function: reverse-engineering
630 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| KasperskyLab/hrtng An IDA Pro plugin (C++) providing a rich toolkit for reverse engineering: string/data decryption, deobfuscation of Hex-Rays pseudocode, unf… | 87 | 1916 | active |
| stevemk14ebr/PolyHook_2_0 PolyHook 2.0 is a C++20 library for hooking functions at runtime on x86 and x64 architectures. It supports multiple hooking techniques (inl… | 73 | 1890 | active |
| federicodotta/Brida Brida is a Burp Suite extension that bridges Burp Suite and Frida, letting testers invoke and manipulate an application's own methods while… | 49 | 1889 | active |
| DerekSelander/LLDB A collection of LLDB aliases, regexes, and Python scripts that extend Apple's LLDB debugger with commands for heap searching, class dumping… | 47 | 1883 | active |
| airbus-seclab/bincat BinCAT is a static binary code analysis toolkit that performs value analysis, taint analysis, type reconstruction, and use-after-free/doubl… | 29 | 1872 | active |
| emsec/ChameleonMini ChameleonMini is a freely programmable, portable NFC device that can emulate and clone contactless smartcards, read RFID tags, and sniff/lo… | 23 | 1869 | active |
| abc123info/BlueTeamTools BlueTeamTools is a Java-based GUI toolbox that aggregates utilities for blue-team security analysts, covering memory-shell decompilation, w… | 91 | 1859 | active |
| chame1eon/jnitrace jnitrace is a Frida-based command-line tool that dynamically traces JNI API calls made by native libraries in Android apps. It works like f… | 23 | 1859 | stable |
| filiksyos/gitreverse GitReverse is a web application that turns any public GitHub repository into a single synthetic prompt that could have been used to vibe-co… | 59 | 1851 | active |
| schemacrawler/SchemaCrawler SchemaCrawler is a free Java-based database schema discovery and comprehension tool that extracts database metadata via JDBC and outputs it… | 99 | 1826 | active |
| HoShiMin/Kernel-Bridge Kernel-Bridge is a C++20 Windows kernel driver template, development framework, and kernel-mode API with wrappers, including a hypervisor s… | 23 | 1822 | active |
| QBDI/QBDI QBDI (QuarkslaB Dynamic binary Instrumentation) is a modular, cross-platform, cross-architecture DBI framework built on LLVM, supporting x8… | 83 | 1815 | active |
| AloneMonkey/MonkeyDev MonkeyDev is an Xcode-integrated framework (an upgraded fork of iOSOpenDev) for developing iOS tweaks and command-line tools using CaptainH… | 32 | 6799 | maintenance |
| marin-m/vmlinux-to-elf A Python CLI (with optional GUI) that recovers a fully analyzable ELF file from raw or stripped Linux kernel images (vmlinux, vmlinuz, bzIm… | 88 | 1805 | stable |
| redasm-dev/redasm REDasm is an open-source disassembler and binary analysis tool with a native Qt6 GUI, supporting many CPU architectures and executable form… | 94 | 1801 | active |
| collin80/SavvyCAN SavvyCAN is a Qt-based cross-platform CAN bus analysis tool for capturing, visualizing, saving, and loading CAN frames. It supports many lo… | 60 | 1782 | active |
| JesusFreke/smali smali/baksmali is an assembler and disassembler for the dex bytecode format used by Android's Dalvik VM. It converts dex files to human-rea… | 10 | 6628 | maintenance |
| pwn20wndstuff/Undecimus Undecimus is the open-source iOS app behind the unc0ver jailbreak, supporting iOS 11.0 through 12.4 on ARM64 devices. It applies kernel and… | 23 | 6621 | maintenance |
| xaitax/Chrome-App-Bound-Encryption-Decryption A Windows post-exploitation research tool that bypasses Chromium's App-Bound Encryption using direct syscall-based reflective process hollo… | 63 | 1762 | active |
| 19MisterX98/SeedcrackerX SeedCrackerX is a Fabric mod for Minecraft that reverse-engineers the world seed of a server from in-game structural and terrain data. It i… | 84 | 1740 | active |
| sigalor/whatsapp-web-reveng A reverse-engineered description and Node.js re-implementation of the WhatsApp Web API, communicating over WebSockets with the same encrypt… | 32 | 6491 | maintenance |
| MatheuZSecurity/Singularity Singularity is a stealthy Linux kernel module (LKM) rootkit targeting modern 6.x kernels, using ftrace-based syscall hooking to hide proces… | 56 | 1736 | active |
| polymorf/findcrypt-yara An IDA Pro plugin that uses YARA rules to scan binaries for known cryptographic constants and other recognizable byte patterns. It helps re… | 32 | 1735 | active |
| revng/revng rev.ng is an open-source binary analysis framework and decompiler built on LLVM and QEMU, supporting over 20 CPU architectures. It automati… | 77 | 1728 | active |
| CodingGay/BlackDex BlackDex is an Android app that unpacks DEX files from installed or uninstalled APKs on Android 5.0-12 without requiring root, Xposed, Frid… | 23 | 6439 | maintenance |
| vfsfitvnm/frida-il2cpp-bridge A Frida module written in TypeScript for dumping, tracing, and hijacking IL2CPP (Unity) applications at runtime without needing the global-… | 93 | 1726 | active |
| cmu-sei/pharos Pharos is a static binary analysis framework from Carnegie Mellon's Software Engineering Institute built on the ROSE compiler infrastructur… | 75 | 1723 | active |
| ev-flow/quark-engine Quark Engine is an Android malware scoring and analysis system that inspects APKs using rule-based behavioral detection on Dalvik bytecode.… | 98 | 1713 | active |
| lasting-yang/frida_hook_libart A collection of Frida hook scripts for intercepting Android ART JNI functions, most notably RegisterNatives. It reveals native method regis… | 54 | 1713 | active |
| hasherezade/tiny_tracer A Pin Tool built on Intel Pin for dynamic binary instrumentation that traces API calls, syscalls, selected instructions, and section transi… | 80 | 1692 | active |
| KeenSecurityLab/BinAbsInspector BinAbsInspector is a static analyzer for automated reverse engineering and vulnerability scanning in binaries, built on abstract interpreta… | 23 | 1672 | active |
| longld/peda PEDA is a Python plugin for GDB that enhances the debugger's display and adds exploit development commands. It provides colorized disassemb… | 23 | 6147 | maintenance |
| 0xdea/frida-scripts A collection of Frida instrumentation scripts for reverse engineering mobile apps and native binaries, including tracers and enumerators fo… | 80 | 1653 | active |
| Air14/HyperHide HyperHide is a hypervisor-based anti-anti-debug plugin for x64dbg/x32dbg that hides debuggers from detection. It uses Intel EPT to hook sys… | 23 | 1652 | active |
| zardus/preeny Preeny is a collection of LD_PRELOAD libraries written in C that help with binary exploitation and CTF-style challenges. It disables functi… | 54 | 1650 | active |
| kefir500/apk-editor-studio APK Editor Studio is a free, open-source, cross-platform GUI tool for reverse-engineering Android APK files, built in C++/Qt. It lets users… | 24 | 1647 | active |
| outtable/confuse-9live A macOS GUI application (distributed as a DMG, not source code) that obfuscates iOS app binaries and resources to bypass App Store review i… | 57 | 1636 | active |
| illera88/Ponce Ponce is an IDA Pro plugin that adds one-click symbolic execution and taint analysis over binaries, built on the Triton engine and written … | 34 | 1627 | active |
| wuba/WBBlades WBBlades is a set of Mach-O based tools for iOS development that detects useless ObjC/Swift classes, protocols, and resources, analyzes pac… | 23 | 1611 | active |
| Jon-Becker/heimdall-rs Heimdall is a Rust-based EVM smart contract toolkit for bytecode analysis, decompilation, disassembly, control flow graph generation, stora… | 89 | 1602 | active |
| pmret/papermario A work-in-progress matching decompilation of Paper Mario for the Nintendo 64, written in C. It rebuilds byte-identical ROMs for the US, JP,… | 77 | 1601 | active |
| horsicq/XELFViewer XELFViewer is a GUI application for viewing and editing ELF (Executable and Linkable Format) binary files on Windows, Linux and macOS. It i… | 67 | 1584 | active |
| attify/firmware-analysis-toolkit Firmware Analysis Toolkit (FAT) is a Python-based automation wrapper around Firmadyne that emulates IoT and embedded device firmware images… | 23 | 1582 | active |
| pret/pokefirered A complete decompilation of Pokémon FireRed and LeafGreen that rebuilds byte-identical GBA ROM images from C source code. It is part of the… | 75 | 1574 | active |
| openblack/openblack openblack is an open-source reimplementation of the Black & White (2001) game engine written in modern C++ with OpenGL and Vulkan rendering… | 66 | 1556 | active |
| AeonLucid/AndroidNativeEmu A Python library that partially emulates Android native (.so) libraries on a host machine using the Unicorn CPU emulator. It emulates the J… | 26 | 1549 | active |
| m4b/goblin Goblin is a Rust library for parsing and loading binary executable formats including ELF, Mach-O, PE, and Unix/BSD archives. It offers zero… | 71 | 1541 | stable |
| igogo-x86/HexRaysPyTools An IDA Pro plugin that enhances the Hex-Rays decompiler workflow. It assists in reconstructing structures and classes, detecting virtual ta… | 32 | 1533 | active |
| sandeco/reversa Reversa is a specification reverse-engineering framework that installs into legacy codebases and coordinates specialized AI agents to analy… | 59 | 1526 | active |
| deathmemory/FridaContainer FridaContainer is a modular collection of popular and custom Frida scripts written in TypeScript to speed up reverse engineering work on An… | 56 | 1512 | active |
| DarthTon/Blackbone Blackbone is a C++ library for Windows memory hacking, providing APIs for process memory manipulation, DLL injection, manual PE image mappi… | 32 | 5479 | maintenance |
| ChendoChap/pOOBs4 A kernel exploit for PlayStation 4 firmware 9.00 that leverages a filesystem (exfat) bug triggered via a specially formatted USB drive, com… | 32 | 1503 | stable |
| T4y1oR/RingQ RingQ is a post-exploitation antivirus evasion tool that obfuscates and loads arbitrary Windows executables or shellcode (e.g., Cobalt Stri… | 27 | 1497 | active |
| dekuNukem/bob_cassette_rewinder An open-source hardware/firmware project that defeats the DRM on Bob dishwasher detergent cassettes, allowing users to reset and refill the… | 32 | 1493 | active |
| Fuzion24/JustTrustMe An Xposed module for rooted Android devices that disables SSL certificate pinning in apps, enabling traffic interception during security au… | 23 | 5361 | maintenance |
| winsiderss/phnt A collection of Windows Native API (NT API) header files for user-mode C/C++ programs, maintained since 2009 for the Process Hacker/System … | 66 | 1463 | active |
| duty1g/x64dbg-mcp-server A native MCP (Model Context Protocol) plugin for x64dbg written in Zig that exposes the debugger's full functionality over HTTP with Stream… | 57 | 1460 | active |
| submato/xhscrawl A Python-based reverse-engineering toolkit for Xiaohongshu (XHS) web APIs, focusing on generating the encrypted x-s signature parameter via… | 72 | 1452 | active |
| ViRb3/magisk-frida A Magisk/KernelSU/APatch module that automatically installs and runs frida-server on boot on rooted Android devices. It stays up to date by… | 93 | 1450 | active |
| ergrelet/unlicense A Python 3 command-line tool that dynamically unpacks executables protected with Themida/WinLicense 2.x and 3.x. It automatically recovers … | 23 | 1450 | active |
| nowsecure/r2frida r2frida is a radare2 plugin that integrates the Frida dynamic instrumentation toolkit, letting users inspect and manipulate local or remote… | 94 | 1434 | active |
| bacher09/pwgen-for-bios A collection of master password generators for various BIOS/UEFI firmware from vendors like Dell, HP, Asus, Samsung, and Sony. It powers th… | 62 | 1433 | active |
| WPeace-HcH/WPeGPT WPeGPT is an IDA Pro plugin that integrates LLM models (OpenAI, DeepSeek, or any OpenAI-compatible API) into binary analysis workflows. It … | 75 | 1418 | active |
| Gezine/Y2JB Y2JB is a PS5 exploit that achieves userland code execution through the console's YouTube app. It supports firmware 4.03+ via a payload del… | 78 | 1412 | active |
| Dryxio/auto-re-agent auto-re-agent is an open-source AI reverse-engineering agent that combines Ghidra binary analysis with LLMs (Claude, Codex, OpenAI-compatib… | 78 | 1410 | active |
| INotGreen/XiebroC2 XiebroC2 is an open-source command-and-control (C2) framework for penetration testing, written in Go with a .NET teamserver. It supports Lu… | 27 | 1391 | active |
| hasherezade/libpeconv libPeConv is a C++ library for loading, manipulating, and dumping Windows PE (Portable Executable) files. It provides a 'swiss army knife' … | 67 | 1385 | active |
| Spuckwaffel/UEDumper UEDumper is a C++ tool that dumps Unreal Engine games (UE 4.19 through 5.3) and generates SDKs, with a live ImGui-based editor for viewing … | 55 | 1380 | active |
| ChiChou/grapefruit Grapefruit is an open-source mobile security testing suite for iOS and Android that provides a browser-based GUI over Frida for runtime ins… | 91 | 1379 | active |
| guidedhacking/GuidedHacking-Injector A C++ DLL injection library supporting x86, WOW64, and x64 injection with five injection methods and six shellcode execution techniques. It… | 32 | 1377 | active |
| ClownQq/YDArk YDArk is a free x64 Windows kernel inspection tool similar to PCHunter, providing GUI views of processes, threads, handles, drivers, kernel… | 32 | 1375 | active |
| hasherezade/exe_to_dll A command-line tool that converts a Windows EXE into a DLL that can be loaded like a library, exporting the original entry point as a 'Star… | 55 | 1373 | stable |
| syssec-utd/pylingual PyLingual is a CPython bytecode decompiler that recovers Python source code from .pyc files for all Python versions since 3.6. It can be ru… | 63 | 1365 | active |
| Morsmalleo/AhMyth AhMyth is a cross-platform Android Remote Administration Tool (RAT) used to build APK payloads and remotely control Android devices through… | 66 | 1364 | active |
| fkie-cad/cwe_checker cwe_checker is a Rust-based suite of checks that detects common bug classes (CWEs) such as null pointer dereferences and buffer overflows i… | 67 | 1352 | active |
| bochs-emu/Bochs Bochs is a portable open-source IA-32 (x86) PC emulator written in C++ that emulates the CPU, common I/O devices, and a custom BIOS. Unlike… | 88 | 1351 | active |
| littleWhiteDuck/SimpleHook SimpleHook is an Xposed/LSPosed module for Android app debugging and research, offering configurable Java/Smali hooking of methods, fields,… | 93 | 1337 | active |
| CERT-Polska/drakvuf-sandbox DRAKVUF Sandbox is an automated, agentless malware analysis system that runs suspicious files inside a hypervisor-level sandbox powered by … | 87 | 1334 | active |
| OpenDriver2/REDRIVER2 A complete open-source C reimplementation of the PlayStation game Driver 2, produced by disassembling and translating the original MIPS cod… | 81 | 1331 | active |
| iGio90/Dwarf Dwarf is a full-featured multi-architecture, multi-OS debugger built on PyQt5 and Frida, aimed at reverse engineers, security analysts, and… | 32 | 1317 | active |
| sharkdp/binocle Binocle is a graphical tool that visualizes binary data by colorizing bytes according to configurable rules and rendering them as pixels in… | 24 | 1317 | stable |
| miscusi-peek/cheatengine-mcp-bridge A bridge that connects AI coding assistants (Claude, Cursor, Copilot) to Cheat Engine via the Model Context Protocol, letting agents read/w… | 60 | 1313 | active |
| CalebFenton/simplify Simplify is a generic Android deobfuscator that virtually executes Dalvik methods in a sandbox (smalivm) and applies optimizations like con… | 23 | 4657 | maintenance |
| Vector35/binaryninja-api The public API, examples, and documentation for Binary Ninja, a commercial reverse engineering platform. It provides C++, Python, and Rust … | 95 | 1303 | active |
| n64decomp/mk64 A complete C decompilation of Mario Kart 64 that rebuilds byte-matching ROMs for USA and European revisions from extracted game assets. It … | 76 | 1292 | active |
| gaasedelen/patching An interactive binary patching plugin for IDA Pro that adds a robust in-disassembler workflow for editing assembly instructions. It support… | 23 | 1279 | active |
| tklengyel/drakvuf DRAKVUF is a virtualization-based, agentless black-box binary analysis system that traces execution of arbitrary binaries, kernels, and fir… | 66 | 1268 | active |
| SychicBoy/NETReactorSlayer NETReactorSlayer is an open-source (GPLv3) deobfuscator and unpacker targeting assemblies protected with Eziriz .NET Reactor. It is availab… | 23 | 1255 | active |
| mamiiblt/instafel Instafel is a modular open-source suite that patches Instagram Alpha APKs to inject custom features, consisting of an Android app UI, an AP… | 70 | 1252 | active |
| relative/synchrony Synchrony is a JavaScript deobfuscator and cleaner focused on undoing obfuscation from javascript-obfuscator/obfuscator.io. It works as a C… | 82 | 1250 | active |
| JetBrains/fernflower Fernflower is an analytical decompiler that converts Java bytecode (class, jar, zip files) back into readable Java source code. It is bundl… | 77 | 4371 | maintenance |
| adolfintel/OpenPods OpenPods is a free and open source Android app that monitors Apple AirPods and Beats headphones over Bluetooth, showing battery and connect… | 46 | 1243 | active |
| paazmaya/shuji Shuji is a Node.js command line utility that reconstructs original JavaScript and CSS source files from sourcemap files (.map), including i… | 77 | 1241 | active |
| rdbo/libmem A cross-platform game hacking library for C, C++, Rust, and Python providing process and memory manipulation, function hooking/detouring, c… | 74 | 1236 | active |
| alexhude/uEmu uEmu is an IDA Pro plugin built on the Unicorn engine that lets you emulate code directly inside the IDA disassembler. It supports x86, x64… | 76 | 1235 | active |
| CensoredUsername/unrpyc Unrpyc is a decompiler that converts compiled Ren'Py .rpyc script files back into readable Ren'Py script source. It can be run as a command… | 72 | 1235 | active |
| horsicq/XPEViewer XPEViewer is a cross-platform GUI application for viewing and editing PE (Portable Executable) files, the executable format used on Windows… | 76 | 1230 | active |
| ThunderCls/xAnalyzer xAnalyzer is a plugin for the x64dbg debugger that performs extended static code analysis on debugged applications. It detects API function… | 51 | 1227 | active |
| cherriesandmochi/gdmaim GDMaim is a Godot Engine plugin that obfuscates all GDScript source code when exporting a project, renaming identifiers, hardcoding constan… | 79 | 1223 | active |
| jxy-s/herpaderping A proof-of-concept tool and technical write-up demonstrating Process Herpaderping, a Windows technique that maps a process image from a fil… | 32 | 1210 | active |