domain: reverse-engineering
558 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| wibus-wee/InjectGUI InjectGUI is a macOS graphical application that wraps the QiuChenly InjectLib framework for injecting dylibs into macOS applications, handl… | 10 | 1222 | abandoned |
| jacopotediosi/GAppsMod GAppsMod is a root-required Android application that tweaks Google apps (like Phone and Messages) by modifying the Phenotype DB flags manag… | 10 | 1218 | abandoned |
| leo9960/wechat-app-unpack A JavaScript tool and write-up for unpacking WeChat Mini Program .wxapkg packages, restoring source files like app-config., app-service.js,… | 32 | 1167 | abandoned |
| firesunCN/WechatEnhancement An Xposed framework module written in Java that hooks the WeChat Android app to add features like automatic red packet and transfer accepta… | 23 | 1153 | abandoned |
| yulingtianxia/FishChat FishChat is an Objective-C hooking project that injects a dylib into a decrypted WeChat.app binary to modify its behavior on non-jailbroken… | 10 | 1103 | abandoned |
| okcar-os/android OkcarOS is an open-source Android 13-based ROM (built on LineageOS) that lets an Android smartphone act as a CarPlay device, streaming audi… | 69 | 1077 | abandoned |
| EquiFox/KsDumper KsDumper is a Windows tool that dumps process memory (including protected processes with stripped handles) using a kernel driver, rebuildin… | 23 | 1055 | abandoned |
| halfkiss/ZjDroid ZjDroid is an Xposed framework module for dynamic reverse engineering of Android apps. It supports memory dumping of DEX files, BackSmali d… | 32 | 1021 | abandoned |
| gchq/CyberChef CyberChef is a browser-based web application for performing a wide range of 'cyber' operations such as encryption, encoding, compression, h… | 98 | 35679 | active |
| MobSF/Mobile-Security-Framework-MobSF MobSF is an automated all-in-one mobile application security testing framework for Android, iOS, and Windows Mobile apps. It performs stati… | 94 | 21650 | active |
| basketikun/chatgpt2api A self-hosted reverse-engineered implementation of ChatGPT's official web interfaces, exposing OpenAI-compatible API endpoints for text gen… | 77 | 6012 | active |
| RfidResearchGroup/proxmark3 The Iceman fork of Proxmark3, the client software for the Proxmark3 RFID analysis device, supporting reading, cloning, simulating, and snif… | 88 | 5986 | active |
| aidlearning/AidLearning-FrameWork AidLux (originally AidLearning) is an AIoT development platform that runs a native Ubuntu Linux environment with GUI, deep learning tooling… | 70 | 5797 | active |
| ReagentX/imessage-exporter A Rust CLI tool and companion library that exports iMessage data to portable txt/html formats while preserving attachments and full message… | 96 | 5535 | active |
| abcz316/SKRoot-linuxKernelRoot SKRoot is a kernel-level hidden root solution for Android that patches stock kernel images without source code, granting root privileges wh… | 85 | 3897 | active |
| gtworek/PSBits A collection of relatively simple C and PowerShell snippets for digging deeper into Windows internals, security, and forensics. Each folder… | 76 | 3519 | active |
| 0xd4d/dnlib dnlib is a C# library that reads and writes .NET assemblies and modules, including method bodies and IL code. It supports loading modules f… | 61 | 2483 | stable |
| ValveResourceFormat/ValveResourceFormat Source 2 Viewer (VRF) is an open-source tool for browsing VPK archives and viewing, extracting, and decompiling Source 2 game assets such a… | 95 | 2391 | active |
| nfcgate/nfcgate NFCGate is an Android application for capturing, analyzing, modifying, relaying, replaying, and cloning NFC traffic. It is a security resea… | 84 | 2333 | active |
| Ch0pin/medusa MEDUSA is a modular automation framework and script repository for runtime testing and investigating Android and iOS apps, built on FRIDA. … | 84 | 2332 | active |
| googleprojectzero/sandbox-attacksurface-analysis-tools A suite of PowerShell tools and .NET libraries from Google Project Zero for analyzing Windows sandbox attack surfaces. It includes NtCoreLi… | 56 | 2332 | active |
| o-gs/dji-firmware-tools A collection of C command-line tools for extracting, modifying, and repacking firmware of DJI drones such as Phantom, Mavic, Inspire, and S… | 74 | 2186 | active |
| abc123info/BlueTeamTools BlueTeamTools is a Java-based GUI toolbox that aggregates utilities for blue-team security analysts, covering memory-shell decompilation, w… | 91 | 1859 | active |
| Rob--W/crxviewer A browser add-on and web app for viewing the source code of Chrome, Firefox, Opera, Edge, and Thunderbird extensions without installing the… | 72 | 1712 | active |
| newaetech/chipwhisperer ChipWhisperer is an open-source toolchain for hardware security research, providing capture hardware designs, FPGA/USB firmware, and a Pyth… | 79 | 1557 | active |
| sandeco/reversa Reversa is a specification reverse-engineering framework that installs into legacy codebases and coordinates specialized AI agents to analy… | 59 | 1526 | active |
| tyranid/oleviewdotnet OleView.NET is a .NET application that merges the classic SDK tools OleView and Test Container into one COM/OLE viewer and inspector. It le… | 23 | 1417 | active |
| platomav/MEAnalyzer ME Analyzer is a Python command-line tool that parses and identifies Intel Engine (CSME, TXE, SPS, GSC) and Graphics firmware images, repor… | 79 | 1320 | active |
| sulab999/AppMessenger AppMessenger is a free cross-platform (Windows/Mac/Linux, Java-based) GUI tool for analyzing mobile application packages including APK (And… | 86 | 1308 | active |
| MarshalX/yandex-music-api An unofficial Python client library for the undocumented Yandex Music API, built via reverse engineering. It offers both synchronous and as… | 72 | 1250 | active |
| jxy-s/herpaderping A proof-of-concept tool and technical write-up demonstrating Process Herpaderping, a Windows technique that maps a process image from a fil… | 32 | 1210 | active |
| maoabc/nmmp nmmp is an APK/AAB/AAR hardening tool that converts Dalvik bytecode from classes.dex into native C code executed by a custom dex virtual ma… | 40 | 1202 | active |
| greatscottgadgets/luna LUNA is an Amaranth HDL (Python) framework providing FPGA gateware and software for working with USB, from passive protocol analysis to bui… | 75 | 1133 | active |
| open-obfuscator/o-mvll O-MVLL is an LLVM-based code obfuscator for native code that integrates with Clang and the Swift compiler via the LLVM pass manager, with o… | 97 | 1129 | active |
| platomav/BIOSUtilities A collection of Python-based BIOS/UEFI utilities for extracting, unpacking, and analyzing firmware images from vendors like AMI, Insyde, Ph… | 45 | 1078 | active |
| Lazarus-AI/clearwing Clearwing is a dual-mode autonomous offensive-security tool that combines a network-pentest ReAct agent with an LLM-driven source-code vuln… | 63 | 1063 | active |
| vitoplantamura/BugChecker BugChecker is a SoftICE-like kernel and user-mode debugger for Windows (XP through 11, x86 and x64) that runs entirely on the machine being… | 22 | 1055 | active |
| iptag/jimeng-api A self-hosted API service that reverse-engineers Jimeng AI (China) and Dreamina (international) to expose free AI image and video generatio… | 10 | 1041 | active |
| nowsecure/fsmon fsmon is a low-level, cross-platform filesystem monitoring CLI tool written in C that reports real-time file operations (create, delete, mo… | 57 | 1023 | active |
| hugsy/cemu CEmu is a lightweight assembly playground providing GUI, CLI, and library interfaces for writing, compiling, disassembling, and emulating a… | 23 | 1019 | active |
| odedshimon/BruteShark BruteShark is an open-source Network Forensic Analysis Tool (NFAT) that deeply inspects network traffic from PCAP/PCAPng files or live capt… | 23 | 3395 | maintenance |
| seemoo-lab/openhaystack OpenHaystack is a framework and macOS application for creating custom Bluetooth tracking tags that leverage Apple's Find My (offline findin… | 67 | 13467 | experimental |
| asLody/SandHook SandHook is an Android ART runtime hooking library supporting Java method hooks and native inline hooks on Android 4.4 through 11.0 for bot… | 23 | 2229 | maintenance |
| ViRb3/TrustMeAlready An Xposed module for rooted Android devices that disables SSL certificate verification and pinning system-wide. It hooks Java trust-check m… | 10 | 1508 | maintenance |
| nccgroup/house House is a runtime mobile application analysis toolkit with a web GUI, powered by Frida and written in Python. It simplifies dynamic functi… | 32 | 1463 | maintenance |
| jesparza/peepdf peepdf is a Python tool for analyzing PDF files to determine whether they are malicious, offering object inspection, filter/encoding decodi… | 32 | 1461 | maintenance |
| RazTools/Studio A fork of AssetStudio, a GUI and CLI tool for inspecting and extracting assets (textures, sprites, meshes, animations) from Unity asset bun… | 10 | 1295 | maintenance |
| positive-security/find-you A modified version of OpenHaystack that demonstrates a stealth AirTag clone capable of bypassing Apple's Find My tracking protection featur… | 32 | 1239 | maintenance |
| Al-Azif/ps4-exploit-host A self-hosted exploit hosting tool for game consoles (PS4, PS5, Vita, Switch, Wii) that serves exploits over a LAN via DNS and HTTP. It can… | 23 | 1203 | maintenance |
| JackOfMostTrades/gadgetinspector A Java bytecode analyzer that automatically discovers deserialization gadget chains in Java libraries and application classpaths. It produc… | 32 | 1090 | maintenance |
| eveem-org/panoramix Panoramix is a Python-based decompiler that converts Ethereum smart contract bytecode into readable pseudocode, powering the Eveem.org serv… | 32 | 1042 | maintenance |
| nmikhailov/Validity90 A reverse-engineering project for Validity/Synaptics fingerprint readers (USB IDs 138a:0090, 138a:0094, 138a:0097, 06cb:0081, 06cb:009a), p… | 32 | 1875 | experimental |
| Proxmark/proxmark3 The official (now archived) client software, FPGA logic, and design documentation for the Proxmark3, a general-purpose RFID tool that can s… | 50 | 3534 | abandoned |
| Gh0u1L5/WechatMagician WechatMagician is an open-source Xposed module written in Kotlin that hooks into the WeChat app to give users full control over chat messag… | 23 | 1894 | abandoned |
| stypr/clubhouse-py A Python implementation of the Clubhouse social audio API, including a standalone desktop client. It was created for security research and … | 10 | 1655 | abandoned |
| asLody/legend Legend is a Java method hooking framework for Android that works without root access, supporting both Dalvik and ART runtimes. It lets deve… | 32 | 1605 | abandoned |
| acheong08/Bard A Python SDK and CLI that reverse engineers Google's Bard chatbot API, allowing programmatic access using session cookies. It offers both s… | 10 | 1393 | abandoned |
| elvanderb/TCP-32764 A collection of Python proof-of-concept code and research notes documenting a hidden backdoor listening on TCP port 32764 in Linksys, Netge… | 32 | 1291 | abandoned |
← prev page 6 / 6