function: reverse-engineering
630 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| cv-cat/XianYuApis A reverse-engineered unofficial API library for Xianyu (Goofish, Alibaba's second-hand marketplace) that wraps its HTTP endpoints and WebSo… | 79 | 1206 | active |
| x64dbg/GleeBug GleeBug is a debugging framework for Windows written in C, designed to make building debuggers and debugging tools complete and easy to use… | 76 | 1201 | active |
| zetaloop/BetterWX A set of Python patch scripts for WeChat PC 4.0 on Windows x64 that enable anti-revoke (message recall prevention with notice), multi-insta… | 33 | 1201 | active |
| petoolse/petools PE Tools is a Windows GUI toolkit for researching and manipulating Portable Executable (PE) files and running processes. It bundles a PE he… | 44 | 1197 | active |
| P3GLEG/Whaler Whaler is a Go CLI tool that reverse engineers Docker images back into the Dockerfiles that created them. It also extracts files added via … | 57 | 1192 | active |
| hamishcoleman/thinkpad-ec A Linux command-line toolkit for extracting, examining, and patching ThinkPad xx30-series embedded controller (EC) firmware. Its main purpo… | 42 | 1192 | active |
| goretk/redress Redress is a command-line tool for analyzing stripped Go binaries, reconstructing symbols and extracting information such as compiler versi… | 94 | 1186 | active |
| yazgx97/frida-ios-hook A Python/JavaScript CLI tool that wraps Frida to make it easy to trace classes and functions, hook methods, and modify return values on iOS… | 69 | 1183 | active |
| YosysHQ/icestorm Project IceStorm documents the reverse-engineered bitstream format of Lattice iCE40 FPGAs and provides tools for analyzing and creating bit… | 57 | 1182 | active |
| dethrace-labs/dethrace Dethrace is an open-source reverse-engineering project that rebuilds the 1997 driving/mayhem game Carmageddon to run natively on modern sys… | 81 | 1181 | active |
| tiltedphoques/TiltedEvolution Tilted Online (Skyrim Together) is a C++ framework that adds online multiplayer to Bethesda games, currently supporting Skyrim Special Edit… | 77 | 1180 | active |
| geohot/qira QIRA is a QEMU-based interactive runtime analyser that traces program execution and presents it in a web UI, acting as a competitor to stra… | 23 | 4070 | maintenance |
| reversenseorg/dexcalibur Reversense (Dexcalibur 2) is a binary intelligence platform that automates reverse engineering of mobile and embedded applications. It comb… | 68 | 1168 | active |
| nccgroup/Sniffle Sniffle is an open-source sniffer for Bluetooth 5 and 4.x LE that runs on TI CC1352/CC26x2 hardware with a Python host-side tool. It captur… | 42 | 1164 | active |
| P1sec/hermes-dec hermes-dec is a Python-based reverse engineering tool that disassembles and decompiles React Native applications compiled to the Hermes VM … | 98 | 1156 | active |
| WhiteNightShadow/hello_js_reverse_skill An AI-powered 'Skill' package for JavaScript reverse engineering that plugs into AI coding tools like Claude Code, Cursor, and Codex. It pr… | 78 | 1156 | active |
| naim94a/lumen Lumen is a self-hosted, open-source replacement for Hex-Rays' Lumina server that stores and shares IDA Pro function signatures, comments, a… | 67 | 1151 | active |
| ben-sb/javascript-deobfuscator A general-purpose JavaScript deobfuscator that removes common obfuscation techniques such as array unpacking, proxy functions, expression o… | 46 | 1149 | active |
| ichason/CPosed CPosed is an Android hooking framework forked from LSPosed that enables Xposed-style module injection on rooted devices running Android 8.1… | 47 | 1148 | active |
| JusticeRage/Manalyze Manalyze is a static analyzer for PE (Windows executable) files written in C++. It performs primary malware assessment by parsing PE struct… | 87 | 1145 | active |
| ExeinfoASL/ASL Exeinfo Pe is a free Windows GUI tool that detects packers, protectors, compilers, .NET obfuscators, and packed binary data formats in PE e… | 93 | 1142 | active |
| GJDuck/e9patch E9Patch is a static binary rewriting tool for x86_64 Linux ELF executables and shared objects, producing patched binaries that work as drop… | 83 | 1137 | active |
| AloneMonkey/frida-ios-dump A Python CLI script that uses Frida to dump decrypted iOS app binaries from a jailbroken device and packages them into an IPA. It connects … | 32 | 3921 | maintenance |
| greatscottgadgets/luna LUNA is an Amaranth HDL (Python) framework providing FPGA gateware and software for working with USB, from passive protocol analysis to bui… | 75 | 1133 | active |
| david942j/seccomp-tools A Ruby-based CLI toolkit for analyzing seccomp BPF filters, supporting dumping, disassembling, assembling, emulating, and auditing seccomp … | 88 | 1132 | active |
| mrphrazer/reverser_ai ReverserAI is a Binary Ninja plugin that provides automated reverse engineering assistance using locally-hosted large language models runni… | 68 | 1127 | active |
| REhints/efiXplorer efiXplorer is an IDA Pro plugin and loader that automates static analysis of UEFI firmware. It recovers EFI service function calls, identif… | 90 | 1125 | active |
| CodingGay/BlackObfuscator BlackObfuscator is a Java-based obfuscator for Android DEX files that applies control flow flattening to make decompiled code hard to analy… | 31 | 1123 | active |
| Endermanch/XPKeygen A C++ tool that generates valid Windows XP and Windows Server 2003 VLK product keys from a raw product key, based on reverse-engineered ell… | 62 | 1122 | active |
| Washi1337/AsmResolver AsmResolver is a .NET library for reading, modifying, and writing Portable Executable (PE) files, including those with .NET metadata. It pr… | 94 | 1117 | active |
| luoyesiqiu/dpt-shell dpt-shell is an Android Dex protection shell that hollows out DEX method implementations and reconstructs them at runtime to protect APK/AA… | 100 | 1115 | active |
| KJCracks/Clutch Clutch is a fast iOS executable decryption and dumping tool that extracts decrypted binaries and .ipa files from installed apps on jailbrok… | 23 | 3824 | maintenance |
| TheOfficialFloW/h-encore h-encore is a fully chained kernel exploit (jailbreak) for the PlayStation Vita on firmwares 3.65-3.68. It enables kernel and user modifica… | 23 | 1108 | stable |
| moshowgame/Navicat_Keygen_Patch A collection of keygen, patch, and trial-reset tools for bypassing activation of Navicat database client versions 15-17, distributed as DLL… | 47 | 1105 | active |
| jwping/wxbot A Go-based WeChat hook/robot framework that injects into the Windows PC WeChat client (specific versions 3.9.8.x) to expose a bot API, runn… | 27 | 1099 | active |
| SteamTracking/SteamTracking A project that tracks and reverse-engineers Steam and Valve data, including protobuf definitions and changes across Steam services. It moni… | 77 | 1095 | active |
| wisk/medusa Medusa is an open-source, modular, interactive disassembler written in C++, organized as a library with frontends including a GUI (qMedusa)… | 57 | 1090 | active |
| bkerler/mtkclient A Python utility for exploiting, reading, and writing flash memory on MediaTek (MTK) smartphones via the BootROM or preloader. It supports … | 72 | 1088 | active |
| amruth-sn/kong Kong is an LLM-orchestrated reverse engineering CLI that plugs AI into Ghidra's analysis engine to recover function names, types, and struc… | 63 | 1087 | active |
| memflow/memflow memflow is a Rust library providing a modular framework for physical memory introspection of machines, including live hardware, virtual mac… | 58 | 1087 | active |
| bitdefender/bddisasm bddisasm is a fast, lightweight x86/x64 instruction decoder library written in C with no external dependencies, no memory allocation, and t… | 74 | 1084 | active |
| HZJQF/help_tool A PyQt5-based Windows GUI tool that uses inference models to identify the encryption or hashing algorithm behind a given ciphertext and att… | 24 | 1083 | active |
| gorisanson/pikachu-volleyball A browser-based reimplementation of the 1997 Windows game Pikachu Volleyball, created by reverse engineering the original machine code (phy… | 71 | 1080 | active |
| mandiant/GoReSym GoReSym is a cross-platform CLI tool that extracts symbols, function metadata, types, and program metadata from Go binaries, including stri… | 91 | 1069 | active |
| nathanlopez/Stitch Stitch is a cross-platform Python Remote Administration Tool (RAT) framework for building custom payloads for Windows, macOS, and Linux. It… | 32 | 3660 | maintenance |
| RuntimeBrowser RuntimeBrowser is a class browser for the Objective-C runtime on iOS and OS X that exposes all loaded classes, methods, and dynamically gen… | 70 | 3658 | maintenance |
| QQBackup/qq-win-db-key A collection of Python and Frida scripts for extracting database encryption keys from QQ (Tencent's messenger) across Windows, Linux, macOS… | 72 | 1064 | active |
| lico-n/ZygiskFrida A Zygisk (and Riru) module for rooted Android devices that injects the Frida gadget into application processes in a stealthy manner. It avo… | 52 | 1063 | active |
| theapache64/stackzy Stackzy is a cross-platform desktop application built with Compose Desktop that identifies the libraries used inside an Android APK. It dec… | 71 | 1062 | active |
| Xeeynamo/sotn-decomp A matching decompilation project recreating the C source code of Castlevania: Symphony of the Night from its original binaries for PS1, PSP… | 68 | 1062 | active |
| ZeroMemoryEx/Chaos-Rootkit Chaos-Rootkit is an x64 Ring 0 Windows kernel rootkit written in C++ as a research project to understand kernel internals and rootkit techn… | 58 | 1061 | active |
| MatthewKuKanich/CAN_Commander CAN Commander is a tool for reverse engineering and analyzing CAN bus systems, pairing a Flipper Zero app with ESP32 firmware to interact w… | 63 | 1059 | active |
| hyugogirubato/KeyDive KeyDive is a Python CLI tool that extracts Widevine L3 DRM keys and device credentials from rooted Android devices using Frida instrumentat… | 80 | 1058 | active |
| echo094/decode-js A Node.js CLI tool built on Babel that analyzes and reverses obfuscated JavaScript back into readable source. It supports common obfuscatio… | 77 | 1054 | active |
| nygard/class-dump class-dump is a command-line utility that examines the Objective-C runtime information in Mach-O binaries and generates Objective-C header … | 23 | 3585 | maintenance |
| apkunpacker/MagiskDetection A curated collection of publicly available proof-of-concept Android apps that detect root, Magisk, Zygisk, and hooking frameworks like Frid… | 68 | 1050 | active |
| paradiseduo/appdecrypt A Swift CLI tool that decrypts FairPlay-encrypted Mach-O application binaries on macOS (SIP-enabled, macOS 11.3 or below, with newer suppor… | 56 | 1046 | active |
| amlweems/xzbot A research toolkit for the xz backdoor (CVE-2024-3094) containing an OpenSSH honeypot patch to detect exploit attempts, a patch script to r… | 25 | 3554 | maintenance |
| mitmproxy/android-unpinner A Python CLI tool that removes certificate pinning from Android APKs so traffic can be intercepted with mitmproxy, without requiring a root… | 54 | 1032 | active |
| kyleavery/AceLdr AceLdr is a position-independent reflective loader (UDRL) for Cobalt Strike written in C, designed to evade memory scanners like Moneta, PE… | 23 | 1031 | active |
| Vuemony/vue-after-free A PlayStation 4 userland code execution exploit delivered through the PlayStation Vue app, chained with kernel exploits (Lapse, Poopsploit/… | 67 | 1029 | active |
| danielweidman/pixmob-ir-reverse-engineering A reverse-engineering project and Python tooling for the PixMob infrared (and RF) protocol used by LED wristbands at large events, enabling… | 62 | 1028 | active |
| Reloaded-Project/Reloaded-II Reloaded II is a universal, C#/.NET-based mod loader and mod management framework for native games on X86 and X64. It uses DLL injection to… | 97 | 1016 | active |
| Spade-sec/First A WeChat mini-program security debugging tool (fork/extension of WMPFDebugger) that uses Frida injection and Chrome DevTools Protocol bridg… | 74 | 1015 | active |
| secretsquirrel/the-backdoor-factory The Backdoor Factory (BDF) is a Python command-line tool that patches Windows PE, Linux ELF, and macOS Mach-O executables with user-supplie… | 32 | 3439 | maintenance |
| gcarmix/HexWalk HexWalk is a cross-platform GUI hex editor, viewer, and binary analyzer built on qhexedit2, Capstone, and Qt. It combines hex editing with … | 84 | 1011 | active |
| indetectables-net/toolkit A curated Windows toolkit bundling 101 applications for reverse engineering, malware analysis, and cracking, installed via an automated Inn… | 89 | 1009 | active |
| LuckyPray/DexKit DexKit is a high-performance dex parsing and deobfuscation library implemented in C++ with Kotlin bindings, used to locate obfuscated class… | 87 | 1008 | active |
| RuoJi6/audit-skills A lightweight Claude/Codex skill package for AI-assisted source code security auditing, covering Java, .NET, and PHP. It provides vulnerabi… | 73 | 1005 | active |
| stephenfewer/ReflectiveDLLInjection A C library implementing reflective DLL injection, a technique for loading a library from memory into a host Windows process without touchi… | 32 | 3343 | maintenance |
| nabla-c0d3/ssl-kill-switch2 SSL Kill Switch 2 is a blackbox Cydia Substrate tweak that disables SSL/TLS certificate validation, including certificate pinning, in iOS a… | 23 | 3311 | maintenance |
| EasyHook/EasyHook EasyHook is a Windows API hooking library that lets you intercept and extend unmanaged code APIs with managed (.NET) or native hook handler… | 23 | 3292 | maintenance |
| morkt/GARbro GARbro is a Windows GUI application for browsing, extracting, and converting resources (archives, images, audio) from visual novel games. I… | 23 | 3263 | maintenance |
| caj2pdf/caj2pdf A Python CLI tool that converts CNKI's proprietary CAJ document files into PDFs while preserving selectable text and outline information. I… | 32 | 3226 | maintenance |
| plasma-disassembler/plasma Plasma is an interactive disassembler for x86/x86-64, ARM, and MIPS binaries that generates indented pseudo-code with colored syntax. It su… | 32 | 3072 | maintenance |
| WindySha/Xpatch Xpatch is a Java CLI tool that repackages and re-signs Android APK files so the resulting APK can load installed Xposed modules. It enables… | 50 | 3057 | maintenance |
| NYAN-x-CAT/AsyncRAT-C-Sharp AsyncRAT is an open-source Remote Access Tool (RAT) written in C# that lets an operator remotely monitor and control Windows client machine… | 23 | 3008 | maintenance |
| ac-pm/Inspeckage Inspeckage is an Xposed module that performs dynamic analysis of Android applications by hooking Android API functions to observe runtime b… | 23 | 2982 | maintenance |
| Jermic/Android-Crack-Tool A macOS GUI application that bundles common Android APK reverse-engineering tools (Apktool, Dex2Jar, JD-GUI, SignApk, Zipalign) into one in… | 23 | 2942 | maintenance |
| tiagorlampert/CHAOS CHAOS is a free and open-source Remote Administration Tool written in Go that generates cross-platform binaries (Windows and Linux) for con… | 23 | 2830 | maintenance |
| lifting-bits/mcsema McSema is a framework that lifts native x86, amd64, aarch64, sparc32, and sparc64 executable binaries (ELF and PE) into LLVM bitcode. It wo… | 10 | 2787 | maintenance |
| ma1co/Sony-PMCA-RE A tool that interfaces with Sony digital cameras over USB to tweak settings, dump firmware, and install custom Android apps via the PlayMem… | 23 | 2777 | maintenance |
| google/enjarify Enjarify is a Python 3 tool that translates Dalvik bytecode from Android APK/DEX files into equivalent Java bytecode (JAR), enabling Java a… | 10 | 2747 | maintenance |
| hanbinglengyue/FART FART is an automated Android app unpacking (dex dumping) tool for ART environments, based on active invocation, implemented on Android 6.0/… | 33 | 2724 | maintenance |
| leibnitz27/cfr CFR (Class File Reader) is a Java decompiler written entirely in Java 6 that can decompile modern Java bytecode, including features from Ja… | 61 | 2675 | maintenance |
| everdox/InfinityHook InfinityHook is a Windows kernel library that hooks system calls, context switches, page faults, and DPCs by abusing ETW trace mechanics, r… | 32 | 2673 | maintenance |
| y9nhjy/Proxifier-Keygen A Python CLI keygen that generates registration keys for Proxifier (setup, portable, and Mac variants), based on a reverse-engineering anal… | 28 | 2664 | maintenance |
| DarthTon/Xenos Xenos is a Windows DLL injector built on the Blackbone library, supporting x86/x64 processes, manual image mapping, managed image injection… | 23 | 2645 | maintenance |
| xoreaxeaxeax/rosenbridge Rosenbridge is a security research project that documents a hardware backdoor in some VIA C3 x86 processors, allowing userland code to bypa… | 32 | 2614 | maintenance |
| seemoo-lab/openhaystack OpenHaystack is a framework and macOS application for creating custom Bluetooth tracking tags that leverage Apple's Find My (offline findin… | 67 | 13467 | experimental |
| xdmjun/wxappUnpacker wxappUnpacker is a Node.js tool that unpacks and decompiles WeChat mini-program packages (.wxapkg files), restoring WXML, WXSS, JS, and con… | 32 | 2430 | maintenance |
| dana-at-cp/backdoor-apk A shell script that automates injecting a Metasploit backdoor payload into any Android APK by decompiling, hooking smali code, and re-signi… | 32 | 2367 | maintenance |
| retroplasma/earth-reverse-engineering A reverse-engineering project documenting and implementing access to Google Earth's undocumented 3D satellite mode, including URL structure… | 10 | 2322 | maintenance |
| buginux/WeChatRedEnvelop An iOS jailbreak tweak (Cydia plugin) written in Objective-C that automatically grabs red envelopes (lucky money) in WeChat. It integrates … | 10 | 2292 | maintenance |
| ldpreload/BlackLotus An open-source UEFI bootkit targeting Windows that implements a Secure Boot bypass, kernel-level persistence, and an HTTP-based C2 loader w… | 29 | 2240 | maintenance |
| JKornev/hidden A Windows kernel driver with a usermode library and CLI that can hide processes, files, directories, and registry keys, and protect process… | 23 | 2051 | maintenance |
| weak1337/Alcatraz Alcatraz is a GUI-based x64 binary obfuscator for Windows PE files (.exe, .dll, .sys) written in C++. It applies transformations like contr… | 31 | 1993 | maintenance |
| corelan/mona mona.py is a Python plugin for debuggers (Immunity Debugger, x64dbg) that assists with exploit development tasks such as finding ROP gadget… | 10 | 1888 | maintenance |
| cobbr/SharpSploit SharpSploit is a .NET post-exploitation library written in C# that highlights the .NET attack surface for red teamers. It ports and extends… | 32 | 1884 | maintenance |
| glmcdona/Process-Dump Process Dump is a Windows command-line reverse-engineering tool that dumps unpacked malware PE files and loose code chunks from process mem… | 23 | 1852 | maintenance |