspects of UniGeek include its comprehensive documentation and support for approximately 18 different device models.
2026-08-03
C++
★ 263
ESP-HACK is a comprehensive firmware for the ESP32 designed for radio frequency research and penetration testing, encompassing protocols in RF, Bluetooth, infrared signals, and GPIO integrations. Targeted at enthusiasts and pentesters, the tool features a wide array of functionalities including WiFi deauthentication, Bluetooth spamming, Sub-GHz signal analysis and jamming (where legal), and infrared control capabilities, all while permitting extensive customization through GPIO and support for various modulations. Its versatility makes it an essential resource for exploring and testing a variety of wireless communication technologies.
2026-03-30
C++
★ 710
Andromeda is a performance-oriented tool designed for accelerating the initial reverse engineering of Android applications, leveraging its C/C++ implementation. It aims to simplify the analysis process with a straightforward command-line interface, making it accessible for security researchers and developers. Currently in early development, Andromeda highlights the potential for speed improvements over alternative solutions in the same domain.
2026-03-30
C++
★ 741
DDisasm is a high-performance disassembler that accurately translates binaries from ELF and PE formats into a reassemblable assembly code representation using the GTIRB intermediate format. Utilizing the Datalog declarative logic programming language, it derives code locations, symbolization, and function boundaries, supporting multiple instruction set architectures including x86, ARM, and MIPS. Notable features include Docker support for easy setup and integration with GTIRB for further binary analysis and manipulation.
2026-03-30
C++
★ 757
GameTracking-Dota2 is a tool designed to automate the tracking of in-game statistics and player performance in Dota 2. Its primary use case is to relieve players of the manual effort involved in monitoring game data, providing streamlined insights into gameplay trends. Notable features include integration with a broader GameTracking ecosystem and community support via Discord.
2026-03-30
C++
★ 749
GpgFrontend is a modern encryption tool that leverages GnuPG to facilitate easy and secure encryption and signing of texts and files across multiple platforms, including Windows, macOS, and Linux. Key features include a portable solution that can be run from a USB drive, flexible management of key databases, and a strong focus on user privacy through various safety measures. The tool also supports extensive module development, allowing for customizable user experiences and features.
2026-03-30
C++
★ 807
librw is a cross-platform library designed to re-implement parts of RenderWare graphics, facilitating rendering and file format conversion across various platforms. It supports DFF and TXD file formats for PS2, D3D8, D3D9, and Xbox, with rendering capabilities via D3D9 and OpenGL backends, while being particularly useful for rendering within projects like GTA. Notable features include adaptable file format support, backend rendering versatility, and ongoing compatibility for multiple platforms.
2026-03-30
C++
★ 742
makin is a malware assessment tool designed to simplify the process of identifying anti-debugging techniques employed by malicious samples. It injects a DLL into the target process to monitor specific API calls, providing insights into debugger detection methods, and can generate IDA Pro scripts for setting breakpoints at the identified APIs. Notable features include the ability to hook various functions from ntdll.dll and kernelbase.dll , effectively revealing complex anti-debugging strategies.
2026-03-30
C++
★ 881
VulHunt is a vulnerability hunting framework aimed at assisting security researchers in identifying vulnerabilities within software binaries and UEFI firmware. Built on Binarly’s BIAS, it supports large-scale vulnerability management and integrates community-developed rulepacks while offering scanning capabilities for various binary formats, including BA2 and Binary Ninja databases. Additionally, it features an MCP server for integration with AI assistants, facilitating real-time vulnerability analysis and reporting.
2026-03-22
C++
★ 5651
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
2026-03-22
C++
★ 821
Framework to test any Anti-Cheat
2026-03-22
C++
★ 812
A bunch of Windows anti-debugging tricks for x86 and x64.
2026-03-22
C++
★ 3899
Open-source, cross platform Qt6 based IDE for reverse-engineering Android application packages. It features a friendly IDE-like layout including code editor with syntax highlighting support for *.smali code files.
2026-03-22
C++
★ 1609
RubberDucky like payloads for DigiSpark Attiny85
2026-03-22
C++
★ 1302
Public API, examples, documentation and issues for Binary Ninja
2026-03-22
C++
★ 1201
Export disassemblies into Protocol Buffers
2026-03-22
C++
★ 1316
An Active Defense and EDR software to empower Blue Teams
2026-03-22
C++
★ 2085
Decompilation of The Legend of Zelda: Breath of the Wild (Switch 1.5.0)
2026-03-22
C++
★ 903
Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.
2026-03-22
C++
★ 928
Detect deauthentication frames using an ESP8266
2026-03-22
C++
★ 1268
DRAKVUF Black-box Binary Analysis
2026-03-22
C++
★ 2953
edb is a cross-platform AArch32/x86/x86-64 debugger.
2026-03-22
C++
★ 1124
IDA plugin and loader for UEFI firmware analysis and reverse engineering automation
2026-03-22
C++
★ 2671
ESP32DIV is a multi-purpose wireless testing toolkit powered by an ESP32
2026-03-22
C++
★ 1024
Loading Remote AES Encrypted PE in memory , Decrypted it and run it
2026-03-22
C++
★ 787
Anti Forensics Tool For Red Teamers, Used For Erasing Footprints In The Post Exploitation Phase.
2026-03-22
C++
★ 810
Deploy stealthy reverse shells using advanced process hollowing with GhostStrike – a C++ tool for ethical hacking and Red Team operations.
2026-03-22
C++
★ 822
HAL – The Hardware Analyzer
2026-03-22
C++
★ 1188
Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of a process.
2026-03-22
C++
★ 1020
Hex Viewer/Editor/Analyzer compatible with Linux/Windows/MacOS
2026-03-22
C++
★ 822
Tool for reverse engineering macOS/OS X
2026-03-22
C++
★ 1912
IDA Pro plugin with a rich set of features: decryption, deobfuscation, patching, lib code recognition and various pseudocode transformations
2026-03-22
C++
★ 1459
This project has been moved to:
2026-03-22
C++
★ 824
iMonitor(冰镜 - 终端行为分析系统)
2026-03-22
C++
★ 2821
A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM.
2026-03-22
C++
★ 974
Keylogger is 100% invisible keylogger not only for users, but also undetectable by antivirus software. keylogger Monitors all keystokes, Mouse clicks. It has a seperate process which continues capture system screenshot and send to ftp server in given time.
2026-03-22
C++
★ 2363
A simple keylogger for Windows, Linux and Mac
2026-03-22
C++
★ 2558
Keystone assembler framework: Core (Arm, Arm64, Hexagon, Mips, PowerPC, Sparc, SystemZ & X86) + bindings
2026-03-22
C++
★ 1907
library for importing functions from dlls in a hidden, reverse engineer unfriendly way
2026-03-22
C++
★ 12978
视觉小说翻译器 / Visual Novel Translator
2026-03-22
C++
★ 1081
An open source interactive disassembler
2026-03-22
C++
★ 4207
An open-source low-code modding framework to create, manage and use themes/plugins for the desktop Steam Client without any low-level internal interaction or overhead.
2026-03-22
C++
★ 1837
Multi Theft Auto is a game engine that turns Grand Theft Auto: San Andreas into networked multiplayer.
2026-03-22
C++
★ 2470
Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.
2026-03-22
C++
★ 831
PE (and elf now!) bin2bin obfuscator
2026-03-22
C++
★ 1693
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
2026-03-22
C++
★ 1547
openblack is an open-source game engine that supports playing Black & White (2001).
2026-03-22
C++
★ 3849
Cross-platform game hack for Counter-Strike 2 with Panorama-based GUI.
2026-03-22
C++
★ 904
PDBRipper is a utility for extract an information from PDB-files.
2026-03-22
C++
★ 3517
Portable Executable reversing tool with a friendly GUI
2026-03-22
C++
★ 3582
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
2026-03-22
C++
★ 828
Proofs-of-concept
2026-03-22
C++
★ 765
A Majora's Mask 3D patch that restores some mechanics from the original game to get the best of both worlds
2026-03-22
C++
★ 3195
Playstation 2 Static Recompiler & Runtime Tool to make native PC ports
2026-03-22
C++
★ 1815
A Dynamic Binary Instrumentation framework based on LLVM.
2026-03-22
C++
★ 1706
The OpenSource Disassembler
2026-03-22
C++
★ 977
A modern re-implementation of the classic DOS game Duke Nukem II
2026-03-22
C++
★ 972
Deep ghidra decompiler and sleigh disassembler integration for rizin
2026-03-22
C++
★ 3560
🪅 Windows User Space Emulator
2026-03-22
C++
★ 2036
Lovingly referred to as the Swiss Army Knife of PC gaming, Special K does a bit of everything.
2026-03-22
C++
★ 1290
:zap: Worlds fastest steghide cracker, chewing through millions of passwords per second :zap:
2026-03-22
C++
★ 2214
C++ GUI for TegraRcmSmash (Fusée Gelée exploit for Nintendo Switch)
2026-03-22
C++
★ 844
Enumerate and disable common sources of telemetry used by AV/EDR.
2026-03-22
C++
★ 2575
Extracts text from video games and visual novels. Highly extensible.
2026-03-22
C++
★ 1180
Skyrim mod to play online!
2026-03-22
C++
★ 1635
A Pin Tool for tracing API calls etc
2026-03-22
C++
★ 927
Open Source Tripwire®
2026-03-22
C++
★ 4103
Triton is a dynamic binary analysis library. Build your own program analysis tools, automate your reverse engineering, perform software verification or just emulate code.
2026-03-22
C++
★ 16732
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
2026-03-22
C++
★ 1584
ELF file viewer/editor for Windows, Linux and MacOS.
2026-03-22
C++
★ 961
XMachOViewer is a Mach-O viewer for Windows, Linux and MacOS
2026-03-22
C++
★ 1168
A reimplementation of BioWare's Aurora engine (and derivatives). Pre-pre-alpha :P