
CAPEv2
Malware Configuration And Payload Extraction

Malware Configuration And Payload Extraction

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

an iOS kernel function hooking framework for checkra1n'able devices

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

Scriptable debugger for Android Dalvik VM using JDWP/DDM interfaces to hook methods, inspect process state, and modify runtime behavior without…

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

A Git-native dependency admission controller. Evaluates trust signals on every dependency change and blocks commits or builds when packages fail your…

Agent Skill for operating renef.io — Android ARM64 dynamic instrumentation: hook native/Java, patch memory, trace syscalls, bypass SSL pinning/root…

Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance.


Pluggable linting tool to prevent committing credential.

[Official] Android reverse engineering tool focused on dynamic instrumentation automation leveraging Frida. It disassembles dex, analyzes it…

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

x64 Dynamic Reverse Engineering Toolkit

a guard that blocks catastrophic agent actions

A DTrace on Windows Reimplementation

Injects code into ELF executables post-build