domain: reverse-engineering
558 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| JusticeRage/Gepetto Gepetto is an IDA Pro plugin that queries large language models (OpenAI, Anthropic, Gemini, Ollama, and others) to explain decompiled funct… | 79 | 3461 | active |
| kevoreilly/CAPEv2 CAPEv2 is a malware sandbox derived from Cuckoo that executes malicious files in isolated environments while instrumenting their behavior a… | 77 | 3451 | active |
| pret/pokeemerald A complete decompilation of Pokémon Emerald into C source code that rebuilds the exact original Game Boy Advance ROM. It serves as a base f… | 77 | 3406 | active |
| jehna/humanify A Rust CLI tool that unminifies and deobfuscates JavaScript by using LLMs (OpenAI, Anthropic, Gemini, OpenRouter, or local Ollama) to sugge… | 92 | 3272 | active |
| SteamAutoCracks/Steam-auto-crack A C# tool that automatically cracks Steam games by unpacking SteamStub-protected executables and applying the Goldberg Steam emulator. It a… | 99 | 3243 | active |
| malmeloo/FindMy.py FindMy.py is a Python library for querying Apple's Find My network to fetch and decrypt the location of AirTags, Apple devices, and custom … | 88 | 3223 | active |
| LaurieWired/Malimite Malimite is a Java-based decompiler for iOS and macOS binaries, built on Ghidra, that analyzes IPA files and Application Bundles with direc… | 38 | 3174 | active |
| pxb1988/dex2jar dex2jar is a set of Java-based command-line tools for working with Android .dex and Java .class files. It converts Dalvik executables (e.g.… | 23 | 13135 | maintenance |
| QiuChenly/CoreInject CoreInject (successor to InjectLib) is a macOS application injection and binary-patching tool by QiuChenly, distributed alongside a communi… | 84 | 3157 | active |
| BinDiff BinDiff is an open-source comparison tool for binary files that finds differences and similarities in disassembled code using graph-theoret… | 62 | 3155 | active |
| ttttupup/wxhelper wxhelper is a C++ DLL that hooks the Windows PC WeChat client, exposing its internal functions through a local HTTP server (default port 19… | 61 | 3141 | active |
| biggerstar/wedecode Wedecode is a fully automated tool that decompiles WeChat mini-program and mini-game wxapkg packages back into readable source code (JS, WX… | 60 | 3091 | active |
| m0bilesecurity/RMS-Runtime-Mobile-Security Runtime Mobile Security (RMS) is a NodeJS-powered web interface built on FRIDA for manipulating Android and iOS apps at runtime. It lets us… | 83 | 3075 | active |
| korcankaraokcu/PINCE PINCE is a GDB front-end and reverse engineering tool for Linux, focused on game hacking but usable for general reverse engineering. It pro… | 98 | 3069 | active |
| cilame/v_jstools v_jstools is a Chrome extension (Manifest V3) for debugging and reverse-engineering JavaScript on web pages. It provides API hooking, code … | 58 | 3015 | active |
| eteran/edb-debugger edb is a cross-platform AArch32/x86/x86-64 debugger inspired by OllyDbg, built with Qt and Capstone. It provides a graphical interface for … | 66 | 2952 | active |
| RfidResearchGroup/ChameleonUltra ChameleonUltra is the open-source firmware for an RFID/NFC card emulation device based on the NRF52840, capable of reading, writing, decryp… | 84 | 2949 | active |
| gildor2/UEViewer UE Viewer (umodel) is a desktop application for viewing and exporting visual resources (meshes, animations, textures, sounds) from games bu… | 23 | 2917 | active |
| j4k0xb/webcrack webcrack is a JavaScript reverse-engineering tool that deobfuscates code obfuscated with obfuscator.io, unminifies minified code, and unpac… | 78 | 2876 | active |
| gdbinit/MachOView A macOS GUI application for viewing and exploring Mach-O binary files, revived as a maintained fork with a universal x86_64/arm64 build. It… | 32 | 2868 | active |
| mrexodia/TitanHide TitanHide is a Windows kernel driver that hides debuggers from selected processes by hooking Nt* kernel functions via SSDT hooks and alteri… | 72 | 2840 | active |
| hasherezade/pe_to_shellcode A C++ command-line tool that converts Windows PE executables into shellcode-compatible form, adding a reflective loading stub post-compilat… | 40 | 2793 | active |
| panda-re/panda PANDA is an open-source Platform for Architecture-Neutral Dynamic Analysis built on the QEMU whole-system emulator, supporting record and r… | 93 | 2778 | active |
| Impact-I/reFlutter reFlutter is a Python CLI framework for reverse engineering Flutter mobile apps by repacking APK/IPA files with a specially patched, precom… | 95 | 2738 | active |
| AxtMueller/Windows-Kernel-Explorer Windows Kernel Explorer (WKE) is a free Windows kernel research and inspection tool supporting Windows XP through Windows 11. It loads a ke… | 58 | 2717 | active |
| zinja-coder/jadx-ai-mcp A JADX plugin that bundles an MCP server, allowing LLM clients like Claude to interact with the JADX decompiler for Android APK analysis. I… | 84 | 2711 | active |
| Artikash/Textractor Textractor is an open-source x86/x64 text hooker for Windows that extracts text from video games and visual novels by injecting into text o… | 23 | 2680 | active |
| decompiler-explorer/decompiler-explorer A web service (like Compiler Explorer in reverse) that lets users upload small binaries and compare the decompiled C-like output from many … | 77 | 2639 | active |
| REhints/HexRaysCodeXplorer HexRaysCodeXplorer is a Hex-Rays Decompiler plugin written in C++ that improves code navigation during reverse engineering. It automates re… | 47 | 2637 | active |
| worawit/blutter Blutter is a reverse engineering tool for Flutter mobile applications that compiles the Dart AOT runtime to extract symbols and objects fro… | 72 | 2627 | active |
| Keystone Assembler Engine Keystone is a lightweight multi-platform, multi-architecture assembler framework implemented in C/C++ with bindings for many languages. It … | 65 | 2625 | active |
| zhizhuodemao/js-reverse-mcp An MCP server that gives AI coding agents (Claude, Cursor, Copilot) tools for JavaScript reverse engineering in a headed Chrome browser, in… | 83 | 2608 | active |
| uxmal/reko Reko is a general-purpose binary decompiler that translates machine code executables back into high-level language source. It supports mult… | 89 | 2600 | active |
| gaasedelen/lighthouse Lighthouse is a code coverage explorer plugin for IDA Pro and Binary Ninja that lets reverse engineers interactively visualize execution co… | 53 | 2577 | stable |
| rednaga/APKiD APKiD is a command-line tool that identifies how an Android APK was built, detecting compilers, packers, obfuscators, and app-shielding/RAS… | 78 | 2565 | active |
| bkerler/edl A Python CLI tool for communicating with Qualcomm devices in EDL (Emergency Download) mode via the Sahara, Firehose, Streaming, and Diag pr… | 66 | 2547 | active |
| onekey-sec/unblob unblob is an extraction suite that parses unknown binary blobs for 78+ archive, compression, and file-system formats, recursively extractin… | 91 | 2544 | active |
| evi0s/WMPFDebugger A debugger tweak for WeChat's Mini-Program Framework (WMPF) that exploits the remote debug feature of WeChat devtools to enable full Chrome… | 65 | 2542 | active |
| DidierStevens/DidierStevensSuite A bundled collection of Didier Stevens' security research tools, distributed as a ZIP and GitHub repository of Python scripts and utilities… | 75 | 2525 | active |
| bug-bit/fckvip An Android module (likely Magisk/LSPosed-based) that unlocks paid VIP memberships and enhances extended features in certain apps. It requir… | 74 | 2500 | active |
| solemnwarning/rehex Rehex is a cross-platform hex editor designed for reverse engineering binary files, with features like large file support, inline disassemb… | 85 | 2476 | active |
| VirusTotal/yara YARA is a pattern matching tool used to identify and classify malware families and other files based on textual or binary pattern rules. It… | 94 | 9831 | maintenance |
| mandiant/flare-ida A collection of IDA Pro plugins and IDAPython scripts from Mandiant's FLARE team for reverse engineering and malware analysis. It includes … | 10 | 2453 | active |
| Yuyz0112/claude-code-reverse A tool that reverse engineers Claude Code by capturing and visualizing its LLM API interactions. It monkey-patches Claude Code's request co… | 37 | 2428 | active |
| msojocs/fiddler-everywhere-enhance An auto-patch tool that modifies the Fiddler Everywhere web debugging proxy (an Electron app) on Windows and Linux, replacing DLLs and patc… | 88 | 2403 | active |
| bootleg/ret-sync ret-sync is a set of plugins that synchronize a debugging session (WinDbg, GDB, LLDB, OllyDbg, x64dbg) with disassemblers (IDA, Ghidra, Bin… | 53 | 2378 | active |
| jxhczhl/JsRpc JsRpc is a Go-based RPC server that lets you remotely invoke JavaScript methods running in a browser via WebSocket, avoiding the need to ex… | 84 | 2347 | active |
| hzqst/VmwareHardenedLoader A Windows kernel driver that mitigates VMware VM detection by filtering VMware-related firmware strings and blocking VMware PnP registry en… | 87 | 2334 | active |
| Vineflower/vineflower Vineflower is a modern Java and JVM bytecode decompiler forked from Fernflower, focused on producing accurate, readable output with support… | 84 | 2327 | active |
| UMSKT/UMSKT UMSKT (Universal MS Key Toolkit) is an open-source C++ CLI toolkit for researching and experimenting with Microsoft's pre-Vista (pre-2012) … | 78 | 2318 | active |
| REAndroid/APKEditor APKEditor is a Java command-line tool for editing Android APK resources without depending on aapt/aapt2. It can decode binary resources to … | 89 | 2291 | active |
| bitcookies/winrar-keygen An open-source tool and educational write-up explaining the principle behind WinRAR's 'rarreg.key' license file generation, with implementa… | 96 | 2277 | active |
| a2x/cs2-dumper An external offset/interface dumper for Counter-Strike 2 that reads the game process memory via memflow and generates offset files in forma… | 72 | 2275 | active |
| BinaryAnalysisPlatform/bap CMU Binary Analysis Platform (BAP) is a suite of OCaml libraries and a plugin-extensible CLI tool for analyzing binary programs. It lifts b… | 59 | 2253 | active |
| Storyyeller/Krakatau Krakatau is a Rust-based CLI tool for assembling, disassembling, and decompiling Java bytecode. It is specifically designed to handle obfus… | 66 | 2244 | active |
| DanOps-1/Gpt-Agreement-Payment A Python toolkit that reverse-engineers and replays the end-to-end ChatGPT Plus/Team/Pro subscription payment flow (Stripe Checkout, PayPal… | 53 | 2225 | active |
| grimdoomer/Xbox360BadUpdate A non-persistent, software-only hypervisor exploit for the Xbox 360 that runs unsigned code on the latest dashboard (17559) using a support… | 10 | 2221 | active |
| eeeeeeeeee-code/e0e1-wx A Windows GUI tool (PySide6, Python 3.10+) for analyzing and penetration-testing WeChat mini-programs locally. It automates mini-program pa… | 80 | 2214 | active |
| avast/retdec RetDec is a retargetable machine-code decompiler based on LLVM that converts native binaries back into readable C or Python-like source cod… | 61 | 8612 | maintenance |
| Encryqed/Dumper-7 Dumper-7 is a C++ DLL that, when injected into an Unreal Engine game, generates a full C++ SDK (headers for engine classes, functions, and … | 96 | 2211 | active |
| GlasgowEmbedded/glasgow Glasgow Interface Explorer is an open-source software stack (Python-based) for the Glasgow open hardware tool, an FPGA-based USB interface … | 77 | 2202 | active |
| TheMythologist/GenP GenP is an open-source AutoIt patcher that applies binary hex patches to Adobe Creative Cloud applications on Windows to modify their licen… | 78 | 2196 | active |
| ReClassNET/ReClass.NET ReClass.NET is a .NET-based memory inspection and class structure reconstruction tool for analyzing remote processes, a modernized port of … | 23 | 2187 | active |
| Ylarod/Florida Florida is an automatically patched, anti-detection build of frida-server for Android, tracking the upstream FRIDA project. It rebuilds fri… | 89 | 2175 | active |
| jar-analyzer/jar-analyzer A free, open-source GUI tool for analyzing Java JAR files, offering method call relationship search, DFS call chain analysis, taint analysi… | 94 | 2158 | active |
| sashs/Ropper Ropper is a Python CLI tool that displays information about binary files (ELF, PE, Mach-O, RAW) and finds ROP/JOP gadgets to build exploit … | 77 | 2144 | active |
| 0xsdeo/AntiDebug_Breaker A Chrome browser extension built on the Hook_JS library that assists with JavaScript reverse engineering and penetration testing reconnaiss… | 76 | 2122 | active |
| tyilo/insert_dylib A command line utility written in C that inserts a dylib load command (LC_LOAD_DYLIB or LC_LOAD_WEAK_DYLIB) into Mach-O binaries, including… | 38 | 2092 | active |
| redballoonsecurity/ofrak OFRAK is a binary analysis and modification platform that identifies, unpacks, analyzes, modifies, and repacks binaries, with first-class s… | 67 | 2067 | active |
| lasting-yang/frida_dump A collection of Frida scripts for dumping DEX files and native shared libraries (.so) from running Android processes. It includes SoFixer-b… | 49 | 2067 | active |
| erocarrera/pefile pefile is a multi-platform Python module for parsing and working with Portable Executable (PE) files such as EXE and DLL binaries. It expos… | 67 | 2064 | stable |
| CYB3RMX/Qu1cksc0pe Qu1cksc0pe is an all-in-one malware analysis tool that statically and dynamically analyzes many file types, including Windows/Linux/macOS e… | 77 | 2049 | active |
| mandiant/speakeasy Speakeasy is a Windows user-mode and kernel-mode emulation framework that runs binaries, drivers, and shellcode inside a modeled Windows ru… | 91 | 2036 | active |
| aixed/WeChat-Hook A Windows x64 DLL (loaded as a version.dll proxy into WeChat PC) that hooks WeChat 3.9.10.16 / 4.1.10.27 and exposes a local HTTP API for s… | 96 | 2033 | active |
| ainfosec/FISSURE FISSURE is an open-source RF and reverse engineering framework built around software-defined radios, supporting signal detection, classific… | 76 | 2033 | active |
| UnderminersTeam/UndertaleModTool A GUI and CLI tool for modding, decompiling, and unpacking Undertale, Deltarune, and other GameMaker Studio games. It provides editors for … | 95 | 2012 | active |
| endrazine/wcc The Witchcraft Compiler Collection (WCC) is a set of compilation tools for performing binary manipulation on ELF executables across POSIX p… | 90 | 2010 | active |
| dqzg12300/fridaUiTools fridaUiTools is a PyQt5 desktop workbench that wraps Frida into a unified GUI for attaching to processes, managing hook script templates, v… | 86 | 2010 | active |
| EgeBalci/sgn SGN is a polymorphic binary encoder that encodes shellcode using an additive feedback loop similar to an LFSR, producing statically undetec… | 91 | 2003 | active |
| google/android-classyshark ClassyShark is a standalone binary inspection tool for Android developers that browses Android executables and shows class interfaces, memb… | 10 | 7558 | maintenance |
| vmoranv/jshookmcp An MCP server exposing 600+ tools across 34 domains for JavaScript reverse engineering and security research, including browser automation,… | 59 | 1954 | active |
| de4dot/de4dot de4dot is an open-source .NET deobfuscator and unpacker written in C# that restores packed and obfuscated .NET assemblies to near-original … | 10 | 7437 | maintenance |
| IDA-NO-MCP A collection of reverse engineering skills (prompt/plugin packages) for AI coding assistants like Claude Code, designed to work with IDA-NO… | 58 | 1946 | active |
| axi0mX/ipwndfu ipwndfu is an open-source Python tool that exploits iOS device bootroms, most notably via the checkm8 exploit, to put devices into pwned DF… | 32 | 7397 | maintenance |
| vxunderground/VX-API VX-API is a C++ collection of functions implementing malicious functionality to aid in malware development, maintained by vx-underground. I… | 32 | 1938 | active |
| JustasMasiulis/lazy_importer A header-only C++ library for resolving Windows DLL exports at runtime in a way that hides imports from static analysis tools. It uses comp… | 32 | 1920 | stable |
| KasperskyLab/hrtng An IDA Pro plugin (C++) providing a rich toolkit for reverse engineering: string/data decryption, deobfuscation of Hex-Rays pseudocode, unf… | 87 | 1916 | active |
| stevemk14ebr/PolyHook_2_0 PolyHook 2.0 is a C++20 library for hooking functions at runtime on x86 and x64 architectures. It supports multiple hooking techniques (inl… | 73 | 1890 | active |
| federicodotta/Brida Brida is a Burp Suite extension that bridges Burp Suite and Frida, letting testers invoke and manipulate an application's own methods while… | 49 | 1889 | active |
| DerekSelander/LLDB A collection of LLDB aliases, regexes, and Python scripts that extend Apple's LLDB debugger with commands for heap searching, class dumping… | 47 | 1883 | active |
| airbus-seclab/bincat BinCAT is a static binary code analysis toolkit that performs value analysis, taint analysis, type reconstruction, and use-after-free/doubl… | 29 | 1872 | active |
| chame1eon/jnitrace jnitrace is a Frida-based command-line tool that dynamically traces JNI API calls made by native libraries in Android apps. It works like f… | 23 | 1859 | stable |
| DosX-dev/obfus.h A macro-only C header library that obfuscates code at compile time, designed for the Tiny C Compiler on Windows x86/x64. It provides contro… | 68 | 1836 | active |
| HoShiMin/Kernel-Bridge Kernel-Bridge is a C++20 Windows kernel driver template, development framework, and kernel-mode API with wrappers, including a hypervisor s… | 23 | 1822 | active |
| QBDI/QBDI QBDI (QuarkslaB Dynamic binary Instrumentation) is a modular, cross-platform, cross-architecture DBI framework built on LLVM, supporting x8… | 83 | 1815 | active |
| AloneMonkey/MonkeyDev MonkeyDev is an Xcode-integrated framework (an upgraded fork of iOSOpenDev) for developing iOS tweaks and command-line tools using CaptainH… | 32 | 6799 | maintenance |
| lifting-bits/remill Remill is a C++ library that statically translates machine code instructions (x86, amd64, AArch64, SPARC32/64) into LLVM bitcode. It is des… | 80 | 1808 | active |
| marin-m/vmlinux-to-elf A Python CLI (with optional GUI) that recovers a fully analyzable ELF file from raw or stripped Linux kernel images (vmlinux, vmlinuz, bzIm… | 88 | 1805 | stable |
| redasm-dev/redasm REDasm is an open-source disassembler and binary analysis tool with a native Qt6 GUI, supporting many CPU architectures and executable form… | 94 | 1801 | active |
| 0vercl0k/wtf wtf (what the fuzz) is a distributed, code-coverage guided, snapshot-based fuzzer for attacking user- and kernel-mode targets on Windows an… | 74 | 1793 | active |