Ross ROSS = Recommend OSS · open-source software intelligence for agents

function: reverse-engineering

630 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
NationalSecurityAgency/ghidra
Ghidra is a software reverse engineering framework built by the NSA that includes a suite of tools for disassembly, decompilation, graphing…
9572873stable
WerWolv/ImHex
ImHex is a free, open-source hex editor built for reverse engineers, programmers, and security researchers. It offers binary analysis featu…
8654573active
skylot/jadx
JADX is a Dex to Java decompiler that produces readable Java source code from Android APK, dex, aar, aab, and zip files, available as both …
8850219active
x64dbg/x64dbg
x64dbg is an open-source user-mode binary debugger for Windows supporting both 32-bit and 64-bit executables. It is optimized for reverse e…
9049306active
huiyadanli/RevokeMsgPatcher
A Windows GUI tool that patches PC WeChat, QQ, and TIM binaries to prevent message recall (anti-revoke), and optionally enables WeChat mult…
7038583active
zhaoxuya520/reverse-skill
A cybersecurity skill router pack that directs AI coding agents (Claude Code, Cursor, Cline, Kiro) to the right reverse-engineering, penetr…
6929591active
librepods-org/librepods
LibrePods is an open-source app that unlocks Apple AirPods-exclusive features on Linux and Android by implementing the proprietary Bluetoot…
8629585active
ILSpy
ILSpy is an open-source, cross-platform .NET assembly browser and decompiler that converts compiled .NET binaries back into readable C# sou…
9825954active
iBotPeaches/Apktool
Apktool is a Java-based command-line tool for reverse engineering Android APK files. It decodes resources and manifest files to nearly orig…
8925386stable
radare2
Radare2 is a libre reverse engineering framework and command-line toolset for analyzing, disassembling, debugging, emulating, and modifying…
9424652active
Frida
Frida is a dynamic instrumentation toolkit that lets developers, reverse-engineers, and security researchers inject JavaScript or native li…
9421752active
cheat-engine/cheat-engine
Cheat Engine is a desktop development environment for modding games and applications, centered on a memory scanner that finds and edits pro…
3019055active
Konloch/bytecode-viewer
Bytecode Viewer is a free, open-source Java and Android APK reverse engineering suite that bundles six Java decompilers, bytecode disassemb…
7315614active
ReFirmLabs/binwalk
Binwalk is a fast firmware analysis tool rewritten in Rust that identifies and optionally extracts files and data embedded inside other fil…
6614276active
sunnyyoung/WeChatTweak
A command-line tool that patches the WeChat macOS client to add features like preventing message revocation, blocking automatic updates, an…
7113827active
HIllya51/LunaTranslator
LunaTranslator is a Windows application that translates visual novels (galgames) in real time. It extracts text via win32 hooking or OCR an…
9512912active
jopohl/urh
Universal Radio Hacker (URH) is a complete open-source suite for investigating wireless protocols, with native support for many common Soft…
1012569active
mrexodia/ida-pro-mcp
An MCP server and IDA Pro plugin that connects IDA Pro's binary analysis capabilities to language models, enabling AI-assisted reverse engi…
6111616active
Detect It Easy
Detect It Easy (DiE) is a cross-platform file type identification tool that uses signature-based and heuristic analysis to detect compilers…
8111420active
pwndbg/pwndbg
Pwndbg is a Python-based plug-in for GDB and LLDB that enhances low-level debugging with features tailored to reverse engineering and explo…
9410801active
rr-debugger/rr
rr is a lightweight record-and-replay framework for Linux that captures the full execution of applications (process and thread trees) and r…
6710630active
LaurieWired/GhidraMCP
GhidraMCP is a Model Context Protocol server implemented as a Ghidra plugin that exposes Ghidra's reverse engineering tools to LLM clients.…
349865active
xenia-project/xenia
Xenia is an experimental open-source emulator for the Xbox 360, developed through reverse engineering of legally purchased hardware and gam…
639649active
alufers/mitmproxy2swagger
A CLI tool that converts mitmproxy traffic captures (and HAR files) into OpenAPI 3.0 / Swagger specifications. It lets you reverse-engineer…
839594active
Il2CppDumper
Il2CppDumper is a C# command-line tool that extracts type, method, and string information from Unity IL2CPP binaries and their global-metad…
239339active
unicorn-engine/unicorn
Unicorn is a lightweight, multi-architecture CPU emulator framework based on QEMU, supporting ARM, ARM64, M68K, MIPS, PowerPC, RISC-V, SPAR…
759268stable
angr
angr is a Python 3 binary analysis framework that loads executables across many architectures and formats, providing disassembly, IR liftin…
779039active
diasurgical/devilution
Devilution is a reconstructed version of the original Diablo (1996) game source code, reverse-engineered from leaked symbol files and debug…
428996active
capstone-engine/capstone
Capstone is a lightweight, multi-architecture, multi-platform disassembly framework written in pure C, designed to be the ultimate disassem…
978976stable
n64decomp/sm64
A complete community decompilation of Super Mario 64 covering the Japan, North America, Europe, Shindou, and iQue releases, written in C. I…
238737active
hugsy/gef
GEF (GDB Enhanced Features) is a single-file Python plugin for GDB that adds a modern, feature-rich debugging experience for exploit develo…
778326active
PCILeech
PCILeech is DMA attack software that uses PCIe hardware devices (or software memory acquisition methods) to read and write target system me…
657899active
r0ysue/r0capture
A Frida-based universal Android application-layer packet capture script that hooks SSL/TLS regardless of certificate pinning, obfuscation, …
647750active
SimoneAvogadro/android-reverse-engineering-skill
A Claude Code skill that decompiles Android APK/XAPK/JAR/AAR files and extracts the HTTP APIs an app uses, including Retrofit, OkHttp, Ktor…
597376active
Col-E/Recaf
Recaf is a modern Java bytecode editor with a JavaFX GUI that abstracts away low-level class file complexities like constant pools and stac…
697355active
albertan017/LLM4Decompile
LLM4Decompile is an open-source series of large language models (1.3B to 33B) trained to decompile binary code back into readable, executab…
556986active
hedge-dev/XenonRecomp
XenonRecomp is a static recompilation tool that converts Xbox 360 (PowerPC) executables into C++ code that can be recompiled into native ex…
386451active
microsoft/Detours
Microsoft Detours is a C++ library for intercepting, monitoring, and instrumenting Win32 API calls on Windows via function hooking and bina…
676364stable
dnSpy/dnSpy
dnSpy is a Windows GUI application for debugging and editing .NET and Unity assemblies without needing source code. It combines a debugger,…
1029689maintenance
dwisiswant0/apkleaks
APKLeaks is a Python CLI tool that decompiles Android APK files with jadx and scans them for URIs, endpoints, and hardcoded secrets using r…
396275active
androguard/androguard
Androguard is a full Python tool and library for reverse engineering and analyzing Android files, including DEX/ODEX bytecode disassembly a…
836209active
mandiant/capa
capa is Mandiant FLARE's open-source tool that identifies capabilities in executable files (PE, ELF, .NET, shellcode) by matching expert-wr…
876156active
qilingframework/qiling
Qiling is a Python-based binary emulation framework built on Unicorn Engine that emulates executables across multiple platforms (Windows, m…
796075active
RfidResearchGroup/proxmark3
The Iceman fork of Proxmark3, the client software for the Proxmark3 RFID analysis device, supporting reading, cloning, simulating, and snif…
885986active
Ackites/KillWxapkg
A Go-based CLI tool that automatically decrypts, unpacks, and decompiles WeChat mini-program .wxapkg packages, restoring the original proje…
145957active
TsudaKageyu/minhook
MinHook is a minimalistic, lightweight C library for intercepting (hooking) x86 and x64 function calls on Windows, using a trampoline/detou…
625955stable
jindrapetrik/jpexs-decompiler
JPEXS Free Flash Decompiler (FFDec) is an open-source Java application for decompiling and editing Adobe Flash SWF files. It extracts resou…
935828active
cinit/QAuxiliary
QAuxiliary is an open-source Xposed module based on QNotified that adds extra features and tweaks to the QQ and TIM Android messaging clien…
925720active
lief-project/LIEF
LIEF is a cross-platform C++ library (with Python and Rust bindings) for parsing, inspecting, modifying, and writing executable file format…
975549stable
zeldaret/oot
A community-driven, work-in-progress decompilation of The Legend of Zelda: Ocarina of Time that recreates readable C source code from the o…
765489active
CreditTone/hooker
hooker is a Frida-based reverse engineering toolkit for Android that provides a comfortable command-line interface with universal hooking s…
705285active
mentebinaria/retoolkit
An Inno Setup-based installer that bundles a curated collection of reverse engineering and malware analysis tools for x86/x64 Windows syste…
825278active
Naituw/IPAPatch
IPAPatch is an Xcode project template that lets you patch decrypted iOS app IPA files by injecting your own dynamic libraries, without requ…
545275active
timschneeb/GalaxyBudsClient
An unofficial desktop and Android manager for Samsung Galaxy Buds earbuds, built in C#. It exposes detailed battery stats, diagnostics, cus…
865190active
zhkl0228/unidbg
A Java-based framework that emulates Android (and experimentally iOS) native libraries on non-ARM hosts, including JNI, syscalls, and ARM32…
795165active
TwilitRealm/dusklight
Dusklight is a reverse-engineered, open-source reimplementation of The Legend of Zelda: Twilight Princess that runs the game natively on PC…
805152active
niklashigi/apk-mitm
A Node.js CLI application that automatically patches Android APK files to allow HTTPS traffic inspection through a man-in-the-middle proxy.…
235092stable
atom0s/Steamless
Steamless is a C# tool that removes the SteamStub DRM protection layer applied to Steam game executables via the Steamworks SDK DRM tool. I…
234990active
pret/pokered
A complete assembly-language disassembly of Pokémon Red and Blue for the Game Boy, which can be rebuilt byte-identical into the original RO…
764892active
charles2gan/GDA-android-reversing-Tool
GDA (GJoy Dex Analyzer) is a fast, native C++ Dalvik bytecode decompiler and reverse analysis platform for Android binaries such as APK, DE…
704818active
aloshdenny/reverse-SynthID
A research tool that reverse-engineers Google's SynthID watermark embedded in Gemini-generated images using spectral analysis and signal pr…
664815active
jmpews/Dobby
Dobby is a lightweight, modular function hooking framework supporting multiple platforms (Windows, macOS, iOS, Android, Linux) and architec…
244813active
snesrev/zelda3
A reverse-engineered reimplementation of The Legend of Zelda: A Link to the Past written in ~70-80k lines of C, playable from start to fini…
234739active
MlgmXyysd/Xiaomi-HyperOS-BootLoader-Bypass
A proof-of-concept PHP tool that exploits a vulnerability to bypass Xiaomi HyperOS community account restrictions on BootLoader unlock bind…
404738active
vaibhavpandeyvpz/apkstudio
APK Studio is an open-source, cross-platform Qt6 IDE for reverse-engineering Android application packages. It bundles decompiling, recompil…
694630active
k4zmu2a/SpaceCadetPinball
A cross-platform decompilation of the classic 3D Pinball for Windows – Space Cadet game, rebuilt in C++ from the original Windows XP binary…
234621active
ReversecLabs/drozer
drozer is an open-source security assessment framework for Android that lets testers assume the role of an app and interact with the Androi…
574597active
zrax/pycdc
Decompyle++ is a C++ tool that translates compiled Python bytecode (.pyc files) back into readable Python source code. It includes pycdas, …
664594active
hluwa/frida-dexdump
A Frida-based CLI tool that finds and dumps DEX files from an Android app's memory, enabling unpacking of packed or obfuscated APKs. It sup…
104560stable
taviso/loadlibrary
A library that lets native Linux programs load and call functions from Windows DLLs via a custom PE/COFF loader with a dlopen-like API. It …
394501active
JonathanSalwan/ROPgadget
ROPgadget is a Python command-line tool that searches binaries for ROP gadgets to facilitate return-oriented programming exploitation. It s…
674470active
BeichenDream/Godzilla
Godzilla is a Java-based webshell management tool supporting dynamic payloads for JSP, ASPX, and PHP targets with multiple AES/XOR encrypto…
234455active
extremecoders-re/pyinstxtractor
A Python script that extracts the contents of PyInstaller-generated executables, including fixing pyc headers so bytecode decompilers can p…
844447stable
orhun/binsider
Binsider is a terminal user interface tool for analyzing ELF binaries, offering static and dynamic analysis, string inspection, linked libr…
844404active
joxeankoret/diaphora
Diaphora is a free and open source program diffing (binary diffing) tool that works as an IDA Pro plugin, comparing binaries to find change…
944373active
zyantific/zydis
Zydis is a fast, lightweight x86/x86-64 disassembler and encoder library written in C with zero dependencies, not even libc. It supports al…
654351active
rocky/python-uncompyle6
uncompyle6 is a cross-version Python bytecode decompiler that translates bytecode from Python 1.0 through 3.8 back into equivalent Python s…
624316active
JonathanSalwan/Triton
Triton is a dynamic binary analysis library providing dynamic symbolic execution, taint analysis, and ISA semantics for x86, x86-64, ARM32,…
654274active
x64dbg/ScyllaHide
ScyllaHide is an advanced usermode anti-anti-debug library that hooks Windows functions to hide the presence of a debugger from debugged pr…
234271active
magcius/noclip.website
noclip.website is a browser-based application that lets users explore and fly through video game levels rendered from reverse-engineered mo…
774246active
JaveleyQAQ/WeChatOpenDevTools-Python
A Python tool that force-enables the hidden developer tools (F12) in WeChat mini programs and WeChat's built-in browser. It is a Python rew…
164211active
mandiant/flare-floss
FLOSS (FLARE Obfuscated String Solver) is a Python CLI tool from Mandiant that automatically extracts and deobfuscates strings from malware…
674138active
GDRETools/gdsdecomp
A tool for reverse engineering Godot game projects, supporting full project recovery from PCK, APK, or EXE files. It includes a PCK extract…
984112active
wux1an/wxapkg
A cross-platform desktop GUI tool built with Wails for scanning, decrypting, and unpacking WeChat mini-program .wxapkg files. It restores t…
694037active
HyperDbg/HyperDbg
HyperDbg is an open-source, hypervisor-assisted debugger for Windows (with Linux support in development) that uses Intel VT-x and EPT to de…
944012active
APKLab/APKLab
APKLab is a VS Code extension that turns the editor into an Android reverse-engineering workbench by integrating Apktool, Jadx, uber-apk-si…
743952active
a0rtega/pafish
Pafish is a Windows testing tool that applies the same VM and sandbox detection techniques used by malware families to check whether an ana…
103946active
cea-sec/miasm
Miasm is a free and open source (GPLv2) reverse engineering framework written in Python for analyzing, modifying, and generating binary pro…
673944active
hasherezade/pe-sieve
PE-sieve is a lightweight Windows tool that scans a given process for malicious implants such as replaced or injected PE files, shellcodes,…
713867active
danielkrupinski/Osiris
Osiris is a cross-platform (Windows and Linux) game hack for Counter-Strike 2, built in C++20 with a GUI and rendering based on the game's …
773848active
ax/apk.sh
A Bash script that automates Android APK reverse engineering tasks such as pulling, decoding, rebuilding, and patching APKs. It wraps apkto…
733822active
Rizin
Cutter is a free and open-source graphical reverse engineering platform built on top of the Rizin framework, a Unix-friendly command-line t…
883806active
hasherezade/pe-bear
PE-bear is a multiplatform GUI reversing tool for Windows PE (Portable Executable) files, built on bearparser and capstone. It gives malwar…
783781active
HookVip (NewHookVip)
NewHookVip is an Xposed module for Android that hooks into target apps to unlock certain membership/VIP features, remove some restrictions,…
753696active
blacktop/ipsw
ipsw is a Go-based command-line research framework for downloading, parsing, and analyzing Apple iOS and macOS firmware (IPSW/OTA files), M…
953669active
e-m-b-a/emba
EMBA is an open-source firmware security analyzer for embedded Linux devices, written in Bash. It automates firmware extraction, static and…
933614active
Lessica/TrollFools
TrollFools is an iOS application for TrollStore that performs in-place tweak injection into installed apps using insert_dylib and ChOma. It…
743599active
java-decompiler/jd-gui
JD-GUI is a standalone graphical Java decompiler that displays Java source code reconstructed from .class files. It lets users browse decom…
2315180maintenance
icedland/iced
iced is a fast and correct x86/x64 (16/32/64-bit) instruction decoder, disassembler, and assembler library with bindings for Rust, .NET, Ja…
673556active
momo5502/sogen
Sogen is a C++ userspace emulator that runs Windows and Linux binaries at the CPU and syscall level without a real operating system, execut…
673553active

page 1 / 7 next →