domain: reverse-engineering
558 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| ma1co/OpenMemories-Tweak An Android app that runs on Sony cameras supporting PlayMemories Camera Apps to unlock hidden settings such as the 30-minute video recordin… | 23 | 1390 | maintenance |
| grayhatacademy/ida A collection of IDA Python plugins, scripts, and modules for the IDA Pro disassembler. It provides reusable tooling for binary analysis and… | 32 | 1368 | maintenance |
| GoSSIP-SJTU/Armariris Armariris is an LLVM-based code obfuscation framework maintained by Shanghai Jiao Tong University's cryptography and computer security lab.… | 32 | 1348 | maintenance |
| gdabah/distorm diStorm3 is a lightweight, fast disassembler library for x86/AMD64 machine code, licensed under BSD. It acts as a decomposer, returning bin… | 23 | 1345 | maintenance |
| wbenny/hvpp hvpp is a lightweight Intel VT-x hypervisor written in modern C++ that virtualizes an already-running operating system, primarily targeting… | 32 | 1344 | maintenance |
| Cherrison/CrackMinApp A Windows GUI tool (built with C# and Node.js) that one-click decompiles WeChat mini-program .wxapkg packages back into readable source cod… | 32 | 1344 | maintenance |
| blackberry/pe_tree PE Tree is a Python module and standalone GUI application for viewing Portable Executable (PE) files in a tree-view, built on pefile and Py… | 10 | 1343 | maintenance |
| tobefuturer/restore-symbol A command-line reverse engineering tool that restores stripped Objective-C symbol tables in iOS Mach-O binaries. It injects OC method and b… | 32 | 1337 | maintenance |
| Cur10s1tyByt3/GenP An archival repository preserving the source materials and documentation of GenP, an AutoIt-based patcher tool targeting Adobe software on … | 57 | 1327 | maintenance |
| RUB-SysSec/DroneSecurity A proof-of-concept receiver and decoder for DJI's Drone-ID protocol broadcast over OcuSync 2.0, developed for an NDSS 2023 paper. It decode… | 31 | 1309 | maintenance |
| wbenny/injdrv A proof-of-concept Windows kernel driver that injects DLLs into user-mode processes using Asynchronous Procedure Calls (APC). It hooks into… | 32 | 1296 | maintenance |
| alexzielenski/optool A command line tool for modifying Mach-O binaries on macOS and iOS. It can insert or remove load commands, strip or repair code signatures,… | 23 | 1287 | maintenance |
| rocky/python-decompile3 decompyle3 is a native Python decompiler that translates Python bytecode (versions 3.7 and 3.8) back into equivalent Python source code. It… | 68 | 1269 | maintenance |
| darkr4y/geacon Geacon is a Go implementation of CobaltStrike's Beacon implant, built to study the C2 protocol through reverse engineering. It supports com… | 32 | 1266 | maintenance |
| 0xjiayu/go_parser An IDA Pro plugin written in Python that parses Golang binaries, recovering function names, source file paths, strings, types, and interfac… | 23 | 1255 | maintenance |
| codilime/veles Veles is a cross-platform desktop tool for binary data analysis that uses statistical visualizations to reveal patterns in large binary fil… | 10 | 1239 | maintenance |
| DerekSelander/dsdump dsdump is a command-line tool that inspects Mach-O binaries, dumping symbol tables plus Objective-C classes and Swift type descriptors, act… | 10 | 1226 | maintenance |
| softScheck/tplink-smartplug A Python command-line client for the proprietary TP-Link Smart Home protocol that controls HS100, HS110, and KP115 WiFi smart plugs over TC… | 32 | 1200 | maintenance |
| SciresM/hactool hactool is a C command-line tool for inspecting, decrypting, and extracting common Nintendo Switch file formats such as NCA, XCI, PFS0, Rom… | 23 | 1179 | maintenance |
| strazzere/android-unpacker A collection of Android unpacking tools presented at Defcon 22, including gdb-based scripts and a native unpacker for packers like APKProte… | 23 | 1178 | maintenance |
| siyujie/OkHttpLogger-Frida A Frida script that hooks OkHttp's RealCall class in Android apps to intercept and log HTTP requests and responses, including headers and b… | 32 | 1166 | maintenance |
| sh4hin/Androl4b AndroL4b is an Ubuntu MATE-based virtual machine preloaded with Android security, reverse engineering, and malware analysis tools such as R… | 32 | 1166 | maintenance |
| ghidraninja/ghidra_scripts A collection of scripts for the Ghidra software reverse engineering suite, adding features like crypto constant detection via YARA, binwalk… | 32 | 1165 | maintenance |
| crypto2011/IDR IDR (Interactive Delphi Reconstructor) is a Windows decompiler for EXE and DLL files compiled with Delphi 2 through Delphi XE4. It performs… | 23 | 1154 | maintenance |
| Sentinel-One/CobaltStrikeParser A Python parser that extracts Cobalt Strike Beacon configuration from stageless PE files, memory dumps, or C2 URLs. It heuristically finds … | 10 | 1138 | maintenance |
| anestisb/vdexExtractor A command-line tool written in C that decompiles and extracts Android Dex bytecode from Vdex files produced by the ART runtime's dex2oat co… | 32 | 1135 | maintenance |
| mildsunrise/protobuf-inspector A Python CLI tool that parses Google Protobuf encoded blobs (wire format 2 or 3) without knowing their schema definition, printing a colore… | 32 | 1125 | maintenance |
| kevthehermit/RATDecoders A Python library and CLI tool (malconf) that statically analyzes malware samples from common Remote Access Trojan (RAT) families and extrac… | 32 | 1120 | maintenance |
| CTCaer/jc_toolkit A Windows desktop application for managing, inspecting, and customizing Nintendo Switch Joy-Con controllers over Bluetooth HID. It provides… | 23 | 1101 | maintenance |
| sibears/IDAGolangHelper A set of IDA Pro Python scripts that parse Go type information embedded in compiled Go binaries and register the recovered types inside IDA… | 32 | 1092 | maintenance |
| mmozeiko/aes-finder A small C++ command-line utility that scans the memory of running processes to locate AES encryption and decryption keys (128, 192, and 256… | 32 | 1083 | maintenance |
| xdmjun/mp-unpack A tool for unpacking WeChat mini-program packages (wxapkg files) to recover readable source code. It appears to be a reverse-engineering ut… | 32 | 1079 | maintenance |
| silverf0x/RpcView RpcView is a free, open-source Windows GUI tool for exploring and decompiling Microsoft RPC (Remote Procedure Call) interfaces present on a… | 23 | 1070 | maintenance |
| sickcodes/Docker-eyeOS A Docker container that boots the iPhone's iOS xnu kernel (arm64) under QEMU with KVM acceleration, exposing SSH and GDB ports for kernel d… | 32 | 1061 | maintenance |
| DavidBuchanan314/ambiguous-png-packer A Python tool that crafts PNG files rendering differently in Apple software versus other viewers, exploiting a parsing ambiguity in Apple's… | 32 | 1059 | maintenance |
| wwh1004/ExtremeDumper A Windows GUI tool for dumping .NET assemblies from running processes, including bypassing anti-dump protections. It can also inject .NET a… | 23 | 1054 | maintenance |
| btbd/access A Windows kernel driver plus DLL wrapper that lets a usermode process perform privileged operations on protected processes without creating… | 32 | 1053 | maintenance |
| itenfay/WeChat_tweak An iOS tweak (plugin) for WeChat written in Objective-C that adds features like auto-grabbing red envelopes, blocking messages, preventing … | 70 | 1052 | maintenance |
| sonyxperiadev/ApkAnalyser ApkAnalyser is a stand-alone Java (J2SE) GUI tool for static and virtual analysis of Android APK files. It supports disassembling and modif… | 10 | 1047 | maintenance |
| fangshufeng/MachOView MachOView is a macOS GUI application for browsing and analyzing Mach-O binary files, a maintained fork of the original gdbinit/MachOView th… | 23 | 1046 | maintenance |
| KULeuven-COSIC/Starlink-FI A research project from KU Leuven COSIC providing the design of a custom modchip that performs voltage fault injection to bypass signature … | 32 | 1044 | maintenance |
| thomasxm/BOAZ_beta BOAZ is a multilayered AV/EDR evasion framework written in C++/C with Python linking, designed to generate polymorphic payloads that bypass… | 57 | 1042 | maintenance |
| 9176324/Shark Shark is a Windows kernel driver project written in C that disables Kernel Patch Protection (PatchGuard) in real time on Windows 7 (7600) a… | 23 | 1042 | maintenance |
| x0tools/WeChatOpenDevTools A Windows tool that patches WeChat to enable the built-in DevTools (F12) for debugging WeChat Official Accounts and Mini Programs. It suppo… | 27 | 1041 | maintenance |
| anhkgg/SuperDllHijack SuperDllHijack is a C++ library implementing a general DLL hijacking technique for Windows that forwards calls to the original DLL without … | 32 | 1035 | maintenance |
| d35ha/CallObfuscator CallObfuscator is a C++ library and CLI tool that hides Windows PE imports by rewriting the Import Address Table so sensitive APIs appear a… | 23 | 1024 | maintenance |
| F8LEFT/SoFixer SoFixer is a command-line tool that repairs ELF shared object (.so) files dumped from process memory, fixing section headers, program heade… | 10 | 1024 | maintenance |
| rwfpl/rewolf-wow64ext A C++ helper library enabling 32-bit (x86) applications running under the WOW64 layer on 64-bit Windows to interact with native x64 process… | 23 | 1015 | maintenance |
| Inori/FuckGalEngine A collection of C tools for unpacking, repacking, and hooking visual novel (galgame) engines to enable fan translation and modifications. I… | 32 | 1013 | maintenance |
| WithSecureLabs/python-exe-unpacker A Python CLI script that unpacks and decompiles Windows EXEs compiled from Python code, supporting executables built with py2exe and PyInst… | 32 | 1013 | maintenance |
| JJTech0130/pypush A Python library for interacting with Apple's private APIs, originally a proof-of-concept iMessage reverse-engineering project. It currentl… | 65 | 3768 | experimental |
| ran-j/PS2Recomp A PlayStation 2 static recompiler that translates PS2 ELF binaries (MIPS R5900 instructions) into C++ code, plus a runtime to execute the g… | 72 | 3200 | experimental |
| b-nnett/grok-bot-0.18-reconstructed An unofficial, source-oriented reconstruction of the Grok Bot 0.18.0 macOS Electron app, with readable TypeScript implementations of its ru… | 57 | 2974 | experimental |
| SamboyCoding/Cpp2IL Cpp2IL is a work-in-progress tool that reverses Unity's IL2CPP build process, recovering managed DLLs from IL2CPP-compiled games. It parses… | 78 | 2597 | experimental |
| can1357/NoVmp NoVmp is a static devirtualizer that translates VMProtect x64 3.x-virtualized binaries into optimized VTIL intermediate code, optionally re… | 23 | 2185 | experimental |
| JSREI/ast-hook-for-js-RE A browser memory roaming tool for JavaScript reverse engineering that hooks variable assignments via AST-transformed proxy responses. It le… | 23 | 1912 | experimental |
| rexdex/recompiler A C++ tool that converts Xbox 360 PowerPC executables into native Windows x86 executables, handling CPU translation, endianness, and GPU em… | 32 | 1740 | experimental |
| zeldaret/mm A work-in-progress from-scratch decompilation of The Legend of Zelda: Majora's Mask (N64 US 1.0), recreating readable C source code that bu… | 77 | 1710 | experimental |
| vtil-project/VTIL-Core VTIL-Core is the core library of the Virtual-machine Translation Intermediate Language project, an optimizing compiler infrastructure built… | 75 | 1581 | experimental |
| JonathanSalwan/VMProtect-devirtualization An experimental research project demonstrating a dynamic approach to devirtualize pure functions protected by VMProtect 3.x using symbolic … | 32 | 1494 | experimental |
| whitequark/unfork unfork(2) is a proof-of-concept Linux technique and library that joins two process address spaces into one, the inverse of fork(2), by comb… | 32 | 1488 | experimental |
| alephsecurity/xnu-qemu-arm64 A fork of QEMU that emulates an iPhone (iPhone 6s Plus) well enough to boot a fully functional iOS 12.1 system, including launchd, bash, SS… | 32 | 1460 | experimental |
| iPower/KasperskyHook A Windows research project that hooks system calls by loading Kaspersky's hypervisor driver (klhk.sys) and a custom kernel driver that subv… | 66 | 1314 | experimental |
| xodus-gaming/xodus Xodus is a Rust project aiming to bring XBOX PC (Game Pass) games to Linux and possibly macOS by implementing XBOX authentication, MSIXVC p… | 61 | 1270 | experimental |
| xoreos/xoreos xoreos is an open-source (GPLv3+) reimplementation of BioWare's Aurora engine and its derivatives, targeting games from Neverwinter Nights … | 68 | 1168 | experimental |
| JuliaPoo/Artfuscator Artfuscator is a novelty C compiler built on ELVM that compiles C programs into a binary whose entire control flow graph renders as a chose… | 32 | 1102 | experimental |
| medusalix/FreeMDU FreeMDU is an open hardware and software project for communicating with Miele appliances through their proprietary optical infrared diagnos… | 60 | 1060 | experimental |
| CodeTips/BaiduNetdiskPlugin-macOS A macOS plugin that patches the Baidu Netdisk client binary via dylib injection to fake SVIP status and remove local download speed limits.… | 10 | 8873 | abandoned |
| acheong08/EdgeGPT A Python library that reverse engineers Microsoft's Bing Chat (EdgeGPT) API, providing unofficial programmatic access to Bing AI conversati… | 10 | 7851 | abandoned |
| cuckoosandbox/cuckoo Cuckoo Sandbox is an open-source automated dynamic malware analysis system that executes suspicious files in an isolated environment and re… | 10 | 5964 | abandoned |
| qwerty472123/wxappUnpacker wxappUnpacker is a tool for unpacking and decompiling packaged WeChat mini-program (wxapkg) files back into readable source files such as w… | 10 | 4506 | abandoned |
| trailofbits/manticore Manticore is a symbolic execution tool for analyzing Ethereum smart contracts, Linux ELF binaries, and WASM modules. It explores program st… | 10 | 3857 | abandoned |
| djkaty/Il2CppInspector Il2CppInspector is an automated tool for reverse engineering Unity IL2CPP binaries, extracting type definitions, metadata and method pointe… | 23 | 3036 | abandoned |
| stefanesser/dumpdecrypted A dylib that, when injected via DYLD_INSERT_LIBRARIES into an encrypted iPhone application on a jailbroken device, dumps the decrypted Mach… | 32 | 3035 | abandoned |
| google/binnavi BinNavi is a binary analysis IDE for inspecting, navigating, editing, and annotating control-flow and call graphs of disassembled code, wit… | 10 | 2883 | abandoned |
| tostercx/GTAO_Booster_PoC A proof-of-concept DLL injection that patches two bugs in GTA Online to drastically reduce load times on CPU-bound systems. It was official… | 10 | 2871 | abandoned |
| DrizzleRisk/drizzleDumper drizzleDumper is a memory-search-based Android unpacking tool that dumps DEX files from packed/protected Android apps. It runs as a command… | 32 | 2415 | abandoned |
| dgiese/dustcloud A research project for reverse engineering and rooting Xiaomi Smart Home devices, including robot vacuums, providing methods to root device… | 23 | 2281 | abandoned |
| 8enet/Charles-Crack A repository that provided a crack/patch to bypass licensing of Charles Proxy, an HTTP debugging proxy tool. The repository content was rem… | 32 | 2149 | abandoned |
| HikariObfuscator/Hikari Hikari is an LLVM-based code obfuscator that transforms compiled binaries with techniques like string encryption, indirect branching, funct… | 10 | 2106 | abandoned |
| TKkk-iOSer/WeChatPlugin-iOS A jailbreak tweak (dylib) for the WeChat iOS app, built with Theos in Objective-C. It patches WeChat's runtime behavior to add unofficial f… | 32 | 1864 | abandoned |
| Neo23x0/yarGen yarGen is a Python CLI tool that generates YARA rules from strings found in malware samples, filtering out strings that appear in a large i… | 50 | 1811 | abandoned |
| Xposed-Modules-Repo/com.bug.hookvip An Xposed module for Android that hooks into apps to unlock certain VIP/membership features and extend functionality. The repository has be… | 10 | 1762 | abandoned |
| KEV0143/Direct-memory-access-CS2-DMA A C++ framework demonstrating Direct Memory Access (DMA) interaction with Counter-Strike 2, covering memory reading, entity-state parsing, … | 62 | 1749 | abandoned |
| tdryer/hangups hangups is the first third-party instant messaging client for Google Hangouts, implemented by reverse-engineering Hangouts' proprietary pro… | 32 | 1745 | abandoned |
| Gh0u1L5/WechatSpellbook An open-source WeChat plugin framework written in Kotlin that sits on top of hooking frameworks like Xposed or VirtualXposed. It exposes a … | 32 | 1732 | abandoned |
| Cisco-Talos/pyrebox PyREBox is a Python-scriptable reverse engineering sandbox built on QEMU that provides whole-system dynamic analysis and debugging of runni… | 10 | 1684 | abandoned |
| chaitin/passionfruit Passionfruit is a web-based GUI tool for blackbox assessment of iOS apps, built on the Frida instrumentation framework and Vue.js. It lets … | 10 | 1668 | abandoned |
| viper-framework/viper Viper is a Python-based binary analysis and management framework for organizing collections of malware and exploit samples along with analy… | 10 | 1562 | abandoned |
| sailro/Reflexil Reflexil is a .NET assembly editor that runs as a plugin for Reflector, ILSpy, and JustDecompile. Built on Mono.Cecil, it can manipulate IL… | 10 | 1530 | abandoned |
| kennytm/iphone-private-frameworks A collection of C headers for private frameworks and undocumented interfaces of iPhoneOS 3.x and earlier, used for jailbroken iOS tweak dev… | 10 | 1462 | abandoned |
| hteso/iaito Iaitō is a Qt and C++ graphical user interface for the radare2 reverse engineering framework, aimed at users who find radare2's CLI too dif… | 32 | 1457 | abandoned |
| das-labor/panopticon Panopticon is a libre, cross-platform disassembler written in Rust for reverse engineering binaries. It supports AMD64, x86, AVR, and MOS 6… | 10 | 1445 | abandoned |
| xmoezzz/KrkrExtract KrkrExtract is a Windows tool for extracting and repacking XP3 archive files used by the Kirikiri (krkr2/krkrz) visual novel game engine, s… | 10 | 1430 | abandoned |
| RaduMC/AssetStudio AssetStudio is a standalone Windows GUI tool for exploring, previewing, and extracting assets from Unity game files and bundles. It can exp… | 23 | 1421 | abandoned |
| zyq8709/DexHunter DexHunter is an automatic unpacking tool for Android Dex files protected by app-hardening services. It works by replacing the ART and DVM r… | 32 | 1357 | abandoned |
| ClaudiuGeorgiu/Obfuscapk Obfuscapk is a modular Python tool that obfuscates Android APKs and App Bundles in a black-box fashion, without needing source code, by dec… | 10 | 1272 | abandoned |
| crmulliner/adbi ADBI is a dynamic binary instrumentation toolkit for Android ARM and Thumb binaries, based on library injection and inline hooking of funct… | 32 | 1266 | abandoned |
| tomer8007/widevine-l3-decryptor A Chrome extension that demonstrated bypassing Widevine L3 DRM by hijacking Encrypted Media Extensions calls to extract content decryption … | 10 | 1246 | abandoned |
| optiv/Mangle Mangle is a Go-based CLI tool that manipulates compiled Windows executables (.exe and DLL) to evade EDR detection. It strips known indicato… | 10 | 1235 | abandoned |