Ross ROSS = Recommend OSS · open-source software intelligence for agents

domain: reverse-engineering

558 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
JusticeRage/Gepetto
Gepetto is an IDA Pro plugin that queries large language models (OpenAI, Anthropic, Gemini, Ollama, and others) to explain decompiled funct…
793461active
kevoreilly/CAPEv2
CAPEv2 is a malware sandbox derived from Cuckoo that executes malicious files in isolated environments while instrumenting their behavior a…
773451active
pret/pokeemerald
A complete decompilation of Pokémon Emerald into C source code that rebuilds the exact original Game Boy Advance ROM. It serves as a base f…
773406active
jehna/humanify
A Rust CLI tool that unminifies and deobfuscates JavaScript by using LLMs (OpenAI, Anthropic, Gemini, OpenRouter, or local Ollama) to sugge…
923272active
SteamAutoCracks/Steam-auto-crack
A C# tool that automatically cracks Steam games by unpacking SteamStub-protected executables and applying the Goldberg Steam emulator. It a…
993243active
malmeloo/FindMy.py
FindMy.py is a Python library for querying Apple's Find My network to fetch and decrypt the location of AirTags, Apple devices, and custom …
883223active
LaurieWired/Malimite
Malimite is a Java-based decompiler for iOS and macOS binaries, built on Ghidra, that analyzes IPA files and Application Bundles with direc…
383174active
pxb1988/dex2jar
dex2jar is a set of Java-based command-line tools for working with Android .dex and Java .class files. It converts Dalvik executables (e.g.…
2313135maintenance
QiuChenly/CoreInject
CoreInject (successor to InjectLib) is a macOS application injection and binary-patching tool by QiuChenly, distributed alongside a communi…
843157active
BinDiff
BinDiff is an open-source comparison tool for binary files that finds differences and similarities in disassembled code using graph-theoret…
623155active
ttttupup/wxhelper
wxhelper is a C++ DLL that hooks the Windows PC WeChat client, exposing its internal functions through a local HTTP server (default port 19…
613141active
biggerstar/wedecode
Wedecode is a fully automated tool that decompiles WeChat mini-program and mini-game wxapkg packages back into readable source code (JS, WX…
603091active
m0bilesecurity/RMS-Runtime-Mobile-Security
Runtime Mobile Security (RMS) is a NodeJS-powered web interface built on FRIDA for manipulating Android and iOS apps at runtime. It lets us…
833075active
korcankaraokcu/PINCE
PINCE is a GDB front-end and reverse engineering tool for Linux, focused on game hacking but usable for general reverse engineering. It pro…
983069active
cilame/v_jstools
v_jstools is a Chrome extension (Manifest V3) for debugging and reverse-engineering JavaScript on web pages. It provides API hooking, code …
583015active
eteran/edb-debugger
edb is a cross-platform AArch32/x86/x86-64 debugger inspired by OllyDbg, built with Qt and Capstone. It provides a graphical interface for …
662952active
RfidResearchGroup/ChameleonUltra
ChameleonUltra is the open-source firmware for an RFID/NFC card emulation device based on the NRF52840, capable of reading, writing, decryp…
842949active
gildor2/UEViewer
UE Viewer (umodel) is a desktop application for viewing and exporting visual resources (meshes, animations, textures, sounds) from games bu…
232917active
j4k0xb/webcrack
webcrack is a JavaScript reverse-engineering tool that deobfuscates code obfuscated with obfuscator.io, unminifies minified code, and unpac…
782876active
gdbinit/MachOView
A macOS GUI application for viewing and exploring Mach-O binary files, revived as a maintained fork with a universal x86_64/arm64 build. It…
322868active
mrexodia/TitanHide
TitanHide is a Windows kernel driver that hides debuggers from selected processes by hooking Nt* kernel functions via SSDT hooks and alteri…
722840active
hasherezade/pe_to_shellcode
A C++ command-line tool that converts Windows PE executables into shellcode-compatible form, adding a reflective loading stub post-compilat…
402793active
panda-re/panda
PANDA is an open-source Platform for Architecture-Neutral Dynamic Analysis built on the QEMU whole-system emulator, supporting record and r…
932778active
Impact-I/reFlutter
reFlutter is a Python CLI framework for reverse engineering Flutter mobile apps by repacking APK/IPA files with a specially patched, precom…
952738active
AxtMueller/Windows-Kernel-Explorer
Windows Kernel Explorer (WKE) is a free Windows kernel research and inspection tool supporting Windows XP through Windows 11. It loads a ke…
582717active
zinja-coder/jadx-ai-mcp
A JADX plugin that bundles an MCP server, allowing LLM clients like Claude to interact with the JADX decompiler for Android APK analysis. I…
842711active
Artikash/Textractor
Textractor is an open-source x86/x64 text hooker for Windows that extracts text from video games and visual novels by injecting into text o…
232680active
decompiler-explorer/decompiler-explorer
A web service (like Compiler Explorer in reverse) that lets users upload small binaries and compare the decompiled C-like output from many …
772639active
REhints/HexRaysCodeXplorer
HexRaysCodeXplorer is a Hex-Rays Decompiler plugin written in C++ that improves code navigation during reverse engineering. It automates re…
472637active
worawit/blutter
Blutter is a reverse engineering tool for Flutter mobile applications that compiles the Dart AOT runtime to extract symbols and objects fro…
722627active
Keystone Assembler Engine
Keystone is a lightweight multi-platform, multi-architecture assembler framework implemented in C/C++ with bindings for many languages. It …
652625active
zhizhuodemao/js-reverse-mcp
An MCP server that gives AI coding agents (Claude, Cursor, Copilot) tools for JavaScript reverse engineering in a headed Chrome browser, in…
832608active
uxmal/reko
Reko is a general-purpose binary decompiler that translates machine code executables back into high-level language source. It supports mult…
892600active
gaasedelen/lighthouse
Lighthouse is a code coverage explorer plugin for IDA Pro and Binary Ninja that lets reverse engineers interactively visualize execution co…
532577stable
rednaga/APKiD
APKiD is a command-line tool that identifies how an Android APK was built, detecting compilers, packers, obfuscators, and app-shielding/RAS…
782565active
bkerler/edl
A Python CLI tool for communicating with Qualcomm devices in EDL (Emergency Download) mode via the Sahara, Firehose, Streaming, and Diag pr…
662547active
onekey-sec/unblob
unblob is an extraction suite that parses unknown binary blobs for 78+ archive, compression, and file-system formats, recursively extractin…
912544active
evi0s/WMPFDebugger
A debugger tweak for WeChat's Mini-Program Framework (WMPF) that exploits the remote debug feature of WeChat devtools to enable full Chrome…
652542active
DidierStevens/DidierStevensSuite
A bundled collection of Didier Stevens' security research tools, distributed as a ZIP and GitHub repository of Python scripts and utilities…
752525active
bug-bit/fckvip
An Android module (likely Magisk/LSPosed-based) that unlocks paid VIP memberships and enhances extended features in certain apps. It requir…
742500active
solemnwarning/rehex
Rehex is a cross-platform hex editor designed for reverse engineering binary files, with features like large file support, inline disassemb…
852476active
VirusTotal/yara
YARA is a pattern matching tool used to identify and classify malware families and other files based on textual or binary pattern rules. It…
949831maintenance
mandiant/flare-ida
A collection of IDA Pro plugins and IDAPython scripts from Mandiant's FLARE team for reverse engineering and malware analysis. It includes …
102453active
Yuyz0112/claude-code-reverse
A tool that reverse engineers Claude Code by capturing and visualizing its LLM API interactions. It monkey-patches Claude Code's request co…
372428active
msojocs/fiddler-everywhere-enhance
An auto-patch tool that modifies the Fiddler Everywhere web debugging proxy (an Electron app) on Windows and Linux, replacing DLLs and patc…
882403active
bootleg/ret-sync
ret-sync is a set of plugins that synchronize a debugging session (WinDbg, GDB, LLDB, OllyDbg, x64dbg) with disassemblers (IDA, Ghidra, Bin…
532378active
jxhczhl/JsRpc
JsRpc is a Go-based RPC server that lets you remotely invoke JavaScript methods running in a browser via WebSocket, avoiding the need to ex…
842347active
hzqst/VmwareHardenedLoader
A Windows kernel driver that mitigates VMware VM detection by filtering VMware-related firmware strings and blocking VMware PnP registry en…
872334active
Vineflower/vineflower
Vineflower is a modern Java and JVM bytecode decompiler forked from Fernflower, focused on producing accurate, readable output with support…
842327active
UMSKT/UMSKT
UMSKT (Universal MS Key Toolkit) is an open-source C++ CLI toolkit for researching and experimenting with Microsoft's pre-Vista (pre-2012) …
782318active
REAndroid/APKEditor
APKEditor is a Java command-line tool for editing Android APK resources without depending on aapt/aapt2. It can decode binary resources to …
892291active
bitcookies/winrar-keygen
An open-source tool and educational write-up explaining the principle behind WinRAR's 'rarreg.key' license file generation, with implementa…
962277active
a2x/cs2-dumper
An external offset/interface dumper for Counter-Strike 2 that reads the game process memory via memflow and generates offset files in forma…
722275active
BinaryAnalysisPlatform/bap
CMU Binary Analysis Platform (BAP) is a suite of OCaml libraries and a plugin-extensible CLI tool for analyzing binary programs. It lifts b…
592253active
Storyyeller/Krakatau
Krakatau is a Rust-based CLI tool for assembling, disassembling, and decompiling Java bytecode. It is specifically designed to handle obfus…
662244active
DanOps-1/Gpt-Agreement-Payment
A Python toolkit that reverse-engineers and replays the end-to-end ChatGPT Plus/Team/Pro subscription payment flow (Stripe Checkout, PayPal…
532225active
grimdoomer/Xbox360BadUpdate
A non-persistent, software-only hypervisor exploit for the Xbox 360 that runs unsigned code on the latest dashboard (17559) using a support…
102221active
eeeeeeeeee-code/e0e1-wx
A Windows GUI tool (PySide6, Python 3.10+) for analyzing and penetration-testing WeChat mini-programs locally. It automates mini-program pa…
802214active
avast/retdec
RetDec is a retargetable machine-code decompiler based on LLVM that converts native binaries back into readable C or Python-like source cod…
618612maintenance
Encryqed/Dumper-7
Dumper-7 is a C++ DLL that, when injected into an Unreal Engine game, generates a full C++ SDK (headers for engine classes, functions, and …
962211active
GlasgowEmbedded/glasgow
Glasgow Interface Explorer is an open-source software stack (Python-based) for the Glasgow open hardware tool, an FPGA-based USB interface …
772202active
TheMythologist/GenP
GenP is an open-source AutoIt patcher that applies binary hex patches to Adobe Creative Cloud applications on Windows to modify their licen…
782196active
ReClassNET/ReClass.NET
ReClass.NET is a .NET-based memory inspection and class structure reconstruction tool for analyzing remote processes, a modernized port of …
232187active
Ylarod/Florida
Florida is an automatically patched, anti-detection build of frida-server for Android, tracking the upstream FRIDA project. It rebuilds fri…
892175active
jar-analyzer/jar-analyzer
A free, open-source GUI tool for analyzing Java JAR files, offering method call relationship search, DFS call chain analysis, taint analysi…
942158active
sashs/Ropper
Ropper is a Python CLI tool that displays information about binary files (ELF, PE, Mach-O, RAW) and finds ROP/JOP gadgets to build exploit …
772144active
0xsdeo/AntiDebug_Breaker
A Chrome browser extension built on the Hook_JS library that assists with JavaScript reverse engineering and penetration testing reconnaiss…
762122active
tyilo/insert_dylib
A command line utility written in C that inserts a dylib load command (LC_LOAD_DYLIB or LC_LOAD_WEAK_DYLIB) into Mach-O binaries, including…
382092active
redballoonsecurity/ofrak
OFRAK is a binary analysis and modification platform that identifies, unpacks, analyzes, modifies, and repacks binaries, with first-class s…
672067active
lasting-yang/frida_dump
A collection of Frida scripts for dumping DEX files and native shared libraries (.so) from running Android processes. It includes SoFixer-b…
492067active
erocarrera/pefile
pefile is a multi-platform Python module for parsing and working with Portable Executable (PE) files such as EXE and DLL binaries. It expos…
672064stable
CYB3RMX/Qu1cksc0pe
Qu1cksc0pe is an all-in-one malware analysis tool that statically and dynamically analyzes many file types, including Windows/Linux/macOS e…
772049active
mandiant/speakeasy
Speakeasy is a Windows user-mode and kernel-mode emulation framework that runs binaries, drivers, and shellcode inside a modeled Windows ru…
912036active
aixed/WeChat-Hook
A Windows x64 DLL (loaded as a version.dll proxy into WeChat PC) that hooks WeChat 3.9.10.16 / 4.1.10.27 and exposes a local HTTP API for s…
962033active
ainfosec/FISSURE
FISSURE is an open-source RF and reverse engineering framework built around software-defined radios, supporting signal detection, classific…
762033active
UnderminersTeam/UndertaleModTool
A GUI and CLI tool for modding, decompiling, and unpacking Undertale, Deltarune, and other GameMaker Studio games. It provides editors for …
952012active
endrazine/wcc
The Witchcraft Compiler Collection (WCC) is a set of compilation tools for performing binary manipulation on ELF executables across POSIX p…
902010active
dqzg12300/fridaUiTools
fridaUiTools is a PyQt5 desktop workbench that wraps Frida into a unified GUI for attaching to processes, managing hook script templates, v…
862010active
EgeBalci/sgn
SGN is a polymorphic binary encoder that encodes shellcode using an additive feedback loop similar to an LFSR, producing statically undetec…
912003active
google/android-classyshark
ClassyShark is a standalone binary inspection tool for Android developers that browses Android executables and shows class interfaces, memb…
107558maintenance
vmoranv/jshookmcp
An MCP server exposing 600+ tools across 34 domains for JavaScript reverse engineering and security research, including browser automation,…
591954active
de4dot/de4dot
de4dot is an open-source .NET deobfuscator and unpacker written in C# that restores packed and obfuscated .NET assemblies to near-original …
107437maintenance
IDA-NO-MCP
A collection of reverse engineering skills (prompt/plugin packages) for AI coding assistants like Claude Code, designed to work with IDA-NO…
581946active
axi0mX/ipwndfu
ipwndfu is an open-source Python tool that exploits iOS device bootroms, most notably via the checkm8 exploit, to put devices into pwned DF…
327397maintenance
vxunderground/VX-API
VX-API is a C++ collection of functions implementing malicious functionality to aid in malware development, maintained by vx-underground. I…
321938active
JustasMasiulis/lazy_importer
A header-only C++ library for resolving Windows DLL exports at runtime in a way that hides imports from static analysis tools. It uses comp…
321920stable
KasperskyLab/hrtng
An IDA Pro plugin (C++) providing a rich toolkit for reverse engineering: string/data decryption, deobfuscation of Hex-Rays pseudocode, unf…
871916active
stevemk14ebr/PolyHook_2_0
PolyHook 2.0 is a C++20 library for hooking functions at runtime on x86 and x64 architectures. It supports multiple hooking techniques (inl…
731890active
federicodotta/Brida
Brida is a Burp Suite extension that bridges Burp Suite and Frida, letting testers invoke and manipulate an application's own methods while…
491889active
DerekSelander/LLDB
A collection of LLDB aliases, regexes, and Python scripts that extend Apple's LLDB debugger with commands for heap searching, class dumping…
471883active
airbus-seclab/bincat
BinCAT is a static binary code analysis toolkit that performs value analysis, taint analysis, type reconstruction, and use-after-free/doubl…
291872active
chame1eon/jnitrace
jnitrace is a Frida-based command-line tool that dynamically traces JNI API calls made by native libraries in Android apps. It works like f…
231859stable
DosX-dev/obfus.h
A macro-only C header library that obfuscates code at compile time, designed for the Tiny C Compiler on Windows x86/x64. It provides contro…
681836active
HoShiMin/Kernel-Bridge
Kernel-Bridge is a C++20 Windows kernel driver template, development framework, and kernel-mode API with wrappers, including a hypervisor s…
231822active
QBDI/QBDI
QBDI (QuarkslaB Dynamic binary Instrumentation) is a modular, cross-platform, cross-architecture DBI framework built on LLVM, supporting x8…
831815active
AloneMonkey/MonkeyDev
MonkeyDev is an Xcode-integrated framework (an upgraded fork of iOSOpenDev) for developing iOS tweaks and command-line tools using CaptainH…
326799maintenance
lifting-bits/remill
Remill is a C++ library that statically translates machine code instructions (x86, amd64, AArch64, SPARC32/64) into LLVM bitcode. It is des…
801808active
marin-m/vmlinux-to-elf
A Python CLI (with optional GUI) that recovers a fully analyzable ELF file from raw or stripped Linux kernel images (vmlinux, vmlinuz, bzIm…
881805stable
redasm-dev/redasm
REDasm is an open-source disassembler and binary analysis tool with a native Qt6 GUI, supporting many CPU architectures and executable form…
941801active
0vercl0k/wtf
wtf (what the fuzz) is a distributed, code-coverage guided, snapshot-based fuzzer for attacking user- and kernel-mode targets on Windows an…
741793active

← prev page 2 / 6 next →