Skip to content
View xorhex's full-sized avatar

Block or report xorhex

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Attack Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by developing a representation of attack flows, modeling attack flow…

TypeScript 747 124 Updated Jun 18, 2026

Python bindings for CHMLIB

Python 58 15 Updated Jun 6, 2025

The python backend for MalShare because PHP can't do everything

Python 2 Updated Apr 25, 2026

Frontend for MalShare.com

PHP 18 6 Updated Jun 11, 2026

A BinaryNinja plugin to graph a BNIL instruction tree

Python 90 12 Updated Nov 7, 2025

A YARA & Malware Analysis Toolkit written in Rust.

Rust 111 8 Updated May 20, 2026

Binary Ninja plugin to resolve IOCTL codes to their WDK-defined names.

Python 5 Updated Mar 4, 2026

IoC Ninja is a Binary Ninja plugin that can improve the QoL of malware analysts.

Python 18 1 Updated Nov 18, 2025

Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers

Python 442 34 Updated Jun 17, 2026

Analyze pcaps with Zeek and a Grafana Dashboard

Python 194 17 Updated May 24, 2024

Look into EDR events from network

Go 25 Updated Nov 20, 2025

A utility to find identically configured domains and web-servers based on a pattern. Used to find phishing kits.

Python 9 1 Updated Nov 21, 2025

Repository for community provided Binary Ninja plugins

Python 579 51 Updated Jun 12, 2026

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

Go 851 84 Updated Dec 10, 2025
TypeScript 11,273 399 Updated Jun 19, 2026
Python 4 Updated Jul 1, 2025

A .NET assembly tracer using Harmony for runtime method interception.

C# 51 4 Updated Oct 24, 2025

A wrapper around Roslyn language server which makes it compatible with editors other than VSCode

Rust 183 12 Updated Feb 5, 2026

IDA Extras is a (growing) collection of IDA UI and other enhancements to overcome some challenges when using IDA.

Python 9 Updated Oct 2, 2025

Binary Ninja plugin to identify obfuscated code and other interesting code constructs

Python 656 72 Updated May 21, 2026

An even funnier way to disable windows defender. (through WSC api)

C++ 3,510 291 Updated Nov 23, 2025

A living guide to lesser-known and evasive Windows API abuses used in malware, with practical reverse engineering notes, YARA detections, and behavioral indicators.

YARA 172 14 Updated Oct 27, 2025

Files for the Reconstructing Rust Types: A Practical Guide for Reverse Engineers workshop at NorthSec 2025, presented on May 15, 2025.

Rust 7 Updated May 15, 2025

Calltree generator for Binary Ninja

Python 46 7 Updated Nov 13, 2025

Windows kernel PDB data parsed into YAML

44 9 Updated Nov 2, 2025

This project provides a collection of Microsoft Windows kernel structures, unions and enumerations. Most of them are not officially documented and cannot be found in Windows Driver Kit (WDK) headers.

HTML 30 6 Updated Nov 2, 2025

This project provides a collection of Microsoft Windows kernel structures, unions and enumerations. Most of them are not officially documented and cannot be found in Windows Driver Kit (WDK) header…

Java 247 38 Updated Nov 2, 2025

Slides and materials for the talk Reconstructing Rust Types: A Practical Guide for Reverse Engineers at RE//verse 2025, presented on February 28, 2025.

HTML 26 Updated May 23, 2025

A Qt widget based on QTextEdit, that changes its height automatically to accommodate the text

Python 12 1 Updated Aug 26, 2013
Next