Open highlighted repo slot
Put your repository first
Promote a GitHub repo at the top of Awesome repository list views for 7 days.
GitHub projects from awesome lists
Search names, descriptions, topics, tags, and stacks, then tune results by ecosystem, freshness, health, and cross-list signal.
Open highlighted repo slot
Promote a GitHub repo at the top of Awesome repository list views for 7 days.
A Repository to Track Anti-Forensic Techniques
Library containing Anti-RE and Anti-Debug methods.
x86-64 virtualizing obfuscator written in Rust
Windows PDB parser for kernel-mode environment.
Dalvik bytecode emulator for Android static analysis | String decryption | Multi-DEX | No Android runtime required
No description.
Ghidra decompiler in your browser
driver manual mapper (outdated/for educational purposes)
Reverse engineering assistant that extracts strings and related pseudocode from a binary file.
pasted eft cheat
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
可在非测试模式下符号化读取内核内存。Kernel memory can be read symbolically in non test mode。
Overwatch Anti-Flag
IDA Claude Code Plugins
This bypass is for anti cheats like battleye and EAC. All this does is abuse lsass's handles and use them for yourself. This is quite useful as this is usermode which doesnt require you to find a way to load a driver
Fully working kernel-mode VAC bypass
🍂 Android aarch64 kernel driver module providing efficient memory operations, touch simulation and IPC. Features include fast memory remapping.
Game cheat base and clean architecture for your next cheat
No description.
A zygisk module that dumps so file from process memory
No description.
The windows kernel debugger consists of two parts, KMOD which is the kernel driver handling ring3 request and KCLI, the command line interface for the driver. It originated due to insufficient useability with CheatEngine's DBVM driver while debugging games running under certain AntiCheat software.
Unreal Engine UI Texture Validator Plugin
Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.
A Model Context Protocol (MCP) server that enables AI assistants to interact with IDA Pro for reverse engineering and binary analysis tasks.
Kasumi - a kernel-level path manipulation and hiding framework
A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.
MalUnpack companion driver
WinDbg Copilot - Agentic Debugging extension
A C++ REPL for IDA Pro / IDA C++ SDK