function: reverse-engineering
630 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| wavestone-cdt/EDRSandblast EDRSandBlast is a C-based offensive security tool that weaponizes vulnerable signed drivers to bypass EDR detections on Windows, including … | 32 | 1844 | maintenance |
| ljc545w/ComWeChatRobot A PC WeChat robot implemented in C++ that reverse-engineers the Windows WeChat client to expose contacts, messaging, group management, and … | 10 | 1816 | maintenance |
| lockedbyte/CVE-2021-40444 A proof-of-concept exploit generator for CVE-2021-40444, a Microsoft Office Word remote code execution vulnerability. It generates maliciou… | 32 | 1800 | maintenance |
| gdbinit/Gdbinit A feature-rich .gdbinit configuration script that enhances GDB with custom commands, macros, and a reverse-engineering-oriented interface f… | 32 | 1796 | maintenance |
| tandasat/HyperPlatform HyperPlatform is an Intel VT-x based hypervisor for Windows that provides a thin VM-exit filtering platform for research. It lets researche… | 10 | 1759 | maintenance |
| java-deobfuscator/deobfuscator A Java-based CLI tool that deobfuscates Java JAR files produced by commercial obfuscators such as Zelix KlassMaster, Stringer, Allatori, Da… | 23 | 1756 | maintenance |
| Paisseon/SatellaJailed Satella Jailed is an in-app purchase cracker for non-jailbroken ('jailed') iOS devices running iOS 12–16, distributed as an injectable dyli… | 32 | 1698 | maintenance |
| marin-m/pbtk pbtk (Protobuf toolkit) is a Python-based set of scripts with a unified GUI for extracting Protobuf data structures from programs (Java run… | 99 | 1679 | maintenance |
| PAGalaxyLab/YAHFA YAHFA is a hook framework for Android ART that enables efficient Java method hooking and replacement. It is distributed as an Android libra… | 23 | 1674 | maintenance |
| taviso/ctftool An interactive command-line tool for exploring the CTF (Clipboard/Text Services Framework) protocol used by Windows Text Services. It suppo… | 23 | 1667 | maintenance |
| asLody/whale Whale is a cross-platform hook framework written in C++ that runs on Android, iOS, Linux, and macOS, supporting ARM/THUMB, ARM64, X86, and … | 32 | 1665 | maintenance |
| dpnishant/appmon AppMon is an automated framework for monitoring and tampering with system API calls of native macOS, iOS, and Android apps, built on Frida.… | 10 | 1630 | maintenance |
| dstmath/frida-unpack A Frida-based unpacking tool for Android apps that hooks libart.so's OpenMemory (or OpenCommon on Android 10) to dump decrypted DEX files f… | 44 | 1612 | maintenance |
| shuhongfan/NavicatCracker A keygen and patcher for activating Navicat 16 database client software without a paid license. It patches the installed Navicat binary and… | 32 | 1601 | maintenance |
| Squalr/Squalr-Sharp Squalr is a high-performance memory editor for Windows desktop games, written in C#, supporting memory scanning, pointer scanning, and x86/… | 23 | 1597 | maintenance |
| lelinhtinh/de4js de4js is a web-based JavaScript deobfuscator and unpacker that transforms obfuscated code (Eval, Array, JSFuck, JJencode, AAencode, Packer,… | 10 | 1580 | maintenance |
| mgechev/ngrev ngrev is a graphical Electron application for reverse engineering Angular projects through static code analysis. It visualizes the relation… | 23 | 1576 | maintenance |
| YimMenu/YimMenu YimMenu is a mod menu for Grand Theft Auto V that protects players against common public crashes and adds gameplay enhancements, including … | 10 | 1569 | maintenance |
| gaasedelen/tenet Tenet is an IDA Pro plugin for exploring and navigating execution traces of binaries. It provides a timeline widget and bidirectional execu… | 23 | 1545 | maintenance |
| AsuharietYgvar/AppleNeuralHash2ONNX A Python tool that converts Apple's NeuralHash perceptual hashing model (used in Apple's CSAM Detection system) into ONNX format. It includ… | 32 | 1534 | maintenance |
| maderix/ANE A research project demonstrating backpropagation and neural network training directly on Apple's Neural Engine using reverse-engineered pri… | 47 | 7253 | experimental |
| chip-red-pill/MicrocodeDecryptor A set of Python scripts for decrypting Intel Atom CPU microcode updates, using encryption keys extracted via the Red Unlock debugging techn… | 32 | 1510 | maintenance |
| WooyunDota/DroidSSLUnpinning A collection of Frida hook scripts (ObjectionUnpinningPlus) that bypass Android certificate pinning so HTTPS traffic can be intercepted wit… | 32 | 1509 | maintenance |
| ViRb3/TrustMeAlready An Xposed module for rooted Android devices that disables SSL certificate verification and pinning system-wide. It hooks Java trust-check m… | 10 | 1508 | maintenance |
| ChiChou/bagbak bagbak is a Node.js CLI tool that uses Frida to decrypt iOS App Store binaries on a jailbroken device, dumping decrypted IPAs including app… | 90 | 1494 | maintenance |
| ezshine/wxapkg-convertor A Node.js command-line tool that decompiles WeChat mini-program and mini-game .wxapkg packages back into readable source code, convertible … | 23 | 1491 | maintenance |
| CYRUS-STUDIO/ApkToolPlus ApkToolPlus is a visual, cross-platform desktop application for Android APK reverse analysis built in Java. It bundles APK decompilation/re… | 40 | 1476 | maintenance |
| nccgroup/house House is a runtime mobile application analysis toolkit with a web GUI, powered by Frida and written in Python. It simplifies dynamic functi… | 32 | 1463 | maintenance |
| ptswarm/reFlutter A Python-based framework that repacks Flutter Android and iOS apps with a patched Flutter engine library to enable dynamic analysis. It red… | 10 | 1463 | maintenance |
| programa-stic/barf-project BARF is an open-source Python framework for binary analysis and reverse engineering. It lifts instructions from x86 and ARM binaries into a… | 32 | 1452 | maintenance |
| L4ys/LazyIDA LazyIDA is an IDA Pro plugin written in Python (IDAPython) that adds convenience features like data format conversion with clipboard copy, … | 62 | 1439 | maintenance |
| 易开发 (DeveloperHelper) DeveloperHelper (易开发) is an Android developer/analysis tool app with an Xposed module that dumps DEX files from packed (hardened) APKs, plu… | 39 | 1419 | maintenance |
| NtQuery/Scylla Scylla is a Windows x86/x64 tool for reconstructing import tables (IAT) of unpacked or dumped binaries. It supports dumping processes, fixi… | 23 | 1418 | maintenance |
| 0xnobody/vmpdump VMPDump is a dynamic dumper and import fixer for binaries protected with VMProtect 3.x (x64), built on the VTIL intermediate language. It s… | 23 | 1412 | maintenance |
| LinusHenze/Fugu14 Fugu14 is an untethered jailbreak for iOS 14.3-14.5.1 targeting arm64e devices, including a kernel exploit, PAC bypass, PPL bypass, and boo… | 10 | 1410 | maintenance |
| ele7enxxh/Android-Inline-Hook A C library for inline hooking of native functions on 32-bit Android, supporting ARM, Thumb16, and Thumb32 instruction sets. It lets you re… | 32 | 1401 | maintenance |
| tandasat/DdiMon DdiMon is a hypervisor-based research tool that performs stealth inline hooking of Windows kernel API calls using Intel VT-x EPT memory sha… | 32 | 1398 | maintenance |
| 0xgalz/Virtuailor Virtuailor is an IDAPython plugin for IDA Pro that reconstructs C++ virtual tables (vtables) for Intel x86/x64 and AArch64 binaries. It com… | 32 | 1395 | maintenance |
| NytroRST/NetRipper NetRipper is a Windows post-exploitation tool that uses API hooking to intercept network traffic, capturing both plain-text and encrypted d… | 32 | 1390 | maintenance |
| ma1co/OpenMemories-Tweak An Android app that runs on Sony cameras supporting PlayMemories Camera Apps to unlock hidden settings such as the 30-minute video recordin… | 23 | 1390 | maintenance |
| grayhatacademy/ida A collection of IDA Python plugins, scripts, and modules for the IDA Pro disassembler. It provides reusable tooling for binary analysis and… | 32 | 1368 | maintenance |
| cr4n5/XiaoYuanKouSuan A Python-based automation tool that cheats at the XiaoYuanKouSuan (小猿口算) math app by capturing packets to obtain answers and using ADB to s… | 22 | 1346 | maintenance |
| gdabah/distorm diStorm3 is a lightweight, fast disassembler library for x86/AMD64 machine code, licensed under BSD. It acts as a decomposer, returning bin… | 23 | 1345 | maintenance |
| wbenny/hvpp hvpp is a lightweight Intel VT-x hypervisor written in modern C++ that virtualizes an already-running operating system, primarily targeting… | 32 | 1344 | maintenance |
| Cherrison/CrackMinApp A Windows GUI tool (built with C# and Node.js) that one-click decompiles WeChat mini-program .wxapkg packages back into readable source cod… | 32 | 1344 | maintenance |
| blackberry/pe_tree PE Tree is a Python module and standalone GUI application for viewing Portable Executable (PE) files in a tree-view, built on pefile and Py… | 10 | 1343 | maintenance |
| fkzhang/WechatUnrecalled An Android plugin that prevents WeChat from recalling chat messages and Moments (SNS) replies, built via hooking. It is no longer open sour… | 23 | 1338 | maintenance |
| tobefuturer/restore-symbol A command-line reverse engineering tool that restores stripped Objective-C symbol tables in iOS Mach-O binaries. It injects OC method and b… | 32 | 1337 | maintenance |
| Cur10s1tyByt3/GenP An archival repository preserving the source materials and documentation of GenP, an AutoIt-based patcher tool targeting Adobe software on … | 57 | 1327 | maintenance |
| myzxcg/RealBlindingEDR A Windows offensive security tool that uses arbitrary kernel read/write via a signed driver to remove AV/EDR kernel callbacks (ObRegisterCa… | 18 | 1324 | maintenance |
| RUB-SysSec/DroneSecurity A proof-of-concept receiver and decoder for DJI's Drone-ID protocol broadcast over OcuSync 2.0, developed for an NDSS 2023 paper. It decode… | 31 | 1309 | maintenance |
| wbenny/injdrv A proof-of-concept Windows kernel driver that injects DLLs into user-mode processes using Asynchronous Procedure Calls (APC). It hooks into… | 32 | 1296 | maintenance |
| med0x2e/SigFlip SigFlip is a red-team tool for patching Authenticode-signed PE files (exe, dll, sys) without invalidating their existing signatures, by emb… | 32 | 1290 | maintenance |
| alexzielenski/optool A command line tool for modifying Mach-O binaries on macOS and iOS. It can insert or remove load commands, strip or repair code signatures,… | 23 | 1287 | maintenance |
| rocky/python-decompile3 decompyle3 is a native Python decompiler that translates Python bytecode (versions 3.7 and 3.8) back into equivalent Python source code. It… | 68 | 1269 | maintenance |
| darkr4y/geacon Geacon is a Go implementation of CobaltStrike's Beacon implant, built to study the C2 protocol through reverse engineering. It supports com… | 32 | 1266 | maintenance |
| 0xjiayu/go_parser An IDA Pro plugin written in Python that parses Golang binaries, recovering function names, source file paths, strings, types, and interfac… | 23 | 1255 | maintenance |
| MinhasKamal/TrojanCockroach Trojan Cockroach is an educational C++ trojan spyware that logs keystrokes on Windows PCs, exfiltrates the stolen data via email, and sprea… | 54 | 1243 | maintenance |
| mgeeky/ThreadStackSpoofer A proof-of-concept C++ implementation of thread call stack spoofing, an in-memory evasion technique that hides shellcode references from a … | 23 | 1242 | maintenance |
| codilime/veles Veles is a cross-platform desktop tool for binary data analysis that uses statistical visualizations to reveal patterns in large binary fil… | 10 | 1239 | maintenance |
| gaffe23/linux-inject A command-line tool written in C that injects a shared object (.so) into a running Linux process using ptrace(), analogous to CreateRemoteT… | 32 | 1238 | maintenance |
| DerekSelander/dsdump dsdump is a command-line tool that inspects Mach-O binaries, dumping symbol tables plus Objective-C classes and Swift type descriptors, act… | 10 | 1226 | maintenance |
| AndroBugs/AndroBugs_Framework AndroBugs Framework is a command-line Android vulnerability scanner that analyzes APK files to find potential security vulnerabilities and … | 10 | 1224 | maintenance |
| am0nsec/HellsGate The original C implementation of the Hell's Gate technique, which resolves Windows system call numbers at runtime to invoke NT APIs directl… | 32 | 1220 | maintenance |
| softScheck/tplink-smartplug A Python command-line client for the proprietary TP-Link Smart Home protocol that controls HS100, HS110, and KP115 WiFi smart plugs over TC… | 32 | 1200 | maintenance |
| bats3c/DarkLoadLibrary DarkLoadLibrary is a C library implementing an alternative to the Windows LoadLibrary API designed for offensive security operations. It lo… | 32 | 1188 | maintenance |
| strazzere/android-unpacker A collection of Android unpacking tools presented at Defcon 22, including gdb-based scripts and a native unpacker for packers like APKProte… | 23 | 1178 | maintenance |
| yangyangwithgnu/bypass_disablefunc_via_LD_PRELOAD A small PHP exploit script plus compiled shared object that bypasses PHP's disable_functions restriction to execute OS commands via LD_PREL… | 32 | 1171 | maintenance |
| sh4hin/Androl4b AndroL4b is an Ubuntu MATE-based virtual machine preloaded with Android security, reverse engineering, and malware analysis tools such as R… | 32 | 1166 | maintenance |
| siyujie/OkHttpLogger-Frida A Frida script that hooks OkHttp's RealCall class in Android apps to intercept and log HTTP requests and responses, including headers and b… | 32 | 1166 | maintenance |
| ghidraninja/ghidra_scripts A collection of scripts for the Ghidra software reverse engineering suite, adding features like crypto constant detection via YARA, binwalk… | 32 | 1165 | maintenance |
| master131/ExtremeInjector A Windows GUI tool for injecting DLLs into running processes, supporting multiple injection methods such as manual mapping, thread hijackin… | 23 | 1165 | maintenance |
| crypto2011/IDR IDR (Interactive Delphi Reconstructor) is a Windows decompiler for EXE and DLL files compiled with Delphi 2 through Delphi XE4. It performs… | 23 | 1154 | maintenance |
| pinauten/Fugu15 Fugu15 is a semi-untethered, permasigned jailbreak for iOS 15 that combines a code-signing bypass, kernel exploit, kernel PAC bypass, and P… | 10 | 1145 | maintenance |
| FuzzySecurity/Sharp-Suite Sharp-Suite is a collection of C# security tooling samples for Windows threat emulation, including techniques like process command-line spo… | 32 | 1144 | maintenance |
| Sentinel-One/CobaltStrikeParser A Python parser that extracts Cobalt Strike Beacon configuration from stageless PE files, memory dumps, or C2 URLs. It heuristically finds … | 10 | 1138 | maintenance |
| anestisb/vdexExtractor A command-line tool written in C that decompiles and extracts Android Dex bytecode from Vdex files produced by the ART runtime's dex2oat co… | 32 | 1135 | maintenance |
| gianlucaborello/libprocesshider A small shared library that hides a specified process from tools like ps and lsof on Linux by hooking libc functions via the ld.so preloade… | 32 | 1130 | maintenance |
| sharpemu/sharpemu SharpEmu is an experimental PlayStation 5 emulator written from scratch in C#, distributed as a single binary that works as both a desktop … | 77 | 5082 | experimental |
| mildsunrise/protobuf-inspector A Python CLI tool that parses Google Protobuf encoded blobs (wire format 2 or 3) without knowing their schema definition, printing a colore… | 32 | 1125 | maintenance |
| decalage2/ViperMonkey ViperMonkey is a VBA parser and emulation engine written in Python for analyzing and deobfuscating malicious macros in Microsoft Office doc… | 32 | 1124 | maintenance |
| mohuihui/antispy AntiSpy is a free Windows anti-rootkit and antivirus toolkit that detects, analyzes, and restores kernel modifications and hooks with the h… | 23 | 1109 | maintenance |
| CTCaer/jc_toolkit A Windows desktop application for managing, inspecting, and customizing Nintendo Switch Joy-Con controllers over Bluetooth HID. It provides… | 23 | 1101 | maintenance |
| sibears/IDAGolangHelper A set of IDA Pro Python scripts that parse Go type information embedded in compiled Go binaries and register the recovered types inside IDA… | 32 | 1092 | maintenance |
| Accenture/Spartacus Spartacus is a Windows toolkit that automates discovery and exploitation of DLL and COM hijacking vulnerabilities by parsing Process Monito… | 10 | 1085 | maintenance |
| mmozeiko/aes-finder A small C++ command-line utility that scans the memory of running processes to locate AES encryption and decryption keys (128, 192, and 256… | 32 | 1083 | maintenance |
| vmt/udis86 Udis86 is a C library (libudis86) for disassembling x86 and x86-64 machine code, decoding raw binary streams into structured instructions w… | 32 | 1080 | maintenance |
| xdmjun/mp-unpack A tool for unpacking WeChat mini-program packages (wxapkg files) to recover readable source code. It appears to be a reverse-engineering ut… | 32 | 1079 | maintenance |
| silverf0x/RpcView RpcView is a free, open-source Windows GUI tool for exploring and decompiling Microsoft RPC (Remote Procedure Call) interfaces present on a… | 23 | 1070 | maintenance |
| asLody/SandVXposed SandVXposed combines VirtualApp's app virtualization with the SandHook hooking framework to run Xposed modules on Android without root acce… | 23 | 1056 | maintenance |
| wwh1004/ExtremeDumper A Windows GUI tool for dumping .NET assemblies from running processes, including bypassing anti-dump protections. It can also inject .NET a… | 23 | 1054 | maintenance |
| btbd/access A Windows kernel driver plus DLL wrapper that lets a usermode process perform privileged operations on protected processes without creating… | 32 | 1053 | maintenance |
| itenfay/WeChat_tweak An iOS tweak (plugin) for WeChat written in Objective-C that adds features like auto-grabbing red envelopes, blocking messages, preventing … | 70 | 1052 | maintenance |
| sonyxperiadev/ApkAnalyser ApkAnalyser is a stand-alone Java (J2SE) GUI tool for static and virtual analysis of Android APK files. It supports disassembling and modif… | 10 | 1047 | maintenance |
| fangshufeng/MachOView MachOView is a macOS GUI application for browsing and analyzing Mach-O binary files, a maintained fork of the original gdbinit/MachOView th… | 23 | 1046 | maintenance |
| KULeuven-COSIC/Starlink-FI A research project from KU Leuven COSIC providing the design of a custom modchip that performs voltage fault injection to bypass signature … | 32 | 1044 | maintenance |
| eveem-org/panoramix Panoramix is a Python-based decompiler that converts Ethereum smart contract bytecode into readable pseudocode, powering the Eveem.org serv… | 32 | 1042 | maintenance |
| 9176324/Shark Shark is a Windows kernel driver project written in C that disables Kernel Patch Protection (PatchGuard) in real time on Windows 7 (7600) a… | 23 | 1042 | maintenance |
| x0tools/WeChatOpenDevTools A Windows tool that patches WeChat to enable the built-in DevTools (F12) for debugging WeChat Official Accounts and Mini Programs. It suppo… | 27 | 1041 | maintenance |
| adi0x90/attifyos Attify OS is a Linux distribution based on Ubuntu 18.04 pre-configured with tools for security assessment and penetration testing of IoT de… | 32 | 1037 | maintenance |