Skip to content
View 8u1a's full-sized avatar

Highlights

  • Pro

Block or report 8u1a

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

JavaScript 6,276 834 Updated Jul 15, 2024

Hypervisor Memory Introspection Core Library

C 676 68 Updated Jan 26, 2026

Command line Java Decompiler

Java 643 99 Updated Mar 23, 2026

Advanced usermode anti-anti-debugger. Forked from https://bitbucket.org/NtQuery/scyllahide

C++ 4,076 492 Updated Jun 4, 2024

Debug Child Process Tool (auto attach)

C 322 36 Updated Aug 11, 2023

IDA Python scripts

Python 12 3 Updated Nov 2, 2017

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

C++ 3,611 469 Updated Apr 14, 2026

Proofs-of-concept

C++ 825 305 Updated Sep 3, 2024

A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)

Assembly 446 90 Updated May 21, 2024

please use https://github.com/fireeye/vivisect instead

Python 16 7 Updated Oct 21, 2025
Python 50 9 Updated Dec 28, 2012

.NET deobfuscator and unpacker.

C# 7,390 2,802 Updated Aug 29, 2020

Cortex: a Powerful Observable Analysis and Active Response Engine

Scala 1,566 258 Updated Mar 24, 2026

CLI tool for open source and threat intelligence

Python 1,269 178 Updated Feb 27, 2025

Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86)

C 8,899 1,485 Updated Feb 19, 2026

CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.

Python 331 93 Updated Dec 6, 2017

Veil 3.1.X (Check version info in Veil at runtime)

Python 4,211 908 Updated Oct 9, 2023

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

PowerShell 2,511 501 Updated Nov 15, 2023

16,432 Free Yara rules created by

YARA 389 59 Updated Jun 1, 2019

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

C++ 48,091 2,709 Updated Apr 14, 2026

Library to load a DLL from memory.

C 3,126 816 Updated Jan 3, 2024

Windows memory hacking library

C++ 5,386 1,422 Updated Jan 26, 2024

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.

C 3,257 819 Updated Sep 3, 2022

A hacky debugger UI for hackers

Python 6,350 421 Updated Jan 30, 2025

pefile is a Python module to read and work with PE (Portable Executable) files

Python 2,032 540 Updated Apr 13, 2026

The pyspresso package is a Python-based framework for debugging Java.

Python 51 14 Updated Jun 17, 2016

YARA signature and IOC database for my scanners and tools

YARA 2,915 660 Updated Apr 9, 2026

Minimal PyPI server for uploading & downloading packages with pip/easy_install

Python 2,024 326 Updated Apr 10, 2026

yarGen is a generator for YARA rules

Python 1,783 306 Updated Jan 10, 2026

Python Decoders for Common Remote Access Trojans

Python 1,117 308 Updated Jul 16, 2024
Next