domain: reverse-engineering
558 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| NationalSecurityAgency/ghidra Ghidra is a software reverse engineering framework built by the NSA that includes a suite of tools for disassembly, decompilation, graphing… | 95 | 72873 | stable |
| WerWolv/ImHex ImHex is a free, open-source hex editor built for reverse engineers, programmers, and security researchers. It offers binary analysis featu… | 86 | 54573 | active |
| skylot/jadx JADX is a Dex to Java decompiler that produces readable Java source code from Android APK, dex, aar, aab, and zip files, available as both … | 88 | 50219 | active |
| x64dbg/x64dbg x64dbg is an open-source user-mode binary debugger for Windows supporting both 32-bit and 64-bit executables. It is optimized for reverse e… | 90 | 49306 | active |
| zhaoxuya520/reverse-skill A cybersecurity skill router pack that directs AI coding agents (Claude Code, Cursor, Cline, Kiro) to the right reverse-engineering, penetr… | 69 | 29591 | active |
| librepods-org/librepods LibrePods is an open-source app that unlocks Apple AirPods-exclusive features on Linux and Android by implementing the proprietary Bluetoot… | 86 | 29585 | active |
| ILSpy ILSpy is an open-source, cross-platform .NET assembly browser and decompiler that converts compiled .NET binaries back into readable C# sou… | 98 | 25954 | active |
| iBotPeaches/Apktool Apktool is a Java-based command-line tool for reverse engineering Android APK files. It decodes resources and manifest files to nearly orig… | 89 | 25386 | stable |
| radare2 Radare2 is a libre reverse engineering framework and command-line toolset for analyzing, disassembling, debugging, emulating, and modifying… | 94 | 24652 | active |
| Frida Frida is a dynamic instrumentation toolkit that lets developers, reverse-engineers, and security researchers inject JavaScript or native li… | 94 | 21752 | active |
| cheat-engine/cheat-engine Cheat Engine is a desktop development environment for modding games and applications, centered on a memory scanner that finds and edits pro… | 30 | 19055 | active |
| javascript-obfuscator/javascript-obfuscator A powerful open-source JavaScript and Node.js obfuscator that transforms readable source code into hard-to-reverse-engineer output using id… | 99 | 16218 | active |
| Konloch/bytecode-viewer Bytecode Viewer is a free, open-source Java and Android APK reverse engineering suite that bundles six Java decompilers, bytecode disassemb… | 73 | 15614 | active |
| ReFirmLabs/binwalk Binwalk is a fast firmware analysis tool rewritten in Rust that identifies and optionally extracts files and data embedded inside other fil… | 66 | 14276 | active |
| jopohl/urh Universal Radio Hacker (URH) is a complete open-source suite for investigating wireless protocols, with native support for many common Soft… | 10 | 12569 | active |
| mrexodia/ida-pro-mcp An MCP server and IDA Pro plugin that connects IDA Pro's binary analysis capabilities to language models, enabling AI-assisted reverse engi… | 61 | 11616 | active |
| Detect It Easy Detect It Easy (DiE) is a cross-platform file type identification tool that uses signature-based and heuristic analysis to detect compilers… | 81 | 11420 | active |
| pwndbg/pwndbg Pwndbg is a Python-based plug-in for GDB and LLDB that enhances low-level debugging with features tailored to reverse engineering and explo… | 94 | 10801 | active |
| majd/ipatool A command-line tool written in Go that lets users search the iOS App Store and download app packages (ipa files) using their Apple ID. It s… | 88 | 9934 | active |
| LaurieWired/GhidraMCP GhidraMCP is a Model Context Protocol server implemented as a Ghidra plugin that exposes Ghidra's reverse engineering tools to LLM clients.… | 34 | 9865 | active |
| xenia-project/xenia Xenia is an experimental open-source emulator for the Xbox 360, developed through reverse engineering of legally purchased hardware and gam… | 63 | 9649 | active |
| alufers/mitmproxy2swagger A CLI tool that converts mitmproxy traffic captures (and HAR files) into OpenAPI 3.0 / Swagger specifications. It lets you reverse-engineer… | 83 | 9594 | active |
| Il2CppDumper Il2CppDumper is a C# command-line tool that extracts type, method, and string information from Unity IL2CPP binaries and their global-metad… | 23 | 9339 | active |
| unicorn-engine/unicorn Unicorn is a lightweight, multi-architecture CPU emulator framework based on QEMU, supporting ARM, ARM64, M68K, MIPS, PowerPC, RISC-V, SPAR… | 75 | 9268 | stable |
| angr angr is a Python 3 binary analysis framework that loads executables across many architectures and formats, providing disassembly, IR liftin… | 77 | 9039 | active |
| capstone-engine/capstone Capstone is a lightweight, multi-architecture, multi-platform disassembly framework written in pure C, designed to be the ultimate disassem… | 97 | 8976 | stable |
| n64decomp/sm64 A complete community decompilation of Super Mario 64 covering the Japan, North America, Europe, Shindou, and iQue releases, written in C. I… | 23 | 8737 | active |
| hugsy/gef GEF (GDB Enhanced Features) is a single-file Python plugin for GDB that adds a modern, feature-rich debugging experience for exploit develo… | 77 | 8326 | active |
| firerpa/lamda FIRERPA (lamda) is an all-in-one Android device control platform whose server runs directly on the device (root or non-root) and exposes 16… | 98 | 8243 | active |
| N64Recomp/N64Recomp A C++ tool that statically recompiles N64 game binaries into portable C code that can be compiled into native executables for any platform.… | 60 | 8093 | active |
| PCILeech PCILeech is DMA attack software that uses PCIe hardware devices (or software memory acquisition methods) to read and write target system me… | 65 | 7899 | active |
| r0ysue/r0capture A Frida-based universal Android application-layer packet capture script that hooks SSL/TLS regardless of certificate pinning, obfuscation, … | 64 | 7750 | active |
| SimoneAvogadro/android-reverse-engineering-skill A Claude Code skill that decompiles Android APK/XAPK/JAR/AAR files and extracts the HTTP APIs an app uses, including Retrofit, OkHttp, Ktor… | 59 | 7376 | active |
| Col-E/Recaf Recaf is a modern Java bytecode editor with a JavaFX GUI that abstracts away low-level class file complexities like constant pools and stac… | 69 | 7355 | active |
| ayoubfaouzi/al-khaser Al-Khaser is a proof-of-concept Windows application that demonstrates a wide range of malware anti-analysis techniques, including anti-debu… | 73 | 7108 | active |
| albertan017/LLM4Decompile LLM4Decompile is an open-source series of large language models (1.3B to 33B) trained to decompile binary code back into readable, executab… | 55 | 6986 | active |
| LumaTeam/Luma3DS Luma3DS is custom firmware for the Nintendo 3DS family of consoles that patches and reimplements parts of the system software. It adds home… | 81 | 6646 | active |
| hedge-dev/XenonRecomp XenonRecomp is a static recompilation tool that converts Xbox 360 (PowerPC) executables into C++ code that can be recompiled into native ex… | 38 | 6451 | active |
| snare/voltron Voltron is an extensible debugger UI toolkit written in Python that adds utility views (registers, disassembly, stack, memory, breakpoints,… | 25 | 6345 | active |
| dnSpy/dnSpy dnSpy is a Windows GUI application for debugging and editing .NET and Unity assemblies without needing source code. It combines a debugger,… | 10 | 29689 | maintenance |
| dwisiswant0/apkleaks APKLeaks is a Python CLI tool that decompiles Android APK files with jadx and scans them for URIs, endpoints, and hardcoded secrets using r… | 39 | 6275 | active |
| androguard/androguard Androguard is a full Python tool and library for reverse engineering and analyzing Android files, including DEX/ODEX bytecode disassembly a… | 83 | 6209 | active |
| mandiant/capa capa is Mandiant FLARE's open-source tool that identifies capabilities in executable files (PE, ELF, .NET, shellcode) by matching expert-wr… | 87 | 6156 | active |
| qilingframework/qiling Qiling is a Python-based binary emulation framework built on Unicorn Engine that emulates executables across multiple platforms (Windows, m… | 79 | 6075 | active |
| Ackites/KillWxapkg A Go-based CLI tool that automatically decrypts, unpacks, and decompiles WeChat mini-program .wxapkg packages, restoring the original proje… | 14 | 5957 | active |
| jindrapetrik/jpexs-decompiler JPEXS Free Flash Decompiler (FFDec) is an open-source Java application for decompiling and editing Adobe Flash SWF files. It extracts resou… | 93 | 5828 | active |
| lief-project/LIEF LIEF is a cross-platform C++ library (with Python and Rust bindings) for parsing, inspecting, modifying, and writing executable file format… | 97 | 5549 | stable |
| zeldaret/oot A community-driven, work-in-progress decompilation of The Legend of Zelda: Ocarina of Time that recreates readable C source code from the o… | 76 | 5489 | active |
| CreditTone/hooker hooker is a Frida-based reverse engineering toolkit for Android that provides a comfortable command-line interface with universal hooking s… | 70 | 5285 | active |
| mentebinaria/retoolkit An Inno Setup-based installer that bundles a curated collection of reverse engineering and malware analysis tools for x86/x64 Windows syste… | 82 | 5278 | active |
| Naituw/IPAPatch IPAPatch is an Xcode project template that lets you patch decrypted iOS app IPA files by injecting your own dynamic libraries, without requ… | 54 | 5275 | active |
| zhkl0228/unidbg A Java-based framework that emulates Android (and experimentally iOS) native libraries on non-ARM hosts, including JNI, syscalls, and ARM32… | 79 | 5165 | active |
| niklashigi/apk-mitm A Node.js CLI application that automatically patches Android APK files to allow HTTPS traffic inspection through a man-in-the-middle proxy.… | 23 | 5092 | stable |
| atom0s/Steamless Steamless is a C# tool that removes the SteamStub DRM protection layer applied to Steam game executables via the Steamworks SDK DRM tool. I… | 23 | 4990 | active |
| pret/pokered A complete assembly-language disassembly of Pokémon Red and Blue for the Game Boy, which can be rebuilt byte-identical into the original RO… | 76 | 4892 | active |
| charles2gan/GDA-android-reversing-Tool GDA (GJoy Dex Analyzer) is a fast, native C++ Dalvik bytecode decompiler and reverse analysis platform for Android binaries such as APK, DE… | 70 | 4818 | active |
| aloshdenny/reverse-SynthID A research tool that reverse-engineers Google's SynthID watermark embedded in Gemini-generated images using spectral analysis and signal pr… | 66 | 4815 | active |
| jmpews/Dobby Dobby is a lightweight, modular function hooking framework supporting multiple platforms (Windows, macOS, iOS, Android, Linux) and architec… | 24 | 4813 | active |
| Integuru-AI/Integuru Integuru is an AI agent that reverse-engineers platforms' internal APIs by analyzing browser network requests (HAR files) and building depe… | 62 | 4760 | active |
| snesrev/zelda3 A reverse-engineered reimplementation of The Legend of Zelda: A Link to the Past written in ~70-80k lines of C, playable from start to fini… | 23 | 4739 | active |
| kaitai-io/kaitai_struct Kaitai Struct is a declarative language for describing binary data structures (file formats, network packet layouts) in .ksy files. A compi… | 76 | 4664 | active |
| vaibhavpandeyvpz/apkstudio APK Studio is an open-source, cross-platform Qt6 IDE for reverse-engineering Android application packages. It bundles decompiling, recompil… | 69 | 4630 | active |
| zrax/pycdc Decompyle++ is a C++ tool that translates compiled Python bytecode (.pyc files) back into readable Python source code. It includes pycdas, … | 66 | 4594 | active |
| hluwa/frida-dexdump A Frida-based CLI tool that finds and dumps DEX files from an Android app's memory, enabling unpacking of packed or obfuscated APKs. It sup… | 10 | 4560 | stable |
| taviso/loadlibrary A library that lets native Linux programs load and call functions from Windows DLLs via a custom PE/COFF loader with a dlopen-like API. It … | 39 | 4501 | active |
| JonathanSalwan/ROPgadget ROPgadget is a Python command-line tool that searches binaries for ROP gadgets to facilitate return-oriented programming exploitation. It s… | 67 | 4470 | active |
| extremecoders-re/pyinstxtractor A Python script that extracts the contents of PyInstaller-generated executables, including fixing pyc headers so bytecode decompilers can p… | 84 | 4447 | stable |
| orhun/binsider Binsider is a terminal user interface tool for analyzing ELF binaries, offering static and dynamic analysis, string inspection, linked libr… | 84 | 4404 | active |
| joxeankoret/diaphora Diaphora is a free and open source program diffing (binary diffing) tool that works as an IDA Pro plugin, comparing binaries to find change… | 94 | 4373 | active |
| Volatility Volatility is an open-source memory forensics framework for extracting digital artifacts from RAM captures of Windows, Linux, and macOS sys… | 84 | 4357 | active |
| zyantific/zydis Zydis is a fast, lightweight x86/x86-64 disassembler and encoder library written in C with zero dependencies, not even libc. It supports al… | 65 | 4351 | active |
| rocky/python-uncompyle6 uncompyle6 is a cross-version Python bytecode decompiler that translates bytecode from Python 1.0 through 3.8 back into equivalent Python s… | 62 | 4316 | active |
| ufrisk/MemProcFS MemProcFS is an memory forensic tool that exposes physical memory, memory dump files, and live memory acquisition sources as files in a vir… | 89 | 4300 | active |
| JonathanSalwan/Triton Triton is a dynamic binary analysis library providing dynamic symbolic execution, taint analysis, and ISA semantics for x86, x86-64, ARM32,… | 65 | 4274 | active |
| x64dbg/ScyllaHide ScyllaHide is an advanced usermode anti-anti-debug library that hooks Windows functions to hide the presence of a debugger from debugged pr… | 23 | 4271 | active |
| magcius/noclip.website noclip.website is a browser-based application that lets users explore and fly through video game levels rendered from reverse-engineered mo… | 77 | 4246 | active |
| JaveleyQAQ/WeChatOpenDevTools-Python A Python tool that force-enables the hidden developer tools (F12) in WeChat mini programs and WeChat's built-in browser. It is a Python rew… | 16 | 4211 | active |
| mandiant/flare-floss FLOSS (FLARE Obfuscated String Solver) is a Python CLI tool from Mandiant that automatically extracts and deobfuscates strings from malware… | 67 | 4138 | active |
| GDRETools/gdsdecomp A tool for reverse engineering Godot game projects, supporting full project recovery from PCK, APK, or EXE files. It includes a PCK extract… | 98 | 4112 | active |
| wux1an/wxapkg A cross-platform desktop GUI tool built with Wails for scanning, decrypting, and unpacking WeChat mini-program .wxapkg files. It restores t… | 69 | 4037 | active |
| HyperDbg/HyperDbg HyperDbg is an open-source, hypervisor-assisted debugger for Windows (with Linux support in development) that uses Intel VT-x and EPT to de… | 94 | 4012 | active |
| APKLab/APKLab APKLab is a VS Code extension that turns the editor into an Android reverse-engineering workbench by integrating Apktool, Jadx, uber-apk-si… | 74 | 3952 | active |
| a0rtega/pafish Pafish is a Windows testing tool that applies the same VM and sandbox detection techniques used by malware families to check whether an ana… | 10 | 3946 | active |
| cea-sec/miasm Miasm is a free and open source (GPLv2) reverse engineering framework written in Python for analyzing, modifying, and generating binary pro… | 67 | 3944 | active |
| hasherezade/pe-sieve PE-sieve is a lightweight Windows tool that scans a given process for malicious implants such as replaced or injected PE files, shellcodes,… | 71 | 3867 | active |
| danielkrupinski/Osiris Osiris is a cross-platform (Windows and Linux) game hack for Counter-Strike 2, built in C++20 with a GUI and rendering based on the game's … | 77 | 3848 | active |
| ax/apk.sh A Bash script that automates Android APK reverse engineering tasks such as pulling, decoding, rebuilding, and patching APKs. It wraps apkto… | 73 | 3822 | active |
| Rizin Cutter is a free and open-source graphical reverse engineering platform built on top of the Rizin framework, a Unix-friendly command-line t… | 88 | 3806 | active |
| pwntester/ysoserial.net ysoserial.net is a proof-of-concept command-line tool that generates deserialization payloads exploiting unsafe .NET object deserialization… | 62 | 3782 | active |
| hasherezade/pe-bear PE-bear is a multiplatform GUI reversing tool for Windows PE (Portable Executable) files, built on bearparser and capstone. It gives malwar… | 78 | 3781 | active |
| HookVip (NewHookVip) NewHookVip is an Xposed module for Android that hooks into target apps to unlock certain membership/VIP features, remove some restrictions,… | 75 | 3696 | active |
| blacktop/ipsw ipsw is a Go-based command-line research framework for downloading, parsing, and analyzing Apple iOS and macOS firmware (IPSW/OTA files), M… | 95 | 3669 | active |
| Lessica/TrollFools TrollFools is an iOS application for TrollStore that performs in-place tweak injection into installed apps using insert_dylib and ChOma. It… | 74 | 3599 | active |
| Mouseww/anything-analyzer An Electron-based all-in-one protocol analysis toolkit that captures HTTP(S) traffic from browsers, desktop apps, terminals, scripts, and m… | 77 | 3586 | active |
| java-decompiler/jd-gui JD-GUI is a standalone graphical Java decompiler that displays Java source code reconstructed from .class files. It lets users browse decom… | 23 | 15180 | maintenance |
| icedland/iced iced is a fast and correct x86/x64 (16/32/64-bit) instruction decoder, disassembler, and assembler library with bindings for Rust, .NET, Ja… | 67 | 3556 | active |
| momo5502/sogen Sogen is a C++ userspace emulator that runs Windows and Linux binaries at the CPU and syscall level without a real operating system, execut… | 67 | 3553 | active |
| bethington/ghidra-mcp A Model Context Protocol (MCP) server and Ghidra plugin exposing 250+ tools that let AI agents drive Ghidra's reverse engineering capabilit… | 83 | 3508 | active |
| open-goal/jak-project OpenGOAL is a project that decompiles the Jak & Daxter PS2 games and recompiles them into native x86-64 ports, including a from-scratch imp… | 99 | 3489 | active |
| LEGO Island (decompilation) A functionally complete reverse-engineered decompilation of the 1997 game LEGO Island, reconstructing C++ source code that matches the orig… | 95 | 3461 | active |
page 1 / 6 next →