Skip to content
Change the repository type filter

All

    Repositories list

    • XProtect Remediator "secret" configurations
      0100Updated Aug 14, 2025Aug 14, 2025
    • Python
      13000Updated Aug 4, 2025Aug 4, 2025
    • A collection of scripts and documents to help future XProtect Remediator (XPR) research
      C++
      1300Updated Jul 22, 2025Jul 22, 2025
    • ShadeBIOS

      Public
      PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025
      C
      74000Updated Jul 16, 2025Jul 16, 2025
    • A tool to show the provenance information of a file or directory
      Swift
      0000Updated Jul 10, 2025Jul 10, 2025
    • A reverse-engineered RemediationBuilder DSL specification
      Swift
      0200Updated Jul 10, 2025Jul 10, 2025
    • A Swift reimplementation of the RemediationBuilder DSL
      Swift
      0100Updated Jul 10, 2025Jul 10, 2025
    • A simple tool to check how provenance sandbox works
      C
      0000Updated Jul 10, 2025Jul 10, 2025
    • A Binary Ninja plugin for analyzing XProtect Remediator binaries.
      Python
      0300Updated Jul 10, 2025Jul 10, 2025
    • A Binary Ninja plugin for analyzing indirect branch targets in x86_64 binaries.
      Python
      0100Updated Jul 10, 2025Jul 10, 2025
    • A Binary Ninja plugin for analyzing Swift binaries
      Python
      0500Updated Jul 10, 2025Jul 10, 2025
    • FEXRD

      Public
      Feature Extractor for FFRI Dataset
      Python
      3500Updated Aug 5, 2024Aug 5, 2024
    • Test files for FEXRD
      0000Updated Aug 5, 2024Aug 5, 2024
    • PoC code and tools for Black Hat USA 2024
      C
      32300Updated Aug 1, 2024Aug 1, 2024
    • Make datasets like FFRI Dataset
      Python
      31221Updated Jul 23, 2024Jul 23, 2024
    • pypeid

      Public
      Yet another implementation of PEiD with yara-python
      Python
      2720Updated Jun 17, 2024Jun 17, 2024
    • LIEF

      Public
      LIEF - Library to Instrument Executable Formats
      C++
      674000Updated Apr 23, 2024Apr 23, 2024
    • eolh

      Public
      Bring Security Observability to Windows Containers
      Go
      455200Updated Apr 2, 2024Apr 2, 2024
    • eolh-docs

      Public
      HTML
      0000Updated Apr 2, 2024Apr 2, 2024
    • Analyzing CHPEV2 ARM64EC and ARM64X
      Python
      104911Updated Nov 2, 2023Nov 2, 2023
    • PoC code of XTA Cache Poisoning presented at Black Hat Asia 2023
      C++
      1300Updated May 10, 2023May 10, 2023
    • PoC code of AOT poisoning presented at Black Hat Asia 2023
      Python
      11100Updated May 10, 2023May 10, 2023
    • radare2

      Public archive
      UNIX-like reverse engineering framework and command-line toolset
      C
      3.1k800Updated Feb 17, 2023Feb 17, 2023
    • Scripts introduced in JSAC2023 presentation on analysis of Go language malware
      Python
      1600Updated Jan 24, 2023Jan 24, 2023
    • magne-flame

      Public archive
      A fast and extensible fuzzing framework
      Rust
      0204Updated Jun 6, 2022Jun 6, 2022
    • Reverse engineering Rosetta 2 on M1 Mac
      Python
      2441510Updated Aug 3, 2021Aug 3, 2021
    • visualize-package

      Public archive
      Compare npm packages by their development momentum
      TypeScript
      2211Updated May 7, 2021May 7, 2021
    • Consideration of packer detection tool for FFRI Dataset scripts
      Jupyter Notebook
      0000Updated Mar 25, 2021Mar 25, 2021
    • Evaluation of packer type estimation/detection tools
      Python
      51300Updated Mar 24, 2021Mar 24, 2021
    • XtaTools

      Public
      PoC code and tools for Black Hat EU 2020
      Python
      71700Updated Dec 9, 2020Dec 9, 2020