Windows kernel + user-mode emulator.
Tools for binaries
Native executables, firmware and shellcode.
80 tools indexed
Multi-agent offensive-security harness that turns your AI coding agent into a bug hunter.
Filesystem forensics library.
Lightweight dynamic instrumentation.
UPX
—Ultimate Packer for eXecutables.
Multi-arch CPU emulator framework.
Memory forensics framework.
AFL fork for Windows binaries.
YARA
—Pattern matching for malware research.
Community YARA rule repository.
Z3
—Theorem prover for SMT problems.
Fast x86/x86-64 disassembler library.
Malware analysis evasion test suite.
angr
—Binary analysis with symbolic execution.
High-speed forensic feature extractor.
capa
—Identify executable capabilities.
DEX ↔ JAR conversion toolkit.
.NET assembly debugger and editor.
IDA Pro emulation scripting framework.
fq
—jq for binary formats.
Terminal-based malware triage toolkit written in Rust
Google's general-purpose fuzzer.
Detect malicious capabilities in code, binaries and containers.
Turn x86/x64 shellcode into polymorphic position-independent VMs.