function: reverse-engineering
630 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| NationalSecurityAgency/ghidra Ghidra is a software reverse engineering framework built by the NSA that includes a suite of tools for disassembly, decompilation, graphing… | 95 | 72873 | stable |
| WerWolv/ImHex ImHex is a free, open-source hex editor built for reverse engineers, programmers, and security researchers. It offers binary analysis featu… | 86 | 54573 | active |
| skylot/jadx JADX is a Dex to Java decompiler that produces readable Java source code from Android APK, dex, aar, aab, and zip files, available as both … | 88 | 50219 | active |
| x64dbg/x64dbg x64dbg is an open-source user-mode binary debugger for Windows supporting both 32-bit and 64-bit executables. It is optimized for reverse e… | 90 | 49306 | active |
| huiyadanli/RevokeMsgPatcher A Windows GUI tool that patches PC WeChat, QQ, and TIM binaries to prevent message recall (anti-revoke), and optionally enables WeChat mult… | 70 | 38583 | active |
| zhaoxuya520/reverse-skill A cybersecurity skill router pack that directs AI coding agents (Claude Code, Cursor, Cline, Kiro) to the right reverse-engineering, penetr… | 69 | 29591 | active |
| librepods-org/librepods LibrePods is an open-source app that unlocks Apple AirPods-exclusive features on Linux and Android by implementing the proprietary Bluetoot… | 86 | 29585 | active |
| ILSpy ILSpy is an open-source, cross-platform .NET assembly browser and decompiler that converts compiled .NET binaries back into readable C# sou… | 98 | 25954 | active |
| iBotPeaches/Apktool Apktool is a Java-based command-line tool for reverse engineering Android APK files. It decodes resources and manifest files to nearly orig… | 89 | 25386 | stable |
| radare2 Radare2 is a libre reverse engineering framework and command-line toolset for analyzing, disassembling, debugging, emulating, and modifying… | 94 | 24652 | active |
| Frida Frida is a dynamic instrumentation toolkit that lets developers, reverse-engineers, and security researchers inject JavaScript or native li… | 94 | 21752 | active |
| cheat-engine/cheat-engine Cheat Engine is a desktop development environment for modding games and applications, centered on a memory scanner that finds and edits pro… | 30 | 19055 | active |
| Konloch/bytecode-viewer Bytecode Viewer is a free, open-source Java and Android APK reverse engineering suite that bundles six Java decompilers, bytecode disassemb… | 73 | 15614 | active |
| ReFirmLabs/binwalk Binwalk is a fast firmware analysis tool rewritten in Rust that identifies and optionally extracts files and data embedded inside other fil… | 66 | 14276 | active |
| sunnyyoung/WeChatTweak A command-line tool that patches the WeChat macOS client to add features like preventing message revocation, blocking automatic updates, an… | 71 | 13827 | active |
| HIllya51/LunaTranslator LunaTranslator is a Windows application that translates visual novels (galgames) in real time. It extracts text via win32 hooking or OCR an… | 95 | 12912 | active |
| jopohl/urh Universal Radio Hacker (URH) is a complete open-source suite for investigating wireless protocols, with native support for many common Soft… | 10 | 12569 | active |
| mrexodia/ida-pro-mcp An MCP server and IDA Pro plugin that connects IDA Pro's binary analysis capabilities to language models, enabling AI-assisted reverse engi… | 61 | 11616 | active |
| Detect It Easy Detect It Easy (DiE) is a cross-platform file type identification tool that uses signature-based and heuristic analysis to detect compilers… | 81 | 11420 | active |
| pwndbg/pwndbg Pwndbg is a Python-based plug-in for GDB and LLDB that enhances low-level debugging with features tailored to reverse engineering and explo… | 94 | 10801 | active |
| rr-debugger/rr rr is a lightweight record-and-replay framework for Linux that captures the full execution of applications (process and thread trees) and r… | 67 | 10630 | active |
| LaurieWired/GhidraMCP GhidraMCP is a Model Context Protocol server implemented as a Ghidra plugin that exposes Ghidra's reverse engineering tools to LLM clients.… | 34 | 9865 | active |
| xenia-project/xenia Xenia is an experimental open-source emulator for the Xbox 360, developed through reverse engineering of legally purchased hardware and gam… | 63 | 9649 | active |
| alufers/mitmproxy2swagger A CLI tool that converts mitmproxy traffic captures (and HAR files) into OpenAPI 3.0 / Swagger specifications. It lets you reverse-engineer… | 83 | 9594 | active |
| Il2CppDumper Il2CppDumper is a C# command-line tool that extracts type, method, and string information from Unity IL2CPP binaries and their global-metad… | 23 | 9339 | active |
| unicorn-engine/unicorn Unicorn is a lightweight, multi-architecture CPU emulator framework based on QEMU, supporting ARM, ARM64, M68K, MIPS, PowerPC, RISC-V, SPAR… | 75 | 9268 | stable |
| angr angr is a Python 3 binary analysis framework that loads executables across many architectures and formats, providing disassembly, IR liftin… | 77 | 9039 | active |
| diasurgical/devilution Devilution is a reconstructed version of the original Diablo (1996) game source code, reverse-engineered from leaked symbol files and debug… | 42 | 8996 | active |
| capstone-engine/capstone Capstone is a lightweight, multi-architecture, multi-platform disassembly framework written in pure C, designed to be the ultimate disassem… | 97 | 8976 | stable |
| n64decomp/sm64 A complete community decompilation of Super Mario 64 covering the Japan, North America, Europe, Shindou, and iQue releases, written in C. I… | 23 | 8737 | active |
| hugsy/gef GEF (GDB Enhanced Features) is a single-file Python plugin for GDB that adds a modern, feature-rich debugging experience for exploit develo… | 77 | 8326 | active |
| PCILeech PCILeech is DMA attack software that uses PCIe hardware devices (or software memory acquisition methods) to read and write target system me… | 65 | 7899 | active |
| r0ysue/r0capture A Frida-based universal Android application-layer packet capture script that hooks SSL/TLS regardless of certificate pinning, obfuscation, … | 64 | 7750 | active |
| SimoneAvogadro/android-reverse-engineering-skill A Claude Code skill that decompiles Android APK/XAPK/JAR/AAR files and extracts the HTTP APIs an app uses, including Retrofit, OkHttp, Ktor… | 59 | 7376 | active |
| Col-E/Recaf Recaf is a modern Java bytecode editor with a JavaFX GUI that abstracts away low-level class file complexities like constant pools and stac… | 69 | 7355 | active |
| albertan017/LLM4Decompile LLM4Decompile is an open-source series of large language models (1.3B to 33B) trained to decompile binary code back into readable, executab… | 55 | 6986 | active |
| hedge-dev/XenonRecomp XenonRecomp is a static recompilation tool that converts Xbox 360 (PowerPC) executables into C++ code that can be recompiled into native ex… | 38 | 6451 | active |
| microsoft/Detours Microsoft Detours is a C++ library for intercepting, monitoring, and instrumenting Win32 API calls on Windows via function hooking and bina… | 67 | 6364 | stable |
| dnSpy/dnSpy dnSpy is a Windows GUI application for debugging and editing .NET and Unity assemblies without needing source code. It combines a debugger,… | 10 | 29689 | maintenance |
| dwisiswant0/apkleaks APKLeaks is a Python CLI tool that decompiles Android APK files with jadx and scans them for URIs, endpoints, and hardcoded secrets using r… | 39 | 6275 | active |
| androguard/androguard Androguard is a full Python tool and library for reverse engineering and analyzing Android files, including DEX/ODEX bytecode disassembly a… | 83 | 6209 | active |
| mandiant/capa capa is Mandiant FLARE's open-source tool that identifies capabilities in executable files (PE, ELF, .NET, shellcode) by matching expert-wr… | 87 | 6156 | active |
| qilingframework/qiling Qiling is a Python-based binary emulation framework built on Unicorn Engine that emulates executables across multiple platforms (Windows, m… | 79 | 6075 | active |
| RfidResearchGroup/proxmark3 The Iceman fork of Proxmark3, the client software for the Proxmark3 RFID analysis device, supporting reading, cloning, simulating, and snif… | 88 | 5986 | active |
| Ackites/KillWxapkg A Go-based CLI tool that automatically decrypts, unpacks, and decompiles WeChat mini-program .wxapkg packages, restoring the original proje… | 14 | 5957 | active |
| TsudaKageyu/minhook MinHook is a minimalistic, lightweight C library for intercepting (hooking) x86 and x64 function calls on Windows, using a trampoline/detou… | 62 | 5955 | stable |
| jindrapetrik/jpexs-decompiler JPEXS Free Flash Decompiler (FFDec) is an open-source Java application for decompiling and editing Adobe Flash SWF files. It extracts resou… | 93 | 5828 | active |
| cinit/QAuxiliary QAuxiliary is an open-source Xposed module based on QNotified that adds extra features and tweaks to the QQ and TIM Android messaging clien… | 92 | 5720 | active |
| lief-project/LIEF LIEF is a cross-platform C++ library (with Python and Rust bindings) for parsing, inspecting, modifying, and writing executable file format… | 97 | 5549 | stable |
| zeldaret/oot A community-driven, work-in-progress decompilation of The Legend of Zelda: Ocarina of Time that recreates readable C source code from the o… | 76 | 5489 | active |
| CreditTone/hooker hooker is a Frida-based reverse engineering toolkit for Android that provides a comfortable command-line interface with universal hooking s… | 70 | 5285 | active |
| mentebinaria/retoolkit An Inno Setup-based installer that bundles a curated collection of reverse engineering and malware analysis tools for x86/x64 Windows syste… | 82 | 5278 | active |
| Naituw/IPAPatch IPAPatch is an Xcode project template that lets you patch decrypted iOS app IPA files by injecting your own dynamic libraries, without requ… | 54 | 5275 | active |
| timschneeb/GalaxyBudsClient An unofficial desktop and Android manager for Samsung Galaxy Buds earbuds, built in C#. It exposes detailed battery stats, diagnostics, cus… | 86 | 5190 | active |
| zhkl0228/unidbg A Java-based framework that emulates Android (and experimentally iOS) native libraries on non-ARM hosts, including JNI, syscalls, and ARM32… | 79 | 5165 | active |
| TwilitRealm/dusklight Dusklight is a reverse-engineered, open-source reimplementation of The Legend of Zelda: Twilight Princess that runs the game natively on PC… | 80 | 5152 | active |
| niklashigi/apk-mitm A Node.js CLI application that automatically patches Android APK files to allow HTTPS traffic inspection through a man-in-the-middle proxy.… | 23 | 5092 | stable |
| atom0s/Steamless Steamless is a C# tool that removes the SteamStub DRM protection layer applied to Steam game executables via the Steamworks SDK DRM tool. I… | 23 | 4990 | active |
| pret/pokered A complete assembly-language disassembly of Pokémon Red and Blue for the Game Boy, which can be rebuilt byte-identical into the original RO… | 76 | 4892 | active |
| charles2gan/GDA-android-reversing-Tool GDA (GJoy Dex Analyzer) is a fast, native C++ Dalvik bytecode decompiler and reverse analysis platform for Android binaries such as APK, DE… | 70 | 4818 | active |
| aloshdenny/reverse-SynthID A research tool that reverse-engineers Google's SynthID watermark embedded in Gemini-generated images using spectral analysis and signal pr… | 66 | 4815 | active |
| jmpews/Dobby Dobby is a lightweight, modular function hooking framework supporting multiple platforms (Windows, macOS, iOS, Android, Linux) and architec… | 24 | 4813 | active |
| snesrev/zelda3 A reverse-engineered reimplementation of The Legend of Zelda: A Link to the Past written in ~70-80k lines of C, playable from start to fini… | 23 | 4739 | active |
| MlgmXyysd/Xiaomi-HyperOS-BootLoader-Bypass A proof-of-concept PHP tool that exploits a vulnerability to bypass Xiaomi HyperOS community account restrictions on BootLoader unlock bind… | 40 | 4738 | active |
| vaibhavpandeyvpz/apkstudio APK Studio is an open-source, cross-platform Qt6 IDE for reverse-engineering Android application packages. It bundles decompiling, recompil… | 69 | 4630 | active |
| k4zmu2a/SpaceCadetPinball A cross-platform decompilation of the classic 3D Pinball for Windows – Space Cadet game, rebuilt in C++ from the original Windows XP binary… | 23 | 4621 | active |
| ReversecLabs/drozer drozer is an open-source security assessment framework for Android that lets testers assume the role of an app and interact with the Androi… | 57 | 4597 | active |
| zrax/pycdc Decompyle++ is a C++ tool that translates compiled Python bytecode (.pyc files) back into readable Python source code. It includes pycdas, … | 66 | 4594 | active |
| hluwa/frida-dexdump A Frida-based CLI tool that finds and dumps DEX files from an Android app's memory, enabling unpacking of packed or obfuscated APKs. It sup… | 10 | 4560 | stable |
| taviso/loadlibrary A library that lets native Linux programs load and call functions from Windows DLLs via a custom PE/COFF loader with a dlopen-like API. It … | 39 | 4501 | active |
| JonathanSalwan/ROPgadget ROPgadget is a Python command-line tool that searches binaries for ROP gadgets to facilitate return-oriented programming exploitation. It s… | 67 | 4470 | active |
| BeichenDream/Godzilla Godzilla is a Java-based webshell management tool supporting dynamic payloads for JSP, ASPX, and PHP targets with multiple AES/XOR encrypto… | 23 | 4455 | active |
| extremecoders-re/pyinstxtractor A Python script that extracts the contents of PyInstaller-generated executables, including fixing pyc headers so bytecode decompilers can p… | 84 | 4447 | stable |
| orhun/binsider Binsider is a terminal user interface tool for analyzing ELF binaries, offering static and dynamic analysis, string inspection, linked libr… | 84 | 4404 | active |
| joxeankoret/diaphora Diaphora is a free and open source program diffing (binary diffing) tool that works as an IDA Pro plugin, comparing binaries to find change… | 94 | 4373 | active |
| zyantific/zydis Zydis is a fast, lightweight x86/x86-64 disassembler and encoder library written in C with zero dependencies, not even libc. It supports al… | 65 | 4351 | active |
| rocky/python-uncompyle6 uncompyle6 is a cross-version Python bytecode decompiler that translates bytecode from Python 1.0 through 3.8 back into equivalent Python s… | 62 | 4316 | active |
| JonathanSalwan/Triton Triton is a dynamic binary analysis library providing dynamic symbolic execution, taint analysis, and ISA semantics for x86, x86-64, ARM32,… | 65 | 4274 | active |
| x64dbg/ScyllaHide ScyllaHide is an advanced usermode anti-anti-debug library that hooks Windows functions to hide the presence of a debugger from debugged pr… | 23 | 4271 | active |
| magcius/noclip.website noclip.website is a browser-based application that lets users explore and fly through video game levels rendered from reverse-engineered mo… | 77 | 4246 | active |
| JaveleyQAQ/WeChatOpenDevTools-Python A Python tool that force-enables the hidden developer tools (F12) in WeChat mini programs and WeChat's built-in browser. It is a Python rew… | 16 | 4211 | active |
| mandiant/flare-floss FLOSS (FLARE Obfuscated String Solver) is a Python CLI tool from Mandiant that automatically extracts and deobfuscates strings from malware… | 67 | 4138 | active |
| GDRETools/gdsdecomp A tool for reverse engineering Godot game projects, supporting full project recovery from PCK, APK, or EXE files. It includes a PCK extract… | 98 | 4112 | active |
| wux1an/wxapkg A cross-platform desktop GUI tool built with Wails for scanning, decrypting, and unpacking WeChat mini-program .wxapkg files. It restores t… | 69 | 4037 | active |
| HyperDbg/HyperDbg HyperDbg is an open-source, hypervisor-assisted debugger for Windows (with Linux support in development) that uses Intel VT-x and EPT to de… | 94 | 4012 | active |
| APKLab/APKLab APKLab is a VS Code extension that turns the editor into an Android reverse-engineering workbench by integrating Apktool, Jadx, uber-apk-si… | 74 | 3952 | active |
| a0rtega/pafish Pafish is a Windows testing tool that applies the same VM and sandbox detection techniques used by malware families to check whether an ana… | 10 | 3946 | active |
| cea-sec/miasm Miasm is a free and open source (GPLv2) reverse engineering framework written in Python for analyzing, modifying, and generating binary pro… | 67 | 3944 | active |
| hasherezade/pe-sieve PE-sieve is a lightweight Windows tool that scans a given process for malicious implants such as replaced or injected PE files, shellcodes,… | 71 | 3867 | active |
| danielkrupinski/Osiris Osiris is a cross-platform (Windows and Linux) game hack for Counter-Strike 2, built in C++20 with a GUI and rendering based on the game's … | 77 | 3848 | active |
| ax/apk.sh A Bash script that automates Android APK reverse engineering tasks such as pulling, decoding, rebuilding, and patching APKs. It wraps apkto… | 73 | 3822 | active |
| Rizin Cutter is a free and open-source graphical reverse engineering platform built on top of the Rizin framework, a Unix-friendly command-line t… | 88 | 3806 | active |
| hasherezade/pe-bear PE-bear is a multiplatform GUI reversing tool for Windows PE (Portable Executable) files, built on bearparser and capstone. It gives malwar… | 78 | 3781 | active |
| HookVip (NewHookVip) NewHookVip is an Xposed module for Android that hooks into target apps to unlock certain membership/VIP features, remove some restrictions,… | 75 | 3696 | active |
| blacktop/ipsw ipsw is a Go-based command-line research framework for downloading, parsing, and analyzing Apple iOS and macOS firmware (IPSW/OTA files), M… | 95 | 3669 | active |
| e-m-b-a/emba EMBA is an open-source firmware security analyzer for embedded Linux devices, written in Bash. It automates firmware extraction, static and… | 93 | 3614 | active |
| Lessica/TrollFools TrollFools is an iOS application for TrollStore that performs in-place tweak injection into installed apps using insert_dylib and ChOma. It… | 74 | 3599 | active |
| java-decompiler/jd-gui JD-GUI is a standalone graphical Java decompiler that displays Java source code reconstructed from .class files. It lets users browse decom… | 23 | 15180 | maintenance |
| icedland/iced iced is a fast and correct x86/x64 (16/32/64-bit) instruction decoder, disassembler, and assembler library with bindings for Rust, .NET, Ja… | 67 | 3556 | active |
| momo5502/sogen Sogen is a C++ userspace emulator that runs Windows and Linux binaries at the CPU and syscall level without a real operating system, execut… | 67 | 3553 | active |
page 1 / 7 next →