--- title: Reverse Engineering kind: overview topics: [reverse-engineering] sources: - wiki/sources/skills/reverse-engineering.md - wiki/sources/README-categories.md - wiki/sources/descriptions/Coldzer0__RE4F.md - wiki/sources/descriptions/0xricksanchez__Shellcoder.md - wiki/sources/descriptions/0xdea__rhabdomancer.md - wiki/sources/descriptions/0xdea__augur.md - wiki/sources/descriptions/0xDbgMan__DrvEye.md - wiki/sources/descriptions/0liverFlow__CVE2PoC.md - wiki/sources/descriptions/0ffffffffh__yummyPaste.md - wiki/sources/descriptions/0xGotcha__XrefXpert.md - wiki/sources/descriptions/0xdea__frida-scripts.md - wiki/sources/descriptions/0xMohammedHassan__morphkatz.md - wiki/sources/descriptions/0x5abe__vifterpreter.md - wiki/sources/descriptions/0xenia__remem.md - wiki/sources/descriptions/0xor0ne__debugoff.md - wiki/sources/descriptions/0xTriboulet__T-1.md - wiki/sources/descriptions/1-3-7__disrobe.md - wiki/sources/descriptions/danigargu__deREferencing.md - wiki/sources/descriptions/Lixense__ff-ace-anticheat-analysis.md - wiki/sources/descriptions/LordeTyrael__PokeAllianceAntiCheatAnalysis.md - wiki/sources/descriptions/zelect0r__zamr.md - wiki/sources/descriptions/zx0CF1__shredder-rs.md - wiki/sources/descriptions/zodiacon__TotalPE2.md - wiki/sources/descriptions/zodiacon__QuickAsm.md - wiki/sources/descriptions/zodiacon__ObjectExplorer.md - wiki/sources/descriptions/skylot__raung.md - wiki/sources/descriptions/iBotPeaches__Apktool.md - wiki/sources/descriptions/zinja-coder__apktool-mcp-server.md - wiki/sources/descriptions/AndnixSH__APKToolGUI.md - wiki/sources/descriptions/APKLab__APKLab.md - wiki/sources/descriptions/xjoker__delamain.md - wiki/sources/descriptions/axelmierczuk__tenrec.md - wiki/sources/descriptions/azw413__Glass.md - wiki/sources/descriptions/ax__apk.sh.md - wiki/sources/descriptions/atlas0fd00m__viv-ghidra-decompiler.md - wiki/sources/descriptions/astrelsky__Ghidra-Cpp-Class-Analyzer.md - wiki/sources/descriptions/astrelsky__GhidraGradlePlugin.md - wiki/sources/descriptions/astrelsky__GhidraOrbis.md - wiki/sources/descriptions/astean1001__ProMBA.md - wiki/sources/descriptions/artmih24__TeleParser.md - wiki/sources/descriptions/arisada__midgetpack.md - wiki/sources/descriptions/arlyon__awesome-wow-rust.md - wiki/sources/descriptions/april-ivy__Apwil.md - wiki/sources/descriptions/angr__angrop.md - wiki/sources/descriptions/anpa1200__Unpacker.md - wiki/sources/descriptions/AndroidReverser-Test__Kernel-Trace.md - wiki/sources/descriptions/Anonym0ose__JitDumper.md - wiki/sources/descriptions/Antelcat__ida_copilot.md - wiki/sources/descriptions/AntonKukoba1__BetterCallStack.md - wiki/sources/descriptions/AllsafeCyberSecurity__awesome-ghidra.md - wiki/sources/descriptions/a0yark__Duckov_marketmod.md - wiki/sources/descriptions/a0rtega__pafish.md - wiki/sources/descriptions/SaadAhla__Anti-Sandbox.md - wiki/sources/descriptions/LostOxygen__gnn_deobfuscation.md - wiki/sources/descriptions/LukeGoule__compact_vm_detector.md - wiki/sources/descriptions/Lima-X__Win32.Nebula.md - wiki/sources/descriptions/LeoChen-CoreMind__VMPacker.md - wiki/sources/descriptions/LabGuy94__OxideDumper.md - wiki/sources/descriptions/L4ys__IDA-WPP-Remover.md - wiki/sources/descriptions/L-Spiro__MhsX.md - wiki/sources/descriptions/LAC-Japan__IDA_Plugin_AntiDebugSeeker.md - wiki/sources/descriptions/Leeksov__rustsecure-re.md - wiki/sources/descriptions/Lavender-exe__Shellcrypt.md - wiki/sources/descriptions/34306__vphone-aio.md - wiki/sources/descriptions/34306__usbliter8-fun.md - wiki/sources/descriptions/34306__mdc0.md - wiki/sources/descriptions/Lakr233__vphone-cli.md - wiki/sources/descriptions/zqxwce__vphone-ws.md - wiki/sources/descriptions/LargoScript__n0xis.md - wiki/sources/descriptions/LaurieWired__Malimite.md - wiki/sources/descriptions/LaurieWired__GhidraMCP.md - wiki/sources/descriptions/LloydLabs__wsb-detect.md - wiki/sources/descriptions/LloydLabs__delete-self-poc.md - wiki/sources/descriptions/LordNoteworthy__al-khaser.md - wiki/sources/descriptions/LongWayHomie__PolyEngine.md - wiki/sources/descriptions/Lucyferek-nunu__vmp-unpacker.md - wiki/sources/descriptions/LSPosed__DexBuilder.md - wiki/sources/descriptions/LSPosed__AndroidHiddenApiBypass.md - wiki/sources/descriptions/LLeavesG__eBPFDexDumper.md - wiki/sources/descriptions/LING71671__open-reverselab.md - wiki/sources/descriptions/LLVMParty__smt-server.md - wiki/sources/descriptions/LuckyPray__DexKit-Android.md - wiki/sources/descriptions/a1ext__auto_re.md - wiki/sources/descriptions/alekzandren__in-memory-mutation-demo.md - wiki/sources/descriptions/akuafif__hXOR-Packer.md - wiki/sources/descriptions/akawashiro__sloader.md - wiki/sources/descriptions/DanielRTeixeira__injectAllTheThings.md - wiki/sources/descriptions/Daniel-Lobo__WineHooks.md - wiki/sources/descriptions/DarthTon__Blackbone.md - wiki/sources/descriptions/DavidBuchanan314__stelf-loader.md - wiki/sources/descriptions/airbus-seclab__qemu_blog.md - wiki/sources/descriptions/airbus-seclab__AutoResolv.md - wiki/sources/descriptions/airbus-cert__comida.md - wiki/sources/descriptions/andrew9382__exe_packer.md - wiki/sources/descriptions/andrew-hoffman__ghidra-vxd-tools.md - wiki/sources/descriptions/anhkgg__awesome-windbg-extensions.md - wiki/sources/descriptions/allogic__KDBG.md - wiki/sources/descriptions/aliyunav__Finger.md - wiki/sources/descriptions/ant4g0nist__lisa.py.md - wiki/sources/descriptions/ant4g0nist__pyre.md - wiki/sources/descriptions/ant4g0nist__rudroid.md - wiki/sources/descriptions/amruth-sn__kong.md - wiki/sources/descriptions/amosshi__binaryinternals.md - wiki/sources/descriptions/apkunpacker__IDA-Gepetto.md - wiki/sources/descriptions/aqilc__chasm.md - wiki/sources/descriptions/arizvisa__ida-minsc.md - wiki/sources/descriptions/aroxby__dynre-x86.md - wiki/sources/descriptions/atrexus__vulkan.md - wiki/sources/descriptions/d35ha__CallObfuscator.md - wiki/sources/descriptions/d35ha__DumpPE.md - wiki/sources/descriptions/d4em0n__exrop.md - wiki/sources/descriptions/d4rksystem__VMwareCloak.md - wiki/sources/descriptions/dmaivel__covirt.md - wiki/sources/descriptions/dmaivel__ntoseye.md - wiki/sources/descriptions/dayzerosec__AMD-SP-Loader.md - wiki/sources/descriptions/damanoreshkan-beep__rtl8852au-userspace.md - wiki/sources/descriptions/david942j__kvm-kernel-example.md - wiki/sources/descriptions/daveymcq__SimpleMemoryEditor.md - wiki/sources/descriptions/digital-dev__Apprentice.md - wiki/sources/descriptions/dashingsoft__pyarmor.md - wiki/sources/descriptions/Fadi002__de4py.md - wiki/sources/descriptions/zhurong2020__pyobfus.md - wiki/sources/descriptions/dariushoule__x64dbg-rippy.md - wiki/sources/descriptions/dariushoule__x64dbg-automate-pyclient.md - wiki/sources/descriptions/beehive-lab__mambo.md - wiki/sources/descriptions/bliutech__mbased.md - wiki/sources/descriptions/bitdefender__river.md - wiki/sources/descriptions/binsnake__fARM64.md - wiki/sources/descriptions/binsnake__KUBERA.md - wiki/sources/descriptions/bethington__ghidra-mcp.md - wiki/sources/descriptions/batteryshark__batteryshark.github.io.md - wiki/sources/descriptions/banteg__bn.md - wiki/sources/descriptions/badhive__stitch.md - wiki/sources/descriptions/bbfox0703__Mydev-Cheat-Engine-Tables.md - wiki/sources/descriptions/beamstar__cheatengine-mcp-bridge.md - wiki/sources/descriptions/binarly-io__idapcode.md - wiki/sources/descriptions/blacktop__ida-mcp-rs.md - wiki/sources/descriptions/bkerler__ida_rpc.md - wiki/sources/descriptions/bobalkkagi__bobalkkagi.md - wiki/sources/descriptions/boratanrikulu__gecit.md - wiki/sources/descriptions/AgentSmithers__x64DbgMCPServer.md - wiki/sources/descriptions/Accenture__protobuf-finder.md - wiki/sources/descriptions/AbyssEngine__AbyssEngine.md - wiki/sources/descriptions/bromoket__x64dbg_mcp.md - wiki/sources/descriptions/Byrom90__XenonDumper.md - wiki/sources/descriptions/danbrodsky__GFred.md - wiki/sources/descriptions/danielplohmann__mcrit-plugin.md - wiki/sources/descriptions/danielplohmann__gui-plugin-template.md - wiki/sources/descriptions/deadeert__EWS.md - wiki/sources/descriptions/dNop90__dOffset.md - wiki/sources/descriptions/dobin__SuperMega.md - wiki/sources/descriptions/dnakov__radare2-mcp.md - wiki/sources/descriptions/dnSpy__dnSpy.md - wiki/sources/descriptions/dnSpy__dnSpy-Unity-mono.md - wiki/sources/descriptions/Unity-Technologies__UnityCsReference.md - wiki/sources/descriptions/00christian00__UnityDecompiled.md - wiki/sources/descriptions/Unity-Technologies__FPSSample.md - wiki/sources/descriptions/dnSpy__Mono.Debugger.Soft.md - wiki/sources/descriptions/rabbanyhmm__DnSpyMCP.md - wiki/sources/descriptions/diversenok__DiaSymbolView.md - wiki/sources/descriptions/djkaty__Il2CppInspector.md - wiki/sources/descriptions/Perfare__Il2CppDumper.md - wiki/sources/descriptions/AssetRipper__AssetRipper.md - wiki/sources/descriptions/Perfare__AssetStudio.md - wiki/sources/descriptions/donaldwuid__unreal_source_explained.md - wiki/sources/descriptions/NotYetGames__WarriOrb.md - wiki/sources/descriptions/Noelo-Lab__decbench.md - wiki/sources/descriptions/Noelo-Lab__kuna.md - wiki/sources/descriptions/NoneShell__IDAComments.md - wiki/sources/descriptions/Noosh404__Maplestory-V179-Cheat-Engine.md - wiki/sources/descriptions/droidrun__droidrun.md - wiki/sources/descriptions/Genymobile__scrcpy.md - wiki/sources/descriptions/barry-ran__QtScrcpy.md - wiki/sources/descriptions/doomedraven__Tools.md - wiki/sources/descriptions/skylot__jadx.md - wiki/sources/descriptions/iamsopotatoe-coder__TinyLoad.md - wiki/sources/descriptions/iArtorias__debug_remover.md - wiki/sources/descriptions/ixty__mandibule.md - wiki/sources/descriptions/itaymigdal__awesome-injection.md - wiki/sources/descriptions/gmh5225__AntiDbg-AmogusPlugin.md - wiki/sources/descriptions/gmh5225__antidbg-Baka.md - wiki/sources/descriptions/NotRequiem__antidbg.md - wiki/sources/descriptions/gmh5225__AutoOpenCAK.md - wiki/sources/descriptions/gmh5225__awesome-executable-packing.md - wiki/sources/descriptions/isadorasophia__murder.md - wiki/sources/descriptions/iss4cf0ng__OpenPetya.md - wiki/sources/descriptions/OpenArena__engine.md - wiki/sources/descriptions/OpenRCT2__OpenRCT2.md - wiki/sources/descriptions/OpenXRay__xray-16.md - wiki/sources/descriptions/jprx__darwin-vm.md - wiki/sources/descriptions/jd-opensource__arkdecompiler.md - wiki/sources/descriptions/hx1997__dayu.md - wiki/sources/descriptions/hugsy__ropgadget-rs.md - wiki/sources/descriptions/hugsy__CFB.md - wiki/sources/descriptions/ergrelet__dll-hot-reload.md - wiki/sources/descriptions/ergrelet__themida-spotter-bn.md - wiki/sources/descriptions/ergrelet__themida-unmutate.md - wiki/sources/descriptions/ergrelet__unlicense.md - wiki/sources/descriptions/ergrelet__windiff.md - wiki/sources/descriptions/eversinc33__drvtrace.md - wiki/sources/descriptions/Vis-Wing__Binoculars.md - wiki/sources/descriptions/VirusTotal__vt-ida-plugin.md - wiki/sources/descriptions/ViRb3__swift-ida.md - wiki/sources/descriptions/VenTaz__Themidie.md - wiki/sources/descriptions/VollRagm__ghostdebug.md - wiki/sources/descriptions/OTFCG__Awesome-Game-Analysis.md - wiki/sources/descriptions/VelocityRa__awesome-game-file-format-reversing.md - wiki/sources/descriptions/vs-sr-dev__pc-wackywheels-doc.md - wiki/sources/descriptions/sosso33__omikron-tns-omk-engine.md - wiki/sources/descriptions/Velaron__cs16-client.md - wiki/sources/descriptions/ValveSoftware__halflife.md - wiki/sources/descriptions/SamVanheer__halflife-unified-sdk.md - wiki/sources/descriptions/SamLarenN__PePacker.md - wiki/sources/descriptions/ValveSoftware__GameNetworkingSockets.md - wiki/sources/descriptions/TASEmulators__BizHawk.md - wiki/sources/descriptions/TLeonardUK__ds2os.md - wiki/sources/descriptions/TLeonardUK__ds3os.md - wiki/sources/descriptions/0x5abe__vifterpreter.md - wiki/sources/descriptions/Goatman13__ps2_ida_vu_micro.md - wiki/sources/descriptions/Goatman13__spu2c.md - wiki/sources/descriptions/Grasscutters__Grasscutter.md - wiki/sources/descriptions/GlacierW__MBA.md - wiki/sources/descriptions/TrackAndTruckDevs__SPF_GhidraPatternHelper.md - wiki/sources/descriptions/TKazer__ScyllaHide-For-IDA9.0RC.md - wiki/sources/descriptions/VirtualBox__virtualbox.md - wiki/sources/descriptions/Vector35__scc.md - wiki/sources/descriptions/Vector35__tanto.md - wiki/sources/descriptions/Vector35__workflow_objc.md - wiki/sources/descriptions/Vector35__official-plugins.md - wiki/sources/descriptions/Vector35__community-plugins.md - wiki/sources/descriptions/Vector35__OpaquePredicatePatcher.md - wiki/sources/descriptions/VarshaWanjari0__Auto-Android-App-Modding-Tool.md - wiki/sources/descriptions/VoidSec__ioctlpus.md - wiki/sources/descriptions/RSDKModding__RSDKv5-Decompilation.md - wiki/sources/descriptions/InfiniteC0re__OpenBarnyard.md - wiki/sources/descriptions/R7flex__dll-ollvm.md - wiki/sources/descriptions/QuesmaOrg__BinaryAudit.md - wiki/sources/descriptions/Reodus__CBS.md - wiki/sources/descriptions/RomanRybachek__Copy_RVA.md - wiki/sources/descriptions/RolfRolles__HexRaysDeob.md - wiki/sources/descriptions/RevEngAI__plugin-ghidra.md - wiki/sources/descriptions/pxb1988__dex2jar.md - wiki/sources/descriptions/zhuzhu-Top__deobf.md - wiki/sources/descriptions/zhizhuodemao__android_proxy_mcp.md - wiki/sources/descriptions/zeroxjf__lightsaber.md - wiki/sources/descriptions/Zenlua__Tool-Tree.md - wiki/sources/descriptions/ZehMatt__CovCane.md - wiki/sources/descriptions/ZehMatt__zyemu.md - wiki/sources/descriptions/ZehMatt__x64dbgPlaytime.md - wiki/sources/descriptions/rooootdev__lara.md - wiki/sources/descriptions/wh1te4ever__darksword-kexploit-fun.md - wiki/sources/descriptions/wh1te4ever__xnu_1day_practice.md - wiki/sources/descriptions/alephsecurity__xnu-qemu-arm64.md - wiki/sources/descriptions/ChefKissInc__qemu-apple-silicon.md - wiki/sources/descriptions/wh1te4ever__HumptyLock.md - wiki/sources/descriptions/jsherman212__xnuspy.md - wiki/sources/descriptions/hackcatml__frida-watchpoint-tutorial.md - wiki/sources/descriptions/hackcatml__kfd-explorer.md - wiki/sources/descriptions/felix-pb__kfd.md - wiki/sources/descriptions/jsacco__ntoskrnlwalker.md - wiki/sources/descriptions/jsacco__NTKernelWalkerLib.md - wiki/sources/descriptions/jonpalmisc__ida_screenshot.md - wiki/sources/descriptions/jnz__q3vm.md - wiki/sources/descriptions/jlucaso1__unturned-godot.md - wiki/sources/descriptions/giladreich__ida_migrator.md - wiki/sources/descriptions/gilboz__ida_kernelcache_ng.md - wiki/sources/descriptions/burrowers__garble.md - wiki/sources/descriptions/buzzer-re__ToCode.md - wiki/sources/descriptions/buzzer-re__Rikugan.md - wiki/sources/descriptions/buzzer-re__NineS.md - wiki/sources/descriptions/c3rb3ru5d3d53c__binlex.md - wiki/sources/descriptions/cellebrite-labs__LabSync.md - wiki/sources/descriptions/cellebrite-labs__FunctionInliner.md - wiki/sources/descriptions/cellebrite-labs__ida_kcpp.md - wiki/sources/descriptions/cellebrite-labs__PPLorer.md - wiki/sources/descriptions/godotengine__godot.md - wiki/sources/descriptions/godotengine__godot-demo-projects.md - wiki/sources/descriptions/cherriesandmochi__gdmaim.md - wiki/sources/descriptions/javascript-obfuscator__javascript-obfuscator.md - wiki/sources/descriptions/jlgreathouse__AMD_IBS_Toolkit.md - wiki/sources/descriptions/jiubanlo__WinNT5_src_20201004.md - wiki/sources/descriptions/jailbreakdotparty__dirtyZero.md - wiki/sources/descriptions/joxeankoret__diaphora.md - wiki/sources/descriptions/joren485__bndb2pat.md - wiki/sources/descriptions/JusticeRage__Gepetto.md - wiki/sources/descriptions/JustasMasiulis__ida_buddy.md - wiki/sources/descriptions/JustasMasiulis__xorstr.md - wiki/sources/descriptions/JustasMasiulis__lazy_importer.md - wiki/sources/descriptions/apekros__binja_sigmaker.md - wiki/sources/descriptions/ahaggard2013__binaryninja-ollama.md - wiki/sources/descriptions/roothide__Dopamine2-roothide.md - wiki/sources/descriptions/zengfr__XrefsExt.md - wiki/sources/descriptions/zboralski__unflutter.md - wiki/sources/descriptions/Guardsquare__flutter-re-demo.md - wiki/sources/descriptions/za233__IDADeflat.md - wiki/sources/descriptions/z1ko__mutaben.md - wiki/sources/descriptions/nhpcc502__MBA-Obfuscator.md - wiki/sources/descriptions/SynthesisLab__MBA.md - wiki/sources/descriptions/MBA-research__mba-wasm.md - wiki/sources/descriptions/yubie-re__ida-jm-xorstr-decrypt-plugin.md - wiki/sources/descriptions/cra0__UE426_ABInfinite-Win64-Shipping.md - wiki/sources/descriptions/craids__AresFramework.md - wiki/sources/descriptions/crtdll__ida-gameguard-str-dec.md - wiki/sources/descriptions/Boyan-MILANOV__ropium.md - wiki/sources/descriptions/BarakAharoni__LADD.md - wiki/sources/descriptions/BataBo__ACEPatcher.md - wiki/sources/descriptions/BaumFX__cpp-anti-debug.md - wiki/sources/descriptions/Blaumaus__le_chiffre.md - wiki/sources/descriptions/Black0ffR__omega-sast.md - wiki/sources/descriptions/Bratah123__BattleAnalysis176.md - wiki/sources/descriptions/Bratah123__SpiritIDAPlugin.md - wiki/sources/descriptions/Bratah123__Spirit-PTCGO.md - wiki/sources/descriptions/DragonMinded__bemaniutils.md - wiki/sources/descriptions/cragson__a53-code-exec.md - wiki/sources/descriptions/cragson__osmium.md - wiki/sources/descriptions/crifan__AutoRename.md - wiki/sources/descriptions/cristeigabriela__bb-viewer.md - wiki/sources/descriptions/cristeigabriela__bb.md - wiki/sources/descriptions/cristeigabriela__IDAFind.md - wiki/sources/descriptions/Cracked5pider__earlycascade-injection.md - wiki/sources/descriptions/CristiNacu__ingsoc.md - wiki/sources/descriptions/CyberSecurityUP__DriverVuln-Analyzer-IDA-Plugin.md - wiki/sources/descriptions/CynicRus__DWARFHelper.md - wiki/sources/descriptions/cpkt9762__ida-cli.md - wiki/sources/descriptions/cpkt9762__solana-sbpf-rlib.md - wiki/sources/descriptions/connormcgarr__EATGuard.md - wiki/sources/descriptions/connorjaydunn__BinaryShield.md - wiki/sources/descriptions/cnitlrt__headless-ida-mcp-server.md - wiki/sources/descriptions/cocomelonc__pawtrace.md - wiki/sources/descriptions/cocomelonc__tabby.md - wiki/sources/descriptions/cocomelonc__peekaboo.md - wiki/sources/descriptions/cansarigol__pdbr.md - wiki/sources/descriptions/caprinux__rel-fuscate.md - wiki/sources/descriptions/cdong1012__ollvm-unflattener.md - wiki/sources/descriptions/JbvrgtonYT__ollvm-unflattener.md - wiki/sources/descriptions/comaeio__SwishDbgExt.md - wiki/sources/descriptions/ytk2128__pe32-password.md - wiki/sources/descriptions/yoavst__ida-ios-helper.md - wiki/sources/descriptions/lj94093__IDAAndroidBreakpoint.md - wiki/sources/descriptions/ykus4__kagura.md - wiki/sources/descriptions/romainthomas__the-poor-mans-obfuscator.md - wiki/sources/descriptions/nkhmelni__Obscura.md - wiki/sources/descriptions/rockbruno__swiftshield.md - wiki/sources/descriptions/ri-char__zygisk-dump-dex.md - wiki/sources/descriptions/ri-char__pwatch.md - wiki/sources/descriptions/elishacloud__dxwrapper.md - wiki/sources/descriptions/enenH__pwatch-c.md - wiki/sources/descriptions/Yayoi-cs__fastDbg.md - wiki/sources/descriptions/Ylarod__hardware-breakpoint.md - wiki/sources/descriptions/yellowbyte__opaque-predicates-detective.md - wiki/sources/descriptions/yaxinsn__vermagic.md - wiki/sources/descriptions/marin-m__vmlinux-to-elf.md - wiki/sources/descriptions/sad0p__venom.md - wiki/sources/descriptions/yardenshafir__WinDbg_Scripts.md - wiki/sources/descriptions/xxFURYWOLFxx__veh-dumper.md - wiki/sources/descriptions/xtremegamer1__vmdevirt-vtil.md - wiki/sources/descriptions/xsj3n__x64-EXE-Packer.md - wiki/sources/descriptions/XMCVE__import-kallsyms.md - wiki/sources/descriptions/xM0kht4r__2Pack.md - wiki/sources/descriptions/frank2__oxide.md - wiki/sources/descriptions/fuqiuluo__amice.md - wiki/sources/descriptions/Systemcluster__wrappe.md - wiki/sources/descriptions/SymbioticSec__ida-security-scanner.md - wiki/sources/descriptions/xqemu__xqemu.md - wiki/sources/descriptions/tteck__Proxmox.md - wiki/sources/descriptions/tenclass__mvisor.md - wiki/sources/descriptions/therealdreg__anticuckoo.md - wiki/sources/descriptions/theo-abel__awesome-anti-virtualization.md - wiki/sources/descriptions/xkevio__kevboy.md - wiki/sources/descriptions/vojty__feather-gb.md - wiki/sources/descriptions/IIIImmmyyy__AntiOllvm.md - wiki/sources/descriptions/IIIImmmyyy__ArmShellCode.md - wiki/sources/descriptions/IcEy-999__Ntoskrnl_Viewer.md - wiki/sources/descriptions/IcyModz420__X360GameHack2025.md - wiki/sources/descriptions/WoahToasty__ToastyLink.md - wiki/sources/descriptions/Iamgublin__ida-codex-mcp.md - wiki/sources/descriptions/xenia-project__xenia.md - wiki/sources/descriptions/wmarti__xenia-mac.md - wiki/sources/descriptions/rexdex__recompiler.md - wiki/sources/descriptions/ex0dus-0x__fuzzable.md - wiki/sources/descriptions/ex0dus-0x__ward.md - wiki/sources/descriptions/exploits-forsale__collateral-damage.md - wiki/sources/descriptions/xemu-project__xemu.md - wiki/sources/descriptions/xp987__symbridge.md - wiki/sources/descriptions/xsslize__idarem.md - wiki/sources/descriptions/xiaoweime__WProtect.md - wiki/sources/descriptions/D7EAD__mkPIVM.md - wiki/sources/descriptions/DeDf__WProtect.md - wiki/sources/descriptions/DimaReverse__nuitka-themida-unpacker.md - wiki/sources/descriptions/jokerNi__WProtectSDK.md - wiki/sources/descriptions/xaitax__NTSleuth.md - wiki/sources/descriptions/x90skysn3k__x260-lenovo-opencore.md - wiki/sources/descriptions/x86matthew__WinVisor.md - wiki/sources/descriptions/xhscfq__anti-cheat-research-index.md - wiki/sources/descriptions/xhscfq__UnrealVTDbg.md - wiki/sources/descriptions/waryas__KACE.md - wiki/sources/descriptions/Qfrost911__KACE.md - wiki/sources/descriptions/gmh5225__StarRail-ACE-B.md - wiki/sources/descriptions/gmh5225__HI3-ACE-B.md - wiki/sources/descriptions/gmh5225__NeacSafe-Analysis.md - wiki/sources/descriptions/x86byte__sbox.md - wiki/sources/descriptions/x86byte__Obfusk8.md - wiki/sources/descriptions/wufhex__Mystic-xorstr.md - wiki/sources/descriptions/nevergiveup-c__obfuscxx.md - wiki/sources/descriptions/Akipe__awesome-android-aosp.md - wiki/sources/descriptions/AkashaCorporation__HikariSystem-HexCore.md - wiki/sources/descriptions/NetKingJ__awesome-android-security.md - wiki/sources/descriptions/savagedamage__android-security-wizard.md - wiki/sources/descriptions/Nalen98__AngryGhidra.md - wiki/sources/descriptions/NaC-L__Mergen.md - wiki/sources/descriptions/Neverdecel__pcileech-memprocfs-mcp.md - wiki/sources/descriptions/NeverSight__NeverD.md - wiki/sources/descriptions/NeverSight__NeverC.md - wiki/sources/descriptions/Nitr0-G__PeVisor.md - wiki/sources/descriptions/Nou4r__Polymorphic-Engine.md - wiki/sources/descriptions/skadro-official__skCrypter.md - wiki/sources/descriptions/ac3ss0r__obfusheader.h.md - wiki/sources/descriptions/DosX-dev__obfus.h.md - wiki/sources/descriptions/DProvinciani__pt-detector.md - wiki/sources/descriptions/DoranekoSystems__DynaDbg.md - wiki/sources/descriptions/adam-040__Enigma.md - wiki/sources/descriptions/adamyaxley__Obfuscate.md - wiki/sources/descriptions/android1337__crystr.md - wiki/sources/descriptions/android1337__crycall.md - wiki/sources/descriptions/android1337__brkida.md - wiki/sources/descriptions/igozdev__xorlit.md - wiki/sources/descriptions/llxiaoyuan__oxorany.md - wiki/sources/descriptions/hanickadot__cthash.md - wiki/sources/descriptions/hanickadot__compile-time-regular-expressions.md - wiki/sources/descriptions/redskal__obfuscatxor.md - wiki/sources/descriptions/serge-14__encrypted_value.md - wiki/sources/descriptions/obama-gaming__xor-float.md - wiki/sources/descriptions/emlinhax__xv.md - wiki/sources/descriptions/emlinhax__DbgViewEx.md - wiki/sources/descriptions/seifreed__r2morph.md - wiki/sources/descriptions/seifreed__r2SMT.md - wiki/sources/descriptions/seifreed__xrefgen.md - wiki/sources/descriptions/secrary__makin.md - wiki/sources/descriptions/revsic__AntiDebugging.md - wiki/sources/descriptions/YouNeverKnow00__Anti-Debugger-Protector-Loader.md - wiki/sources/descriptions/hiatus__adbg.md - wiki/sources/descriptions/herosi__PyClassInformer.md - wiki/sources/descriptions/hfiref0x__WubbabooMark.md - wiki/sources/descriptions/hfiref0x__SyscallTables.md - wiki/sources/descriptions/harlamism__IdaClu.md - wiki/sources/descriptions/hasherezade__pe-bear.md - wiki/sources/descriptions/hasherezade__mal_unpack_drv.md - wiki/sources/descriptions/helpsystems__Agafi.md - wiki/sources/descriptions/helpsystems__turbodiff.md - wiki/sources/descriptions/heeeyaaaa__vmem-decrypt.md - wiki/sources/descriptions/h4sh5__DumpIt-mirror.md - wiki/sources/descriptions/gmh5225__Tool-DIYSystemMemoryDump.md - wiki/sources/descriptions/gmh5225__OfflineCrashDumpUefi.md - wiki/sources/descriptions/adde88__WoWDumpFix.md - wiki/sources/descriptions/helloobaby__wow-IAT-fix.md - wiki/sources/descriptions/gmh5225__ds4-tools.md - wiki/sources/descriptions/gmh5225__dumpwow.md - wiki/sources/descriptions/gmh5225__WOW-WowAutoFishing.md - wiki/sources/descriptions/gmh5225__overwatch-iat-fixer.md - wiki/sources/descriptions/Metick__Anti-Debug.md - wiki/sources/descriptions/Midi12__ow_unpack.md - wiki/sources/descriptions/Midi12__QueryWorkingSetExample.md - wiki/sources/descriptions/liors619__TtdAntiDebugging.md - wiki/sources/descriptions/rrbranco__blackhat2012.md - wiki/sources/descriptions/samshine__ScyllaHideDetector2.md - wiki/sources/descriptions/secrary__idenLibX.md - wiki/sources/descriptions/secrary__idenLib.md - wiki/sources/descriptions/ssyuqixe__obfCoder.md - wiki/sources/descriptions/sfr-development__Lua-Obfuscator-Clyde-Protection.md - wiki/sources/descriptions/x64dbg__x64dbgbinja.md - wiki/sources/descriptions/skr0x1c0__binja_kc.md - wiki/sources/descriptions/jmprdi__binja-division-deoptimization.md - wiki/sources/descriptions/seekbytes__ptxNinja.md - wiki/sources/descriptions/seeinglogic__ariadne.md - wiki/sources/descriptions/pd0wm__binaryninja-pcode.md - wiki/sources/descriptions/PaulNorman01__Forensia.md - wiki/sources/descriptions/P4nda0s__IDA-NO-MCP.md - wiki/sources/descriptions/PAGalaxyLab__ghidra_scripts.md - wiki/sources/descriptions/PartialVolume__shredos.x86_64.md - wiki/sources/descriptions/PickAngE__AntiCheat-Scanner.md - wiki/sources/descriptions/Psmths__windows-forensic-artifacts.md - wiki/sources/descriptions/Pusty__BinaryNinjaPlugins.md - wiki/sources/descriptions/otter-sec__bn-ebpf-solana.md - wiki/sources/descriptions/gmh5225__efiXplorer.md - wiki/sources/descriptions/gmh5225__ethersplay.md - wiki/sources/descriptions/x64dbg__x64dbg.md - wiki/sources/descriptions/x64dbg__SlothBP.md - wiki/sources/descriptions/x64dbg__DotX64Dbg.md - wiki/sources/descriptions/x64dbg__Classroom.md - wiki/sources/descriptions/jdavidberger__chaiScriptPlugin.md - wiki/sources/descriptions/horsicq__x64dbg-Plugin-Manager.md - wiki/sources/descriptions/horsicq__stringsx64dbg.md - wiki/sources/descriptions/glmcdona__strings2.md - wiki/sources/descriptions/galaxyhaxz__devilution.md - wiki/sources/descriptions/bradharding__doomretro.md - wiki/sources/descriptions/Daivuk__PureDOOM.md - wiki/sources/descriptions/ZDoom__gzdoom.md - wiki/sources/descriptions/UZDoom__UZDoom.md - wiki/sources/descriptions/gaasedelen__microavx.md - wiki/sources/descriptions/gamozolabs__mempeek.md - wiki/sources/descriptions/gcarmix__HexWalk.md - wiki/sources/descriptions/horsicq__nfdx64dbg.md - wiki/sources/descriptions/horsicq__Nauz-File-Detector.md - wiki/sources/descriptions/horsicq__XVolkolak.md - wiki/sources/descriptions/momo5502__vmtrace.md - wiki/sources/descriptions/momo5502__sogen.md - wiki/sources/descriptions/gmh5225__idasdk-collection.md - wiki/sources/descriptions/gmh5225__ida-sdk.md - wiki/sources/descriptions/gmh5225__idawilli.md - wiki/sources/descriptions/gmh5225__idaplugins-list.md - wiki/sources/descriptions/gmh5225__ida-plugins.md - wiki/sources/descriptions/gmh5225__idacode.md - wiki/sources/descriptions/gmh5225__ida_vmware_windows_gdb.md - wiki/sources/descriptions/gmh5225__ida_ps5_elf_plugin.md - wiki/sources/descriptions/gmh5225__ida_names.md - wiki/sources/descriptions/gmh5225__ida_export_functions.md - wiki/sources/descriptions/gmh5225__frida-boot.md - wiki/sources/descriptions/gmh5225__FridaScript.md - wiki/sources/descriptions/gmh5225__FakePDB.md - wiki/sources/descriptions/gmh5225__frinet.md - wiki/sources/descriptions/gmh5225__Classy.md - wiki/sources/descriptions/gmh5225__FindFunc.md - wiki/sources/descriptions/mitros123__DragonHook.md - wiki/sources/descriptions/dsasmblr__game-hacking.md - wiki/sources/descriptions/dronavallipranav__rust-obfuscator.md - wiki/sources/descriptions/dyussekeyev__ida-spotlight.md - wiki/sources/descriptions/dzervas__frinja.md - wiki/sources/descriptions/gmh5225__findyara-ida.md - wiki/sources/descriptions/gmh5225__findcrypt-yara.md - wiki/sources/descriptions/gmh5225__ida-function-string-associate.md - wiki/sources/descriptions/gmh5225__ida-find-.data-ptr.md - wiki/sources/descriptions/gmh5225__ida-sigmaker.md - wiki/sources/descriptions/gmh5225__ida_medigate.md - wiki/sources/descriptions/gmh5225__golang_loader_assist.md - wiki/sources/descriptions/geekrainian__killingfloor-bot-client.md - wiki/sources/descriptions/ghidragolf__ghidra_scripts.md - wiki/sources/descriptions/gmh5225__ghidra.md - wiki/sources/descriptions/gmh5225__GhidraDec.md - wiki/sources/descriptions/gmh5225__X64DBG-ViewDllNotification.md - wiki/sources/descriptions/gmh5225__X64DBG-MapLdr.md - wiki/sources/descriptions/gmh5225__integrity_experiments.md - wiki/sources/descriptions/afulsamet__integrity.md - wiki/sources/descriptions/momo5502__patch-finder.md - wiki/sources/descriptions/momo5502__levo.md - wiki/sources/descriptions/milk-analyzer__vmpunpack.md - wiki/sources/descriptions/miyakejima__xigncode3-blackdesert.md - wiki/sources/descriptions/gmh5225__XignCode3-bypass.md - wiki/sources/descriptions/gmh5225__XignCode3-bypass-alternative.md - wiki/sources/descriptions/gmh5225__XignCode-Dump.md - wiki/sources/descriptions/mizt0__mixed-boolean-transform.md - wiki/sources/descriptions/mojtabafalleh__emulator.md - wiki/sources/descriptions/hzqst__unicorn_pe.md - wiki/sources/descriptions/momalab__e3.md - wiki/sources/descriptions/Kwansy98__ApiBreakpoint.md - wiki/sources/descriptions/Kwansy98__x64dbgCallFinder.md - wiki/sources/descriptions/Kurok00__R3nzSkin.md - wiki/sources/descriptions/Krietz7__IDA-DataExportPlus.md - wiki/sources/descriptions/Kharos102__IOCTLDump.md - wiki/sources/descriptions/KelvinMsft__PerfMon.md - wiki/sources/descriptions/KiFilterFiberContext__windows-software-policy.md - wiki/sources/descriptions/Kix48__R6Updater.md - wiki/sources/descriptions/KooroshRZ__Evader.md - wiki/sources/descriptions/FastVM__minivm.md - wiki/sources/descriptions/Fatmike-GH__Fatpack.md - wiki/sources/descriptions/Eronana__packer.md - wiki/sources/descriptions/Enum0x539__Qvoid-Token-Grabber.md - wiki/sources/descriptions/EquiFox__KsDumper.md - wiki/sources/descriptions/Ezmatehw__Encryptix-Crypter.md - wiki/sources/descriptions/Elinam03__Signature-Forge.md - wiki/sources/descriptions/EliseZeroTwo__SEH-Helper.md - wiki/sources/descriptions/ElvisBlue__emotet-deobfuscator.md - wiki/sources/descriptions/ElvisBlue__x64dbgpython.md - wiki/sources/descriptions/0ffffffffh__yummyPaste.md - wiki/sources/descriptions/Kruziikrel1__CSGO-FindMDL.md - wiki/sources/descriptions/KSwordDEV__KSword.md - wiki/sources/descriptions/Kudaes__Shelter.md - wiki/sources/descriptions/morsisko__xFindOut.md - wiki/sources/descriptions/mibho__x64dbgTraceReader.md - wiki/sources/descriptions/m417z__x64dbg-xfg-marker.md - wiki/sources/descriptions/m417z__Multiline-Ultimate-Assembler.md - wiki/sources/descriptions/legendabrn__AutoAttach.md - wiki/sources/descriptions/leeqwind__PESignAnalyzer.md - wiki/sources/descriptions/notpidgey__ManyTypes.md - wiki/sources/descriptions/wtsxDev__reverse-engineering.md - wiki/sources/descriptions/wiresock__ndisapi.md - wiki/sources/descriptions/hercul3s__Packet-Sniffer.md - wiki/sources/descriptions/gmh5225__Akebi-PacketSniffer.md - wiki/sources/descriptions/gmh5225__LostArkLogger.md - wiki/sources/descriptions/seladb__PcapPlusPlus.md - wiki/sources/descriptions/nmap__npcap.md - wiki/sources/descriptions/winsiderss__systeminformer.md - wiki/sources/descriptions/wilszdev__SteamAntiAntiDebug.md - wiki/sources/descriptions/inflation__goldberg_emulator.md - wiki/sources/descriptions/westfox-5__GhidraMetrics.md - wiki/sources/descriptions/securityjoes__ThreatResearch.md - wiki/sources/descriptions/wesmar__KvcForensic.md - wiki/sources/descriptions/wesmar__FileRecoveryTool.md - wiki/sources/descriptions/wesmar__NTFS_EFI.md - wiki/sources/descriptions/wesmar__CmdT.md - wiki/sources/descriptions/gmh5225__AurumRE.md - wiki/sources/descriptions/weak1337__ricochet_deobfuscator.md - wiki/sources/descriptions/weak1337__NO_ACCESS_Protection.md - wiki/sources/descriptions/gmh5225__Alcatraz.md - wiki/sources/descriptions/weak1337__Alcatraz.md - wiki/sources/descriptions/mike1k__perses.md - wiki/sources/descriptions/mike1k__VMPImportFixer.md - wiki/sources/descriptions/waryas__UMPMLib.md - wiki/sources/descriptions/waryas__EUPMAccess.md - wiki/sources/descriptions/wallds__NoVmpy.md - wiki/sources/descriptions/can1357__NoVmp.md - wiki/sources/descriptions/archercreat__titan.md - wiki/sources/descriptions/JonathanSalwan__VMProtect-devirtualization.md - wiki/sources/descriptions/JonathanSalwan__Triton.md - wiki/sources/descriptions/JonathanSalwan__ROPgadget.md - wiki/sources/descriptions/JonDoNym__peinjector.md - wiki/sources/descriptions/JKornev__cfgdump.md - wiki/sources/descriptions/JKornev__hidden.md - wiki/sources/descriptions/JasonGoemaat__CheatEngineMonoHelper.md - wiki/sources/descriptions/Jackiemin233__Gemini-Genius.md - wiki/sources/descriptions/poppopjmp__VMDragonSlayer.md - wiki/sources/descriptions/void-stack__VMUnprotect.md - wiki/sources/descriptions/void-stack__VMUnprotect.Dumper.md - wiki/sources/descriptions/whoamicrash__VMProtectDumper.md - wiki/sources/descriptions/wINfOG__IDA_Easy_Life.md - wiki/sources/descriptions/timetravelthree__IDARustDemangler.md - wiki/sources/descriptions/khang06__genshinjumpfixer2.md - wiki/sources/descriptions/khang06__misc.md - wiki/sources/descriptions/kkent030315__IDARustCargo.md - wiki/sources/descriptions/JANlittle__IDARustHelper.md - wiki/sources/descriptions/nico__demumble.md - wiki/sources/descriptions/threatlabz__pikabot-deobfuscator.md - wiki/sources/descriptions/w00tzenheimer__d810-ng.md - wiki/sources/descriptions/obpo-project__obpo-plugin.md - wiki/sources/descriptions/obfuscar__obfuscar.md - wiki/sources/descriptions/mkaring__ConfuserEx.md - wiki/sources/descriptions/govcert-ch__ConfuserEx_IDAPython.md - wiki/sources/descriptions/nak0823__ObfuscationMethods.md - wiki/sources/descriptions/vxlang__vxlang-page.md - wiki/sources/descriptions/vxCrypt0r__Voidmaw.md - wiki/sources/descriptions/saveme712__BinCon.md - wiki/sources/descriptions/sapdragon__hint-break.md - wiki/sources/descriptions/thefLink__DeepSleep.md - wiki/sources/descriptions/thixotropist__ghidra_decompiler_plugins.md - wiki/sources/descriptions/vsteffen__woody_woodpacker.md - wiki/sources/descriptions/timhsutw__elfuck.md - wiki/sources/descriptions/n1h-nb__Shellcode-Obfuscation.md - wiki/sources/descriptions/n4sm__m0dern_p4cker.md - wiki/sources/descriptions/mefistotelis__ida-pro-loadmap.md - wiki/sources/descriptions/mfthomps__RESimGhidraPlugins.md - wiki/sources/descriptions/milankovo__ida_enums_helper.md - wiki/sources/descriptions/junron__auto-enum.md - wiki/sources/descriptions/milankovo__ida-search.md - wiki/sources/descriptions/milankovo__YaraVM.md - wiki/sources/descriptions/milcert__ExpoMon.md - wiki/sources/descriptions/miscusi-peek__cheatengine-mcp-bridge.md - wiki/sources/descriptions/mix64__ELFpacker.md - wiki/sources/descriptions/droberson__ELFcrypt.md - wiki/sources/descriptions/dimkr__papaw.md - wiki/sources/descriptions/dr4k0nia__Origami.md - wiki/sources/descriptions/r0ngwe1__petoy.md - wiki/sources/descriptions/phra__PEzor.md - wiki/sources/descriptions/nqntmqmqmb__xorPacker.md - wiki/sources/descriptions/volatilityfoundation__volatility3.md - wiki/sources/descriptions/volatilityfoundation__volatility.md - wiki/sources/descriptions/eset__DelphiHelper.md - wiki/sources/descriptions/es3n1n__ida-wakatime-py.md - wiki/sources/descriptions/es3n1n__obfuscator.md - wiki/sources/descriptions/eteran__edb-debugger.md - wiki/sources/descriptions/evild3ad__MemProcFS-Analyzer.md - wiki/sources/descriptions/Eruditi__CE-MCP-Plugin.md - wiki/sources/descriptions/EvilBytecode__GoDefender.md - wiki/sources/descriptions/EvilBytecode__IDontLikeFileLocks.md - wiki/sources/descriptions/EvilBytecode__CustomDpapi.md - wiki/sources/descriptions/Marisa-Chan__GhidrOrean.md - wiki/sources/descriptions/MEhrn00__Ghidra_COFFParser.md - wiki/sources/descriptions/K4ryuu__IDA-VTableExplorer.md - wiki/sources/descriptions/Katharsas__ghidra-struct-importer.md - wiki/sources/descriptions/MayerDaniel__ida_gpt.md - wiki/sources/descriptions/Maxcloud__MapleResearch.md - wiki/sources/descriptions/MatheuZSecurity__ksentinel.md - wiki/sources/descriptions/3intermute__arm64_silent_syscall_hook.md - wiki/sources/descriptions/MatheuZSecurity__Rootkit.md - wiki/sources/descriptions/MatheuZSecurity__RingReaper.md - wiki/sources/descriptions/MagnetForensics__dumpit-linux.md - wiki/sources/descriptions/MemNixFS__MemNixFS.md - wiki/sources/descriptions/MISP__bsimvis.md - wiki/sources/descriptions/push0ebp__xMalHunter.md - wiki/sources/descriptions/push0ebp__sig-database.md - wiki/sources/descriptions/vmi-rs__ephemera.md - wiki/sources/descriptions/tasox__miniDumpReader.md - wiki/sources/descriptions/skelsec__minidump.md - wiki/sources/descriptions/0vercl0k__udmp-parser.md - wiki/sources/descriptions/0vercl0k__kdmp-parser.md - wiki/sources/descriptions/0vercl0k__symbolizer.md - wiki/sources/descriptions/0vercl0k__snapshot.md - wiki/sources/descriptions/0vercl0k__rp.md - wiki/sources/descriptions/libyal__libmdmp.md - wiki/sources/descriptions/mrexodia__DisableParallelLoader.md - wiki/sources/descriptions/mrexodia__dumpulator.md - wiki/sources/descriptions/vm03__payload_dumper.md - wiki/sources/descriptions/ssut__payload-dumper-go.md - wiki/sources/descriptions/vchelaru__FlatRedBall.md - wiki/sources/descriptions/uuksu__RPGMakerDecrypter.md - wiki/sources/descriptions/urho3d__Urho3D.md - wiki/sources/descriptions/rbfx__rbfx.md - wiki/sources/descriptions/turanszkij__WickedEngine.md - wiki/sources/descriptions/trumank__patternsleuth.md - wiki/sources/descriptions/mischasan__aho-corasick.md - wiki/sources/descriptions/trumank__jmap.md - wiki/sources/descriptions/r6e__paksmith.md - wiki/sources/descriptions/atenfyr__UAssetGUI.md - wiki/sources/descriptions/atenfyr__UAssetAPI.md - wiki/sources/descriptions/UE-Explorer__UE-Explorer.md - wiki/sources/descriptions/UETools__UETools.md - wiki/sources/descriptions/UE4SS-RE__RE-UE4SS.md - wiki/sources/descriptions/panzi__rust-u4pak.md - wiki/sources/descriptions/panda3d__panda3d.md - wiki/sources/descriptions/sideeffects__HoudiniEngineForUnreal.md - wiki/sources/descriptions/utmapp__UTM.md - wiki/sources/descriptions/user23333__veh.md - wiki/sources/descriptions/user1342__Obfu-DE-Scate.md - wiki/sources/descriptions/stars-one__ASCTool.md - wiki/sources/descriptions/obfusk__apksigcopier.md - wiki/sources/descriptions/jixiaoyong__ApkSigner.md - wiki/sources/descriptions/un4ckn0wl3z__MemMCP.md - wiki/sources/descriptions/travisfoley__dfirtriage.md - wiki/sources/descriptions/gtworek__VolatileDataCollector.md - wiki/sources/descriptions/mubix__netview.md - wiki/sources/descriptions/mutinylaboratories__ghidra_svr_bridge.md - wiki/sources/descriptions/mrphrazer__obfuscation_detection.md - wiki/sources/descriptions/mrphrazer__obfuscation_analysis.md - wiki/sources/descriptions/mrphrazer__msynth.md - wiki/sources/descriptions/mrphrazer__ghidra-headless-mcp.md - wiki/sources/descriptions/justfoxing__ghidra_bridge.md - wiki/sources/descriptions/Coldzer0__IDA-For-Delphi.md - wiki/sources/descriptions/Coldzer0__LuaDecompiler.md - wiki/sources/descriptions/Comsecuris__gdbghidra.md - wiki/sources/descriptions/jxy-s__vfdynf.md - wiki/sources/descriptions/moyix__gpt-wpre.md - wiki/sources/descriptions/Mrack__DeObfBR.md - wiki/sources/descriptions/MrMugiwara__FTK-imager-OSX.md - wiki/sources/descriptions/Murka007__Glotus-Client.md - wiki/sources/descriptions/Mowokuma__vm_str.hpp.md - wiki/sources/descriptions/MahmoudZohdy__IAT-Obfuscation.md - wiki/sources/descriptions/ManulMap__malstring.md - wiki/sources/descriptions/MuntashirAkon__AppManager.md - wiki/sources/descriptions/MxIris-Reverse-Engineering__ida-mcp-server.md - wiki/sources/descriptions/MxIris-Reverse-Engineering__RuntimeViewer.md - wiki/sources/descriptions/MeroZemory__ida-multi-mcp.md - wiki/sources/descriptions/mrexodia__ida-pro-mcp.md - wiki/sources/descriptions/mrexodia__ida-nexus-docker.md - wiki/sources/descriptions/mrexodia__ida-nexus-events.md - wiki/sources/descriptions/mrexodia__REToolSync.md - wiki/sources/descriptions/mrexodia__lldbext-dump.md - wiki/sources/descriptions/djolertrk__kLLDB.md - wiki/sources/descriptions/mrexodia__TitanHide.md - wiki/sources/descriptions/mrexodia__RiscyWorkshop.md - wiki/sources/descriptions/msd0pe-1__cve-maker.md - wiki/sources/descriptions/Zierax__Grafana-Final-Scanner.md - wiki/sources/descriptions/trailofbits__idac.md - wiki/sources/descriptions/taida957789__ida-mcp-server-plugin.md - wiki/sources/descriptions/saileaxh__iida-mcp.md - wiki/sources/descriptions/rand-tech__pcm.md - wiki/sources/descriptions/trailofbits__CoBRA.md - wiki/sources/descriptions/tomhamidi97-arch__vmp-devirtualization-lab.md - wiki/sources/descriptions/tomhamidi97-arch__frida-vmp-bypass.md - wiki/sources/descriptions/tomvita__SE-tools.md - wiki/sources/descriptions/tomrus88__OpenLumina.md - wiki/sources/descriptions/tmr232__Sark.md - wiki/sources/descriptions/thewhiteninja__ntfstool.md - wiki/sources/descriptions/strozfriedberg__ntfs-linker.md - wiki/sources/descriptions/NTFSparse__ntfs_parse.md - wiki/sources/descriptions/rbmm__USN.md - wiki/sources/descriptions/mentebinaria__retoolkit.md - wiki/sources/descriptions/lilyco-42__rev-tools-setup.md - wiki/sources/descriptions/memflow__memflow-kvm.md - wiki/sources/descriptions/IntroVirt__IntroVirt.md - wiki/sources/descriptions/mgeeky__ShellcodeFluctuation.md - wiki/sources/descriptions/mgeeky__ntfs-journal-viewer.md - wiki/sources/descriptions/rbmm__SearchEx.md - wiki/sources/descriptions/rbmm__KPDB.md - wiki/sources/descriptions/GetRektBoy724__KPDB.md - wiki/sources/descriptions/staturnzz__oob_entry.md - wiki/sources/descriptions/staturnzz__momentarius.md - wiki/sources/descriptions/0x36__weightBufs.md - wiki/sources/descriptions/0x36__Pixel_GPU_Exploit.md - wiki/sources/descriptions/omochikaeri15__battle-cats-complete.md - wiki/sources/descriptions/thalium__symless.md - wiki/sources/descriptions/thalium__rumba.md - wiki/sources/descriptions/thalium__ida_kmdf.md - wiki/sources/descriptions/teemu-l__execution-trace-viewer.md - wiki/sources/descriptions/t3ssellate__unmapper.md - wiki/sources/descriptions/TaszkSecLabs__xiaomi-c400-pwn.md - wiki/sources/descriptions/Vu1nT0tal__firmeye.md - wiki/sources/descriptions/WhatTheFuzz__binaryninja-openai.md - wiki/sources/descriptions/WerWolv__ImHex.md - wiki/sources/descriptions/Washi1337__ghidra-nativeaot.md - wiki/sources/descriptions/Washi1337__AwaitFuscator.md - wiki/sources/descriptions/WenzWenzWenz__DelphiReSym.md - wiki/sources/descriptions/WPeace-HcH__WPeChatGPT.md - wiki/sources/descriptions/WopsS__RenHook.md - wiki/sources/descriptions/SamuelTulach__LightHook.md - wiki/sources/descriptions/WindySha__bypassHiddenApiRestriction.md - wiki/sources/descriptions/Francesco149__uwpinject.md - wiki/sources/descriptions/Francesco149__uwpspy.md - wiki/sources/descriptions/Wunkolo__UWPDumper.md - wiki/sources/descriptions/WRXinYue__STS2-KitLib.md - wiki/sources/descriptions/TindalosKorone__dsh-cheatengine.md - wiki/sources/descriptions/GalaxyBatMan111__dsh-plugins.md - wiki/sources/descriptions/TheZong__Game-Hacking.md - wiki/sources/descriptions/TimMisiak__WinDbgCookbook.md - wiki/sources/descriptions/TensorBlock__awesome-mcp-servers.md - wiki/sources/descriptions/PortSwigger__mcp-server.md - wiki/sources/descriptions/TorqueGameEngines__Torque3D.md - wiki/sources/descriptions/TorqueGameEngines__Torque2D.md - wiki/sources/descriptions/Nuxar1__DecryptionDumper.md - wiki/sources/descriptions/ObEngine__ObEngine.md - wiki/sources/descriptions/OALabs__hashdb-ida.md - wiki/sources/descriptions/OFFTKP__felix86.md - wiki/sources/descriptions/TorgoTorgo__ghidra-findcrypt.md - wiki/sources/descriptions/WolfireGames__overgrowth.md - wiki/sources/descriptions/thatskriptkid__re-harness.md - wiki/sources/descriptions/pr701__fix-arxan.md - wiki/sources/descriptions/t0asts__DIE-engine-web.md - wiki/sources/descriptions/cognis-digital__packpeek.md - wiki/sources/descriptions/pandora-analysis__pandora.md - wiki/sources/descriptions/rednaga__APKiD.md - wiki/sources/descriptions/synacktiv__thats_no_pipe.md - wiki/sources/descriptions/synacktiv__dotNIET.md - wiki/sources/descriptions/svnscha__mcp-windbg.md - wiki/sources/descriptions/Devolutions__windbg-tool.md - wiki/sources/descriptions/DenuvoSoftwareSolutions__GAMBA.md - wiki/sources/descriptions/DenuvoSoftwareSolutions__Onlooker.md - wiki/sources/descriptions/Deniskore__CompileTimeRandom.md - wiki/sources/descriptions/Deatty__Ghidra-Obfuscation-Detection.md - wiki/sources/descriptions/DSecurity__efiSeek.md - wiki/sources/descriptions/DennyDai__headless-ida.md - wiki/sources/descriptions/DNLINYJ__Anti_miHoYo_Jcc_Obfuscate.md - wiki/sources/descriptions/DMaroo__GhidRust.md - wiki/sources/descriptions/Dray973__Aetheris.md - wiki/sources/descriptions/DrYenyen__Drive-Cloning-For-PS4-PS5.md - wiki/sources/descriptions/DumpAnalysis__WinDbg_Copilot.md - wiki/sources/descriptions/0xeb__libghidra.md - wiki/sources/descriptions/0xeb__windbg-copilot.md - wiki/sources/descriptions/Dump-GUY__IDA_PHNT_TYPES.md - wiki/sources/descriptions/Dump-GUY__ApplyCalleeTypeEx.md - wiki/sources/descriptions/kernullist__windbg-decompile-ext.md - wiki/sources/descriptions/brew02__MountSystemPartition.md - wiki/sources/descriptions/bruce30262__TWindbg.md - wiki/sources/descriptions/kernullist__kn-live-dbg.md - wiki/sources/descriptions/kernullist__KnWin32ApiMonitor.md - wiki/sources/descriptions/irql__nokd.md - wiki/sources/descriptions/guoxing2024__magicmida-rs.md - wiki/sources/descriptions/Hendi48__Magicmida.md - wiki/sources/descriptions/guheng-re__unflat.md - wiki/sources/descriptions/greyb1t__GreyM.md - wiki/sources/descriptions/adspro15__km-um-communication.md - wiki/sources/descriptions/gmh5225__Driver-Communication-List.md - wiki/sources/descriptions/gmh5225__win32k_file_collection.md - wiki/sources/descriptions/gmh5225__win32k_file_collection2.md - wiki/sources/descriptions/GetRektBoy724__Win32kHooker.md - wiki/sources/descriptions/gmh5225__ntminhook.md - wiki/sources/descriptions/gmh5225__ntoskrnl_file_collection.md - wiki/sources/descriptions/gmh5225__NtRays.md - wiki/sources/descriptions/gmh5225__manipulating_token.md - wiki/sources/descriptions/gmh5225__HappyIDA.md - wiki/sources/descriptions/gmh5225__hex2dec-mcp.md - wiki/sources/descriptions/gmh5225__IDA2Obj.md - wiki/sources/descriptions/gmh5225__IDA-MapSymbolParser.md - wiki/sources/descriptions/gmh5225__IDA-Pro-SigMaker.md - wiki/sources/descriptions/gmh5225__KitsuPE.md - wiki/sources/descriptions/gmh5225__DLL-Hijack-ExportDumper.md - wiki/sources/descriptions/gmh5225__long_night.md - wiki/sources/descriptions/gmh5225__LazyIDA.md - wiki/sources/descriptions/gmh5225__LetMeGG.md - wiki/sources/descriptions/gmh5225__ida-dark-plus.md - wiki/sources/descriptions/gmh5225__IdaThemer.md - wiki/sources/descriptions/gmh5225__IDASkins.md - wiki/sources/descriptions/gmh5225__ida-nord-theme.md - wiki/sources/descriptions/gmh5225__dp701.md - wiki/sources/descriptions/gmh5225__memcs.md - wiki/sources/descriptions/gmh5225__Malicious-code-detection-bugu.md - wiki/sources/descriptions/gmh5225__MemWars.md - wiki/sources/descriptions/gmh5225__MSSymbolsCollection.md - wiki/sources/descriptions/gmh5225__MapleStory-CMS95-Client-Address.md - wiki/sources/descriptions/ppodds__UniStory.md - wiki/sources/descriptions/ilia810__MapleUnity.md - wiki/sources/descriptions/MapleStoryUnity__MapleStoryUnity.md - wiki/sources/descriptions/PlinKuuu__DanisNightmare.md - wiki/sources/descriptions/PrinceFroggy__MSC.md - wiki/sources/descriptions/PrinceFroggy__MSB.md - wiki/sources/descriptions/Inndy__MSDoggy.md - wiki/sources/descriptions/gmh5225__minecpp.md - wiki/sources/descriptions/gmh5225__CE-remap-plugin.md - wiki/sources/descriptions/gmh5225__wasm-ceserver.md - wiki/sources/descriptions/hasaneyldrm__webcheat.md - wiki/sources/descriptions/gmh5225__compiler-binary-richprint.md - wiki/sources/descriptions/colinsenner__PECleaner.md - wiki/sources/descriptions/gmh5225__bytecode-viewer.md - wiki/sources/descriptions/CalebFenton__simplify.md - wiki/sources/descriptions/CDJuaum__RunEXE.md - wiki/sources/descriptions/CKCat__d810.md - wiki/sources/descriptions/CENSUS__ghidra-frida-hook-gen.md - wiki/sources/descriptions/CUB3D__ghidra-hexagon-sleigh.md - wiki/sources/descriptions/CodingGay__BlackObfuscator.md - wiki/sources/descriptions/ChengChengCC__Ark-tools.md - wiki/sources/descriptions/ClaudiuGeorgiu__Obfuscapk.md - wiki/sources/descriptions/CodeCracker-Tools__MegaDumper.md - wiki/sources/descriptions/Col-E__Recaf.md - wiki/sources/descriptions/gmh5225__binsync.md - wiki/sources/descriptions/gmh5225__cerberus.md - wiki/sources/descriptions/gmh5225__custom-VEH.md - wiki/sources/descriptions/gmh5225__veh-printf-hook.md - wiki/sources/descriptions/gmh5225__no-access-protection-x86.md - wiki/sources/descriptions/gmh5225__memory-relocalloc.md - wiki/sources/descriptions/gmh5225__veh_hide_memory.md - wiki/sources/descriptions/gmh5225__vt-debuger.md - wiki/sources/descriptions/gmh5225__underTheHoodOfExecutables.md - wiki/sources/descriptions/gmh5225__ue5-roll-a-ball-game.md - wiki/sources/descriptions/gmh5225__BT_ModularGameFeatures.md - wiki/sources/descriptions/gmh5225__UE5-FPS-CryptRaider.md - wiki/sources/descriptions/gmh5225__UnrealEngine5-UltimateStreetFighters.md - wiki/sources/descriptions/gmh5225__Unreal-Engine-5-PDB.md - wiki/sources/descriptions/gmh5225__ttddbg.md - wiki/sources/descriptions/gmh5225__retdec.md - wiki/sources/descriptions/gmh5225__r0ak.md - wiki/sources/descriptions/gmh5225__EntropyReducer.md - wiki/sources/descriptions/gmh5225__EasyRe.md - wiki/sources/descriptions/gmh5225__Driver-intel-PEBs-LoopHPCs.md - wiki/sources/descriptions/gmh5225__Driver-SoulExtraction.md - wiki/sources/descriptions/SV-Foster__UnSign.md - wiki/sources/descriptions/KriyosArcane__TrustMeBro.md - wiki/sources/descriptions/gmh5225__DriverBuddyReloaded.md - wiki/sources/descriptions/gmh5225__Dynsec.md - wiki/sources/descriptions/gmh5225__shellcode-EntropyFix.md - wiki/sources/descriptions/friedkiwi__netcrypt.md - wiki/sources/descriptions/frasten__ida-genpatch.md - wiki/sources/descriptions/fr0gger__awesome-ida-x64-olly-plugin.md - wiki/sources/descriptions/fosdickio__binary_ninja_mcp.md - wiki/sources/descriptions/FuzzySecurity__BinaryNinja-Themes.md - wiki/sources/descriptions/Invoke-RE__binja-lattice-mcp.md - wiki/sources/descriptions/fdrechsler__mcp-server-idapro.md - wiki/sources/descriptions/facebookresearch__CUTracer.md - wiki/sources/descriptions/fail46__OHack.md - wiki/sources/descriptions/fksvs__inject.md - wiki/sources/descriptions/firerpa__lamda.md - wiki/sources/descriptions/fmagin__ghidra-openai.md - wiki/sources/descriptions/evyatar9__GptHidra.md - wiki/sources/descriptions/frkngksl__Huan.md - wiki/sources/descriptions/frkngksl__Shoggoth.md - wiki/sources/descriptions/frkngksl__HintInject.md - wiki/sources/descriptions/gmh5225__sigmakerex.md - wiki/sources/descriptions/gmh5225__sk3wldbg.md - wiki/sources/descriptions/gmh5225__Ponce.md - wiki/sources/descriptions/gmh5225__qsynthesis.md - wiki/sources/descriptions/fvrmatteo__DrillAndJoin.md - wiki/sources/descriptions/fuzzypickles14__BetterStringAnalyzer.md - wiki/sources/descriptions/gmh5225__subhook.md - wiki/sources/descriptions/gmh5225__tenet.md - wiki/sources/descriptions/gmh5225__Tenet-IDA9.0.md - wiki/sources/descriptions/goseungduk__CE_Tracer-IDA.md - wiki/sources/descriptions/gregkh__kernel-development.md - wiki/sources/descriptions/google__binexport.md - wiki/sources/descriptions/google__grr.md - wiki/sources/descriptions/googleprojectzero__TinyInst.md - wiki/sources/descriptions/googleprojectzero__winafl.md - wiki/sources/descriptions/0vercl0k__wtf.md - wiki/sources/descriptions/DynamoRIO__drmemory.md - wiki/sources/descriptions/Duntss__IDA-ZVM-Disassembler.md - wiki/sources/descriptions/guidedhacking__GH_AntiDebug_Bypass_Practice_Tool.md - wiki/sources/descriptions/stuxnet147__Themida-Research.md - wiki/sources/descriptions/sodareverse__TDE.md - wiki/sources/descriptions/snesrev__zelda3.md - wiki/sources/descriptions/gta-reversed__gta-reversed-modern.md - wiki/sources/descriptions/gmh5225__reGTA.md - wiki/sources/descriptions/gmh5225__Grand-Theft-Auto-Modding-Source.md - wiki/sources/descriptions/gmh5225__Game-GTA-re3.md - wiki/sources/descriptions/gmh5225__gtav-sourcecode-build-guide.md - wiki/sources/descriptions/gmh5225__gta5view.md - wiki/sources/descriptions/gmh5225__GTA-5-SIGS-1.59.md - wiki/sources/descriptions/gmh5225__reGS.md - wiki/sources/descriptions/gmh5225__GenshinDebuggerBypass.md - wiki/sources/descriptions/dreamstalker__rehlds.md - wiki/sources/descriptions/gmh5225__GoldSourceRebuild.md - wiki/sources/descriptions/electronicarts__CnC_Red_Alert.md - wiki/sources/descriptions/huangkaoya__redalert2.md - wiki/sources/descriptions/Phobos-developers__Phobos.md - wiki/sources/descriptions/s1lentq__ReGameDLL_CS.md - wiki/sources/descriptions/stuxnet147__IDA-Assistant.md - wiki/sources/descriptions/sigwl__AiDA.md - wiki/sources/descriptions/s3rg0x__AIMachDec.md - wiki/sources/descriptions/stride3d__stride.md - wiki/sources/descriptions/stp__stp.md - wiki/sources/descriptions/nbulsi__cirsat.md - wiki/sources/descriptions/stolevchristian__LUDA.md - wiki/sources/descriptions/stijnherfst__HiveWE.md - wiki/sources/descriptions/stevemk14ebr__RETools.md - wiki/sources/descriptions/sterrasec__genpatch.md - wiki/sources/descriptions/patois__genmc.md - wiki/sources/descriptions/ssmugabi__IDAPlugins.md - wiki/sources/descriptions/sneakyevil__ida_functioncolor.md - wiki/sources/descriptions/sean2077__big5-decode-ida.md - wiki/sources/descriptions/kubo__plthook.md - wiki/sources/descriptions/januwA__game-reversed-study.md - wiki/sources/descriptions/janisslsm__ida-ps4-helper.md - wiki/sources/descriptions/janoglezcampos__DeathSleep.md - wiki/sources/descriptions/kovidomi__game-reversing.md - wiki/sources/descriptions/konstantin89__windows-kernel-debugging-guide.md - wiki/sources/descriptions/killvxk__awesome-obfuscations.md - wiki/sources/descriptions/kkpwn__ErisDbg.md - wiki/sources/descriptions/kantam5__DeadByDaylight.md - wiki/sources/descriptions/kirovgrad__Renamaida.md - wiki/sources/descriptions/kp7742__MemDumper.md - wiki/sources/descriptions/hackcatml__zygisk-memdump.md - wiki/sources/descriptions/kotae4__intro-to-gamehacking.md - wiki/sources/descriptions/ALittlePatate__ezfrags.md - wiki/sources/descriptions/ALittlePatate__TaxiDriver.md - wiki/sources/descriptions/gmh5225__Apex-ApexCheat.md - wiki/sources/descriptions/gmh5225__AssaultCubeCheat.md - wiki/sources/descriptions/201580ag__AssaultCube_Cheat.md - wiki/sources/descriptions/korcankaraokcu__PINCE.md - wiki/sources/descriptions/krampus-nuggets__ce-tutorial.md - wiki/sources/descriptions/kweatherman__yara4ida.md - wiki/sources/descriptions/kweatherman__ida_missinglink.md - wiki/sources/descriptions/sengi12__ghidra-hexEditor.md - wiki/sources/descriptions/ntdlll__Scalpel.md - wiki/sources/descriptions/senko37__yarascan-ida.md - wiki/sources/descriptions/senator715__IDA-Fusion.md - wiki/sources/descriptions/snare__ida-efiutils.md - wiki/sources/descriptions/sonyps5201314__pdb.md - wiki/sources/descriptions/sevaa__dwex.md - wiki/sources/descriptions/smartdone__Frida-Scripts.md - wiki/sources/descriptions/rednaga__frida-stack.md - wiki/sources/descriptions/hackcatml__frida-watchpoint-tutorial.md - wiki/sources/descriptions/smallworld-re__smallworld.md - wiki/sources/descriptions/panda-re__panda.md - wiki/sources/descriptions/nyx-fuzz__QEMU-Nyx.md - wiki/sources/descriptions/signal-slot__mcp-gdb.md - wiki/sources/descriptions/jtang613__gdb-mcp.md - wiki/sources/descriptions/jtang613__GhidrAssistMCP.md - wiki/sources/descriptions/jtang613__GhidrAssist.md - wiki/sources/descriptions/jtang613__IDAssist.md - wiki/sources/descriptions/sefcom__oxidizer.md - wiki/sources/descriptions/pandaadir05__re-architect.md - wiki/sources/descriptions/scrt__avdebugger.md - wiki/sources/descriptions/roger1337__JDBG.md - wiki/sources/descriptions/robert-yates__gdbserver9x.md - wiki/sources/descriptions/noword__GDB-Windows-Binaries.md - wiki/sources/descriptions/notsnakesilent__VMPStatic.md - wiki/sources/descriptions/gmh5225__VMP-Vmp3_64bit_disasm-prerelease-.md - wiki/sources/descriptions/gmh5225__Vmp3_utils.md - wiki/sources/descriptions/gmh5225__VMAttack.md - wiki/sources/descriptions/rmusser01__Infosec_Reference.md - wiki/sources/descriptions/ridpath__gamehacking-cheatsheet.md - wiki/sources/descriptions/mytechnotalent__Reverse-Engineering.md - wiki/sources/descriptions/mytechnotalent__Hacking-Windows.md - wiki/sources/descriptions/mytechnotalent__hacking-rust.md - wiki/sources/descriptions/mytechnotalent__go-hacking.md - wiki/sources/descriptions/mytechnotalent__Embedded-Hacking.md - wiki/sources/descriptions/mytechnotalent__embedded-hacking.md - wiki/sources/descriptions/richor1042__IDAFuncOutline.md - wiki/sources/descriptions/revsic__cpp-veh-dbi.md - wiki/sources/descriptions/redthing1__w1tn3ss.md - wiki/sources/descriptions/repnz__ida-plugins.md - wiki/sources/descriptions/rem0obb__rtti-parser.md - wiki/sources/descriptions/rdeioris__LuaMachine.md - wiki/sources/descriptions/Tencent__xLua.md - wiki/sources/descriptions/Tencent__InjectFix.md - wiki/sources/descriptions/nxrighthere__UnrealCLR.md - wiki/sources/descriptions/null-luo__btrace.md - wiki/sources/descriptions/gmh5225__android_ebpf.md - wiki/sources/descriptions/ServenScorpion__VirtualApp.md - wiki/sources/descriptions/SergeyMakeev__TaskScheduler.md - wiki/sources/descriptions/SeriousCache__UABE.md - wiki/sources/descriptions/Razviar__assetstudio.md - wiki/sources/descriptions/Rantanen__ghidra-minidump-loader.md - wiki/sources/descriptions/Serious-Engine__Base.md - wiki/sources/descriptions/ScriptWare-Software__native-predicate-solver.md - wiki/sources/descriptions/SentineLabs__AlphaGolang.md - wiki/sources/descriptions/ShinoLeah__eHook.md - wiki/sources/descriptions/Sh11no__eDBG.md - wiki/sources/descriptions/Satar07__edbgserver.md - wiki/sources/descriptions/Sandspeare__ida2llvm.md - wiki/sources/descriptions/SamuelTulach__unxorer.md - wiki/sources/descriptions/SamuelTulach__ida-unity-pdb-downloader.md - wiki/sources/descriptions/SeeFlowerX__stackplz.md - wiki/sources/descriptions/SeeFlowerX__frida-smali-trace.md - wiki/sources/descriptions/rdbo__libmem.md - wiki/sources/descriptions/raskolnikov90__Beatrice.py.md - wiki/sources/descriptions/radareorg__radius2.md - wiki/sources/descriptions/radareorg__r2garlic.md - wiki/sources/descriptions/neocanable__garlic.md - wiki/sources/descriptions/radareorg__r2ai.md - wiki/sources/descriptions/radareorg__r2a.md - wiki/sources/descriptions/radareorg__iaito.md - wiki/sources/descriptions/rad9800__BloatedHammer.md - wiki/sources/descriptions/qwqdanchun__Pillager.md - wiki/sources/descriptions/quickemu-project__quickemu.md - wiki/sources/descriptions/ktock__qemu-wasm.md - wiki/sources/descriptions/jakcron__nstool.md - wiki/sources/descriptions/Steesha__CodeCleaner.md - wiki/sources/descriptions/Static-Analyzer-Factory__static-analyzer-factory.md - wiki/sources/descriptions/Squalr__Squalr-Sharp.md - wiki/sources/descriptions/Squalr__Squally.md - wiki/sources/descriptions/SteamDatabase__Protobufs.md - wiki/sources/descriptions/StudentBlake__XCI-Explorer.md - wiki/sources/descriptions/CSIT-SG__AETHER.md - wiki/sources/descriptions/Astronaut00__apex-external.md - wiki/sources/descriptions/Atmosphere-NX__Atmosphere.md - wiki/sources/descriptions/CTCaer__hekate.md - wiki/sources/descriptions/Logboy2000__yuzu-archive.md - wiki/sources/descriptions/qqq26__nuzu.md - wiki/sources/descriptions/pudii__gba-ghidra-loader.md - wiki/sources/descriptions/kroy-the-rabbit__openfpga-GBC-cheats-ui.md - wiki/sources/descriptions/ps5-linux__ps5-linux-loader.md - wiki/sources/descriptions/ntfargo__CSSFontFace-Exploit.md - wiki/sources/descriptions/ArabPixel__PSFree-Enhanced.md - wiki/sources/descriptions/pjasicek__OpenClaw.md - wiki/sources/descriptions/piotrbania__frida_usb_dump.md - wiki/sources/descriptions/pgarba__ptrace_read_teb.md - wiki/sources/descriptions/pgarba__ida-llm-explainer.md - wiki/sources/descriptions/percpopper__Splitgate-Internal.md - wiki/sources/descriptions/Pycatchown__ClassMaker.md - wiki/sources/descriptions/pbiernat__ripr.md - wiki/sources/descriptions/palera1n__palera1n.md - wiki/sources/descriptions/opa334__Dopamine.md - wiki/sources/descriptions/oureveryday__VMPUnpacker.md - wiki/sources/descriptions/oxiKKK__ida-vtable-tools.md - wiki/sources/descriptions/oxiKKK__oxware.md - wiki/sources/descriptions/originsec__pocsmith.md - wiki/sources/descriptions/not1cyyy__Kiroshi.md - wiki/sources/descriptions/alexbevi__ghidra-manager.md - wiki/sources/descriptions/alexhude__FRIEND.md - wiki/sources/descriptions/nologic__idaref.md - wiki/sources/descriptions/nodiuus__nocturne.md - wiki/sources/descriptions/layerfsd__phantasm-x86-virtualizer.md - wiki/sources/descriptions/noahware__binprotect.md - wiki/sources/descriptions/nelfo__Milfuscator.md - wiki/sources/descriptions/noahware__hyper-reV.md - wiki/sources/descriptions/samaBR85__OcarinaCTRComposer.md - wiki/sources/descriptions/samaBR85__CTRComposer.md - wiki/sources/descriptions/nillerusr__source-engine.md - wiki/sources/descriptions/gmh5225__SourceEngine2007.md - wiki/sources/descriptions/UTINKA__source-engine.2003.md - wiki/sources/descriptions/nikaiw__VMkatz.md - wiki/sources/descriptions/ReClassNET__ReClass.NET.md - wiki/sources/descriptions/niemand-sec__ReClass.NET-DriverReader.md - wiki/sources/descriptions/gmh5225__ReClass-DMA.md - wiki/sources/descriptions/ajkhoury__ReClassEx.md - wiki/sources/descriptions/BeneficialCode__KReClassEx.md - wiki/sources/descriptions/IAIK__armageddon.md - wiki/sources/descriptions/IChooseYou__Reclass.md - wiki/sources/descriptions/nickcano__RelocBonus.md - wiki/sources/descriptions/gmh5225__COD-boiii.md - wiki/sources/descriptions/nice-sprite__COD7-Tools.md - wiki/sources/descriptions/ndrewh__pyda.md - wiki/sources/descriptions/narumii__Deobfuscator.md - wiki/sources/descriptions/gmh5225__deobfuscator.md - wiki/sources/descriptions/Guardsquare__proguard.md - wiki/sources/descriptions/gmh5225__Bypassing-EasyAntiCheat-Integrity-check.md - wiki/sources/descriptions/microsoft__Detours.md - wiki/sources/descriptions/microsoft__pdblister.md - wiki/sources/descriptions/microsoft__pdb-rs.md - wiki/sources/descriptions/matteyeux__IDArling.md - wiki/sources/descriptions/mastercodeon314__KsDumper-11.md - wiki/sources/descriptions/marcusbotacin__BranchMonitoringProject.md - wiki/sources/descriptions/libiht__libiht.md - wiki/sources/descriptions/intel__pcm.md - wiki/sources/descriptions/gmh5225__AtomPePacker.md - wiki/sources/descriptions/gmh5225__packer-tutorial.md - wiki/sources/descriptions/gmh5225__Practical-Reverse-Engineering-Solutions.md - wiki/sources/descriptions/danielkrupinski__cs2-anticheat.md - wiki/sources/descriptions/danielkrupinski__VAC.md - wiki/sources/descriptions/RenardDev__DumpVAC.md - wiki/sources/descriptions/ianveig29__cs2-internals.md - wiki/sources/descriptions/Salvatore-Als__cs2-signature-list.md - wiki/sources/descriptions/FrySimpl3__SDK_CS2.md - wiki/sources/descriptions/HLND2T__CS2_VibeSignatures.md - wiki/sources/descriptions/gmh5225__pmctrace.md - wiki/sources/descriptions/gmh5225__PMI-hpc.md - wiki/sources/descriptions/gmh5225__PDF-PMC-X86.md - wiki/sources/descriptions/intelpt__winipt.md - wiki/sources/descriptions/intelpt__processor-trace.md - wiki/sources/descriptions/intelpt__WindowsIntelPT.md - wiki/sources/descriptions/australeo__libipt-rs.md - wiki/sources/descriptions/libgdx__libgdx.md - wiki/sources/descriptions/marakew__syser.md - wiki/sources/descriptions/illegal-instruction-co__processhacker-mcp.md - wiki/sources/descriptions/imugee__xdv.md - wiki/sources/descriptions/igromanru__Dark-Souls-III-Cheat-Engine-Guide.md - wiki/sources/descriptions/idkhidden__DrawIDA.md - wiki/sources/descriptions/hyuunnn__Hyara.md - wiki/sources/descriptions/AyinSama__Anti-AntiDebuggerDriver.md - wiki/sources/descriptions/AzzOnFire__yarka.md - wiki/sources/descriptions/hyuunnn__ida-slides.md - wiki/sources/descriptions/icsharpcode__ILSpy.md - wiki/sources/descriptions/marblexu__PythonPlantsVsZombies.md - wiki/sources/descriptions/notahacker8__RobloxCheats.md - wiki/sources/descriptions/LyeDevGit__WonTree-RBLX-Dumper.md - wiki/sources/descriptions/mandiant__dncil.md - wiki/sources/descriptions/mandiant__GoReSym.md - wiki/sources/descriptions/magnussen7__Embuche.md - wiki/sources/descriptions/mahaloz__DAILA.md - wiki/sources/descriptions/litemars__hARMless.md - wiki/sources/descriptions/linuxboot__fiano.md - wiki/sources/descriptions/longqun__Packer.md - wiki/sources/descriptions/cycraft-corp__BinaryAnalysisMCPs.md - wiki/sources/descriptions/cyberus-technology__virtualbox-kvm.md - wiki/sources/descriptions/cxxrev0to1dev__nb_obfuscator.md - wiki/sources/descriptions/ch3rn0byl__ANTfs.md - wiki/sources/descriptions/ch4ncellor__CSGO-P2C-Dumper.md - wiki/sources/descriptions/csgohacks__master-guide.md - wiki/sources/descriptions/click4dylan__CSGO_AnimationCode_Reversed.md - wiki/sources/descriptions/cseagle__blc.md - wiki/sources/descriptions/crytic__ida-evm.md - wiki/sources/descriptions/cursey__x64-virtualizer-rs.md - wiki/sources/descriptions/cursey__regenny.md - wiki/sources/descriptions/cursey__sdkgenny.md - wiki/sources/descriptions/cursey__ue4genny.md - wiki/sources/descriptions/czs108__PE-Packer.md - wiki/sources/descriptions/hid3rx__PEPacker.md - wiki/sources/descriptions/jnastarot__shibari.md - wiki/sources/descriptions/jnastarot__furikuri.md - wiki/sources/descriptions/lzyddf__IDA_Plugin_PCodeGPT.md - wiki/sources/descriptions/loyaltypollution__ida2llvm.md - wiki/sources/descriptions/lstaroth__AntiXorstr.md - wiki/sources/descriptions/lowleveldesign__comon.md - wiki/sources/descriptions/long123king__dk.md - wiki/sources/descriptions/mahmoudimus__ida-sigmaker.md - wiki/sources/descriptions/mahmoudimus__ida-taskr.md - wiki/sources/descriptions/mandiant__flare-vm.md - wiki/sources/descriptions/mandiant__ShimCacheParser.md - wiki/sources/descriptions/fatalSec__DaliVM.md - wiki/sources/descriptions/eybisi__kavanoz.md - wiki/sources/descriptions/loerting__dalvikus.md - wiki/sources/descriptions/kernelstub__Retract.md - wiki/sources/descriptions/kernelstub__Cognitor.md - wiki/sources/descriptions/keowu__sjcam.md - wiki/sources/descriptions/keowu__koidbg.md - wiki/sources/descriptions/keowu__Ryujin.md - wiki/sources/descriptions/ke0z__VulChatGPT.md - wiki/sources/descriptions/katahiromz__RisohEditor.md - wiki/sources/descriptions/index-login__MobileRE-Skill.md - wiki/sources/descriptions/google__android-classyshark.md - wiki/sources/descriptions/gmh5225__PUBGSTAR.md - wiki/sources/descriptions/g2wfw__qbdi-tracer-android.md - wiki/sources/descriptions/rollingrock__bethesda-modding-starter.md - wiki/sources/descriptions/cheat-engine__cheat-engine.md - wiki/sources/descriptions/cheat-engine__ControllerMode.md - wiki/sources/descriptions/clearbluejar__ghidriff.md - wiki/sources/descriptions/allthingsida__idasql.md - wiki/sources/descriptions/allthingsida__idacpp.md - wiki/sources/descriptions/TrungNguyen1909__aarch64-sysreg-ida.md - wiki/sources/descriptions/ThatLing__limba.md - wiki/sources/descriptions/TheAenema__hm-pe-packer.md - wiki/sources/descriptions/ATsahikian__pe-protector.md - wiki/sources/descriptions/89luca89__pakkero.md - wiki/sources/descriptions/TheCruZ__FindXrefs.md - wiki/sources/descriptions/TheHolyOneZ__Zircon-UE-Dumper.md - wiki/sources/descriptions/SwagSoftware__Kisak-Strike.md - wiki/sources/descriptions/SinaKarvandi__Hypervisor-From-Scratch.md - wiki/sources/descriptions/Snoopy-Sec__Localroot-ALL-CVE.md - wiki/sources/descriptions/FreeER__CE-Examples.md - wiki/sources/descriptions/FreeER__CE-Extensions.md - wiki/sources/descriptions/Skyrimfus__CE-lua-extensions.md - wiki/sources/descriptions/Skengdo__battlefield-2042-internal-sdk.md - wiki/sources/descriptions/SilentVoid13__Silent_Packer.md - wiki/sources/descriptions/Siesta__MCORE-Decompiler.md - wiki/sources/descriptions/Sidenai__hyperion-disassembler.md - wiki/sources/descriptions/Hydr8gon__3Beans.md - wiki/sources/descriptions/HyperDbg__HyperDbg.md - wiki/sources/descriptions/HoLLy-HaCKeR__dnSpy.Extension.HoLLy.md - wiki/sources/descriptions/HitmanHimself__GOWTool.md - wiki/sources/descriptions/HeathHowren__Pointer-Lab.md - wiki/sources/descriptions/Hexorg__CheatEngineTables.md - wiki/sources/descriptions/Hexorg__Ouroboros.md - wiki/sources/descriptions/HexRaysSA__rax.md - wiki/sources/descriptions/HexRaysSA__ida-cyberchef.md - wiki/sources/descriptions/HexRaysSA__ida-claude-code-plugins.md - wiki/sources/descriptions/HexRaysSA__goomba.md - wiki/sources/descriptions/HoShiMin__Kernel-Bridge.md - wiki/sources/descriptions/GunshipPenguin__kiteshield.md - wiki/sources/descriptions/HackOvert__AntiDBG.md - wiki/sources/descriptions/HEEAAP__Sentinel-Anti-Cheat.md - wiki/sources/descriptions/CheckPointSW__Nodejs-Tracer.md - wiki/sources/descriptions/CheckPointSW__showstopper.md - wiki/sources/descriptions/CasualX__apexdream.md - wiki/sources/descriptions/CasualX__obfstr.md - wiki/sources/descriptions/GravitLauncher__Avanguard.md - wiki/sources/descriptions/Speedi13__ROP-COMPILER.md - wiki/sources/descriptions/NHCM-dev__BytecodeVM.md - wiki/sources/descriptions/GameHackingBook__GameHackingCode.md - wiki/sources/descriptions/Gekkio__GhidraBoy.md - wiki/sources/descriptions/Gezine__BD-UN-JB.md - wiki/sources/descriptions/GJDuck__e9patch.md - wiki/sources/descriptions/GAMMACASE__PltPatcher.md - wiki/sources/descriptions/10HEAD__ValorantOffsets.md - wiki/sources/descriptions/GLX-ILLUSION__valorant-offsets-autoupdater.md - wiki/sources/descriptions/Berk000x__BinaryLens.md - wiki/sources/descriptions/Ahora57__RaceCondition.md - wiki/sources/descriptions/Ahmadmansoor__x64dbgScript.md - wiki/sources/descriptions/Air14__HyperHide.md - wiki/sources/descriptions/Air14__KDBGDecryptor.md - wiki/sources/descriptions/Adepts-Of-0xCC__MiniDumpWriteDumpPoC.md - wiki/sources/descriptions/AdvDebug__AntiCrack-DotNet.md - wiki/sources/descriptions/AdvDebug__Brovan.md - wiki/sources/descriptions/Maxamedxasa__SakoREStudio.md - wiki/sources/descriptions/piffd0s__Defcon-Dreamcast-Planetweb-Research.md - wiki/sources/descriptions/416rehman__DeepZero.md - wiki/sources/descriptions/19h__eac-analysis.md - wiki/sources/descriptions/4d61726b__VirtualKD-Redux.md - wiki/sources/descriptions/0vercl0k__wtf.md - wiki/sources/descriptions/0xbigshaq__apatchy.md updated: 2026-09-15 confidence: high --- # Reverse Engineering Workflows for protected game clients and anti-cheat components across user mode, kernel, and hypervisor-aware environments: debug/disassemble, DBI, deobfuscation, dump analysis, and IOCTL/callback mapping. Pair [[research-rigor]] when converting tool claims or detector observations into consequential conclusions. (source: wiki/sources/skills/reverse-engineering.md) Record the **artifact hash, format, architecture, tool version, environment, and observed addresses** before drawing conclusions. Separate static inference from runtime evidence and label protection-induced uncertainty. See [[static-runtime-evidence]] for the baseline table and static/runtime finding limits. (source: wiki/sources/skills/reverse-engineering.md) ## Topic routing | Question lane | Route | |---------------|-------| | Binary findings, debuggers, disassemblers, memory tools, DBI | [[binary-evidence]], [[static-runtime-evidence]]; Binary evidence + DBI sections below; [[dynamic-binary-instrumentation]] | | Anti-analysis, game targets, workflow, obfuscation | Workflow + Obfuscation recovery sections; [[mixed-boolean-arithmetic]], [[control-flow-flattening]]; [[overviews/game-engine]] | | Plugins, MCP tools, diffing, anti-debug, virtualization, exploit analysis | MCP-assisted RE + Anti-analysis sections; [[binary-diffing]] | | Repository resource selection | [[resource-selection]], [[repository-navigation]] | | Kernel contracts dominate | [[overviews/windows-kernel]], [[driver-trust-boundaries]] | | Engine models dominate | [[overviews/game-engine]], [[il2cpp]], [[unreal-object-model]], [[source-netvars]] | | Disputed implementation or detectability claims | [[research-rigor]] | Use sibling skill topics when one boundary dominates the question. (source: wiki/sources/skills/reverse-engineering.md) ## Binary evidence Classify the investigative question and preserve address provenance before selecting tools or stating defensive implications. See [[binary-evidence]] for the full question/evidence table, decompiler-reconstruction limits, and finding granularity (imported API vs reachable path vs observed call); [[static-runtime-evidence]] for artifact baseline and static/runtime separation. | Question | Preserve in the report | |----------|------------------------| | Interface abuse | Input origin, callers, privilege, validation—reachable code ≠ proof of invocation | | Integrity tampering | Comparison-data provenance and collector trust | | Packing/obfuscation | Representation uncertainty—obfuscation alone ≠ maliciousness | | Anti-analysis behavior | Environment conditions and observation coverage gaps | | Security-relevant binary change | Semantic delta vs compiler/library/layout noise | Keep file offsets, RVAs, and runtime addresses distinct; validate decompiler types and boundaries against instructions and ABI constraints. For native Linux or Proton targets, route platform context through linux-platform-security before attributing Windows-centric findings. Full-pipeline commercial AC reconstruction archives such as [[xigncode3-blackdesert]] (Black Desert XIGNCODE3: `xmag`/`xnina` container unpack, Ghidra decompilation of native modules, Lua 5.3 recovery, VMProtect `xhunter1` triage, IPC/detection specs, PowerShell live capture) complement captured client-module dumps like [[xigncode-dump]] (gmh5225; modding / offline RE; cheat / explore anticheat:xigncode), narrower exploit PoCs like [[xign-poc-april-2026]], hooking/memory-analysis bypass samples such as [[xigncode3-bypass-alternative]] (C++; cheat / explore anticheat:xigncode), and NetEase NeacSafe client–driver minifilter communication-port RE via [[neacsafe-analysis]] (user-mode probe + saved Pediy notes; `\NeacSafePort` protocol reproduction; gmh5225). (source: wiki/sources/descriptions/miyakejima__xigncode3-blackdesert.md) (source: wiki/sources/descriptions/gmh5225__XignCode-Dump.md) (source: wiki/sources/descriptions/gmh5225__XignCode3-bypass-alternative.md) (source: wiki/sources/descriptions/gmh5225__NeacSafe-Analysis.md) ## Workflow **Initial analysis:** identify protections (packer, obfuscator, anti-cheat), game engine and version, available symbols, and key modules with their callbacks and trust boundaries. Multi-format static recovery pipelines such as [[disrobe]] (1-3-7; Rust CLI; automatic unpack/deobfuscate/decompile for native PE packers, Python protections, APKs, WASM, JVM/.NET/Go/JS bytecode, and nested archives; Ghidra integration; Python/TypeScript bindings; benchmark harnesses; source: wiki/sources/descriptions/1-3-7__disrobe.md) can accelerate protection triage before deep manual RE. **Deep analysis:** locate target functionality, trace execution flow, document structures and memory artifacts, and correlate IOCTLs, kernel callbacks, and runtime integrity checks. EAC driver integrity-check deobfuscation such as [[bypassing-easyanticheat-integrity-check]] (gmh5225; Capstone-based garbage-instruction stripper reveals obfuscated EAC `.sys` integrity logic; reconstructed C++ for section-by-section driver-copy compare; CreateProcess/LoadImage notify hooks) complements reversed-source and decompile dumps when mapping AC self-protection routines. (source: wiki/sources/descriptions/gmh5225__Bypassing-EasyAntiCheat-Integrity-check.md) Linux EAC userland VM reconstruction such as [[eac-analysis]] (19h; `eac.elf` dlopen/trace harness; dispatch/VMTAIL recovery; bytecode→IR/CFG; handler ISA; static path replay; MBA reducers; GDB-assisted dynamic tracing) extends that lane to VM-protected ELF clients beside Windows kernel/driver dumps. (source: wiki/sources/descriptions/19h__eac-analysis.md) Memflow external-VM dossiers such as [[all-about-eac]] (BishopTopG; passive physical-memory acquisition from outside a Windows VM; maps one captured `EasyAntiCheat_EOS.sys` build's kernel callbacks, minifilter policy, device IPC, and per-thread callback contexts with evidence-labeled claims; Cheat / Explore AntiCheat System:EAC) add reproducible out-of-guest EAC kernel-surface documentation beside disk dumps and IDA decompiles. (source: wiki/sources/descriptions/BishopTopG__all-about-eac.md) Scriptable kernel drivers such as [[pawnio]] (namazso; Pawn AMX VM in a WDK `.sys`; signed module load + IOCTL dispatch; phys/virt memory, MSR/PCI, CPUID, CR/DR, I/O ports, SMM natives) support iterative low-level hardware and driver probing without per-experiment driver rebuilds. (source: wiki/sources/descriptions/namazso__PawnIO.md) Lua-in-kernel PoC such as [[ntlua]] (can1357; Lua 5.4 in a kernel driver with UM script dispatch; scripted ring-0 memory/process/MSR introspection) complements Pawn and PHP embedding when prototyping driver-side probes. (source: wiki/sources/descriptions/can1357__NtLua.md) Educational kernel memory-manager probes such as [[wkpe]] (am0nsec; PoC drivers + user tools; process VAD structure walks; version/symbol-tied Windows builds; controlled kernel RE) complement scriptable driver lanes when studying MM internals. (source: wiki/sources/descriptions/am0nsec__wkpe.md) Defensive EAT hook detection such as [[eat-guard]] (connormcgarr; VEH + PAGE_GUARD monitors Export Address Table pages of loaded modules; logs overwrite attempts on exported pointers) illustrates runtime export-table integrity research beside IAT/EAT hook tradecraft. (source: wiki/sources/descriptions/connormcgarr__EATGuard.md) User-mode IOCTL repeaters such as [[ioctlpus]] (VoidSec; C# WinForms + CLI; craft/replay/save/edit DeviceIoControl with arbitrary buffers; driver interface auditing and fuzzing prep) and [[ioctl-helper]] (RomanRybachek; C++/Qt GUI with integrated hex editor; multi-device handle management; driver reversing and kernel comm testing) complement filter-driver tracers [[cfb]]/[[drvtrace]] when actively probing known IOCTL codes. (source: wiki/sources/descriptions/VoidSec__ioctlpus.md) (source: wiki/sources/descriptions/RomanRybachek__ioctl_helper.md) Kernel-side IOCTL hook/dump tooling such as [[ioctldump]] (Kharos102; intercepts and logs IOCTL metadata and deduplicated input buffers from selected target drivers via WDK driver + client; anti-cheat and security-sensitive kernel comm RE; README [Monitor IRP]) complements those tracers when passively mapping proprietary driver interfaces. (source: wiki/sources/descriptions/Kharos102__IOCTLDump.md) Lightweight IDA context-menu [[copy-rva]] (RomanRybachek; Python IDAPython; copies cursor RVA to clipboard for WinDbg breakpoints on drivers without public symbols) speeds static-to-live offset handoff in kernel/driver RE. (source: wiki/sources/descriptions/RomanRybachek__Copy_RVA.md) Engine-specific paths: Unity ([[il2cpp]] / Mono via [[dnspy]]; soft-debugger runtimes from [[dnspy-unity-mono]]; wire-protocol client [[mono-debugger-soft]]; official managed reference [[unity-cs-reference]] for engine/editor C# internals; unofficial ILSpy-decompiled Unity 5.x assembly mirror [[unity-decompiled]] for legacy editor/engine API study (source: wiki/sources/descriptions/00christian00__UnityDecompiled.md); production FPS sample [[fpssample]] for anim/state-machine and netcode architecture study), Unreal (SDK generators, UObject/UFunction hooks), native PE (imports, pattern scan, runtime memory). Title-specific native PE pattern-scan workflows such as [[r3nzskin]] (Kurok00; C++ DLL injector; pattern scanning for post-update LoL offsets; Python automated pattern updaters; community pattern scripts with [[ksdumper-11]] integration; cheat / game:lol `[Skin]`) illustrate runtime offset recovery beside dump-only tooling such as [[lol-offset-dumper]]. (source: wiki/sources/descriptions/Kurok00__R3nzSkin.md) Title-specific R6 offset maintenance such as [[r6-updater]] (Kix48; C++ Windows; pattern scan + memory modules for manager/offset recovery after Siege updates; cheat / game:r6 [Dump]) extends that post-patch signature-refresh lane beside full cheat dumpers such as [[r6-cheat-dumper]]. (source: wiki/sources/descriptions/Kix48__R6Updater.md) Title-specific Valorant offset maintenance such as [[valorant-offsets-autoupdater]] (GLX-ILLUSION; C++ Windows; JSON offset store + network fetch; incremental refresh without full loader rebuild; cheat / game:valorant `[Offset]`) extends that lane beside static feeds such as [[valorant-offsets]]. (source: wiki/sources/descriptions/GLX-ILLUSION__valorant-offsets-autoupdater.md) Lightweight Valorant offset packs such as [[valorantoffsets]] (10HEAD; C/C++ memory and function constants; minimal repo focused on quick patch-tracked updates for external RE and automation toolchains; cheat / game:valorant `[Offset]`) complement that lane beside header-only dumps. (source: wiki/sources/descriptions/10HEAD__ValorantOffsets.md) Apex Legends static PE offset recovery via [[apexdream]] (CasualX; Rust `apexdumper`; pelite-based PE analysis for classes, convars, datamaps, recv tables, interfaces → `gamedata.ini`; complements live-process dumpers such as [[apex-legends-offset-dumper]]; Respawn/Source-style internals RE; cheat / game:apex legends [Offset]) extends that post-patch layout lane with offline binary analysis. (source: wiki/sources/descriptions/CasualX__apexdream.md) Apex Legends external cheat/SDK samples with bundled Rust offset dumpers such as [[astronaut00-apex-external]] (Astronaut00; C++ external + ImGui overlay; companion Rust component for game structure offset maintenance; cheat prototyping + RE experiments; outdated implementation notes; cheat / game:apex legends [External/Offset]) complement live-process dumpers in the same title lane. (source: wiki/sources/descriptions/Astronaut00__apex-external.md) (source: wiki/sources/descriptions/dnSpy__Mono.Debugger.Soft.md) (source: wiki/sources/descriptions/Unity-Technologies__UnityCsReference.md) (source: wiki/sources/descriptions/Unity-Technologies__FPSSample.md) Source 1 internal hook RE samples such as [[csgo-findmdl]] (Kruziikrel1; FindMDL model-changer hook; interface wrappers, offset handling, VMT utilities; injector-loaded DLL; cosmetic MDL path replacement study) complement SDK/offset tooling such as [[csgo-sdk]] when learning engine callback interception. (source: wiki/sources/descriptions/Kruziikrel1__CSGO-FindMDL.md) ## Dynamic binary instrumentation Full DBI frameworks — [[frida]], DynamoRIO, Pin, [[tinyinst]], QBDI — support API hooking, coverage, fuzz harnesses, and driver IOCTL/callback tracing. See [[dynamic-binary-instrumentation]] for the full taxonomy. Bitdefender **RIVER** ([[river]]; Runtime Inspector and Versatile Engine for Reversing) pairs a custom ELF/PE binary loader (external mapping, native import resolution) with runtime instrumentation for x86 dynamic analysis — aimed at malware analysts and binary-loading-framework research. (source: wiki/sources/descriptions/bitdefender__river.md) **MAMBO** ([[mambo]]; beehive-lab; low-overhead ARM/AArch64 Linux DBI via software code cache; instruction callbacks, basic-block tracing, function interception, analysis plugins; transparent on unmodified binaries; cheat / DBI / ARM) complements x86-centric DBI stacks on Linux ARM hosts. (source: wiki/sources/descriptions/beehive-lab__mambo.md) Android ARM64 per-instruction native tracing via [[qbdi-tracer-android]] (QBDI + [[dobby]]; linker SO-load intercept, backtrace + memory/pattern utilities; CMake Android/iOS/ARM64; cheat / assembly instruction tracing). (source: wiki/sources/descriptions/g2wfw__qbdi-tracer-android.md) Google Project Zero **TinyInst** (C/C++; lightweight module-selective DBI; hooking / debugging) sits in that lightweight instrumentation lane. (source: wiki/sources/descriptions/googleprojectzero__TinyInst.md) **Dr. Memory** ([[drmemory]]; DynamoRIO-based dynamic memory debugger; uninitialized reads, OOB, UAF, double-free, leaks; Windows handle/GDI checks; unmodified binaries on Windows/Linux/macOS/Android; IA-32/AMD64/ARM; software hardening and game/anti-cheat reliability testing) complements coverage DBI such as [[winafl]] in the native memory-safety lane. (source: wiki/sources/descriptions/DynamoRIO__drmemory.md) Experimental Windows x86-64 DBI via [[covcane]] (ZehMatt; C++; loader + instrumentation runtime; translation/rewriting/memory/exception handling; Zydis + AsmJIT; cheat / DBI) complements decode/codegen peers such as [[zyemu]]. (source: wiki/sources/descriptions/ZehMatt__CovCane.md) CUDA kernel instruction tracing via [[cutracer]] (facebookresearch; lightweight GPU-side instrumentation vs host-side analysis) complements static PTX tooling such as [[ptxninja]]. (source: wiki/sources/descriptions/facebookresearch__CUTracer.md) **Trap-and-emulate control-flow tracing (CFT):** patch branch sites with fault-generating sentinels (e.g. HLT/SALC, avoiding INT3 integrity scans), catch exceptions, emulate the original branch, log context, restore, and continue. Strategies range from bounded bulk patching (simple, integrity-detectable) through branch chasing and CFG-guided patching (better coverage/safety tradeoff). PAGE_GUARD + trap-flag single-steping avoids direct `.text` patches but remains timing- and guard-state detectable. Illustrative corpus: [[cpp-veh-dbi]], [[w1tn3ss]]. Debugger-assisted encrypted-pointer recovery such as [[decryption-dumper]] (Nuxar1; Windows C++; launches target under debugger, single-steps with Zydis disassembly, tracks register/stack dependencies until decryption output resolves; pattern scan, context restore, instruction filtering; cheat / `[Dump]`) complements CFT when reconstructing live AC-protected pointer decrypt routines in game binaries. (source: wiki/sources/descriptions/Nuxar1__DecryptionDumper.md) **User-mode hypervisor-assisted tracing:** Windows Hypervisor Platform (WHP) hosts guest snippets with per-page R/W/X traps, CPUID interception, and syscall emulation — no kernel driver, composable with disassemblers/emulators. WHP trap libraries such as [[vmtrace]] (host-backed guest memory, page traps, VM-exit single-step tracing; asmjit) sit beside full x64 PE emulators like [[winvisor]] and Hyper-V introspection such as [[hyper-rev]]; benchmark latency and nested-VT constraints on the target build. (source: wiki/sources/descriptions/momo5502__vmtrace.md) Kernel VT-x learning tutorials such as [[hypervisor-from-scratch]] (SinaKarvandi; step-by-step x86 hypervisor build—VMX, VMCS, EPT, running-system virtualization; pairs with [[hv]] and hacked-HV detection research) complement WHP user-mode tracing when studying hardware-assisted analysis foundations. (source: wiki/sources/descriptions/SinaKarvandi__Hypervisor-From-Scratch.md) **Hardware-assisted tracing (LBR/BTS / Intel PT / AMD IBS):** Intel Last Branch Record and Branch Trace Store capture branch-level control flow from CPU branch-recording registers via kernel-mode register access — no software instrumentation patches. Research frameworks such as [[branch-monitoring-project]] (C kernel driver + usermode collection/analysis; PMI lane) and Intel hardware-trace libraries such as [[libiht]] (Tencent Xuanwu Lab; Intel Hardware Trace Library) complement trap-and-emulate CFT and Intel-PT hypervisor fuzzing ([[qemu-nyx]]). Coverage-guided Windows binary fuzzing via [[winafl]] (AFL port; DynamoRIO or Intel PT instrumentation; persistent in-process mode; target-function hooking; corpus minimization + crash triage) targets closed-source apps, drivers, and parsers on Windows hosts. (source: wiki/sources/descriptions/googleprojectzero__winafl.md) Distributed snapshot-based fuzzing via [[wtf]] (0vercl0k; C++; coverage-guided; emulator and virtualization snapshot backends for user-mode and kernel-mode; corpus/coverage/trace tooling; Windows primary + experimental Linux; game components, drivers, system services) extends that lane with fast reset via VM snapshots. (source: wiki/sources/descriptions/0vercl0k__wtf.md) WinDbg VM snapshot capture via [[snapshot]] (0vercl0k; Rust WinDbg extension; JSON CPU state + physical memory crash dump; full-kernel/active-kernel modes; companion to [[wtf]]; kernel/user-mode vulnerability RE) feeds that workflow from live x64 kernel debug sessions. (source: wiki/sources/descriptions/0vercl0k__snapshot.md) Server-side HTTP parser fuzzing via [[apatchy]] (0xbigshaq; Python; replaces Apache HTTPD socket layer with custom I/O filters feeding raw bytes into real request-pipeline code paths; CVE reproducers + Apache internals docs—memory pools, hooks, filters, buckets; HTTP parsing attack-surface research) complements that Windows-centric coverage lane. (source: wiki/sources/descriptions/0xbigshaq__apatchy.md) Fuzz target discovery via [[fuzzable]] (C/C++ source + binary integration; identifies viable function targets for harness setup; cheat / Binary Ninja plugins lane) complements that coverage-guided workflow. (source: wiki/sources/descriptions/ex0dus-0x__fuzzable.md) Application Verifier fault injection via [[vfdynf]] (jxy-s; DynFault provider; stack-hash-based low-resource simulation; hooks wait/heap/VM/registry/file APIs; optional buffer fuzzing for TOCTOU; PCRE2 path exclusions; `vfdynf.dll`; robustness/vuln discovery) complements coverage-guided fuzzing on Windows user-mode targets. (source: wiki/sources/descriptions/jxy-s__vfdynf.md) Windows-native IPT capture via [[winipt]] (`ipt.sys` wrapper; per-process/per-CPU trace buffer management), Rust `ipt.sys` driver-interaction library [[libipt-rs]] (DeviceIoControl start/stop/retrieve; RE-derived interface; capture-only; no decode/coverage) (source: wiki/sources/descriptions/australeo__libipt-rs.md), and [[windows-intel-pt]] (own KM driver + user-mode API; IPT MSR configuration; per-process and system-wide modes; coverage, fuzzing, execution tracing) extends that lane on Windows hosts; decode raw PT streams with [[processor-trace]] (libipt; Intel reference packet/instruction decoder; timing, control flow, multi-format trace reconstruction). ROP/JOP-oriented Windows exploit-detection research via [[pt-detector]] (DProvinciani; KM+UM Intel PT capture; decodes execution streams for suspicious control-flow behavior; C/C++ infrastructure + Python analysis; README [Intel PT]) (source: wiki/sources/descriptions/DProvinciani__pt-detector.md) extends that lane toward control-flow integrity experimentation; [[ingsoc]] (CristiNacu; Windows Intel PT toolkit; KM driver + user-mode controller + Python decoder; optional Kafka trace streaming; execution reconstruction + control-flow/timing visual analytics; exploit/malware behavior + code-reuse research; README [Intel PT]) (source: wiki/sources/descriptions/CristiNacu__ingsoc.md) adds a full-stack PT pipeline with stream analytics. Intel official PMU / bandwidth / PCIe telemetry via [[intel-pcm]] (Performance Counter Monitor; CPU metrics, memory bandwidth, PCIe throughput, power; Docker/CXL; cheat / Windows kernel explorer) complements that lane for system-level counter profiling without IPT decode; [[pmctrace]] (C; ETW-backed real-time PMC reads; micro-architectural events; side-channel / program-analysis RE) offers lightweight counter access beside that official stack; [[pmi-hpc]] (PMI + HPC interrupt-driven monitoring; branch misprediction / cache-miss events; code injection / ROP anomaly detection) extends the PMU lane toward hardware-assisted exploit-pattern detection; [[perfmon]] (KelvinMsft; kernel research driver; PMU/PMI + APIC interrupt paths; SSDT monitoring + hook-style interception; reference papers + test program; README PMI Callback) (source: wiki/sources/descriptions/KelvinMsft__PerfMon.md) documents foundational hardware-assisted monitoring on Win10-era builds; [[driver-intel-pebs-loophpcs]] (gmh5225; LoopHPCs filter driver; PEBS eventing/next/data IPs + LBR control-flow context → loop-centric hot-loop telemetry; unpacker/malware RE) complements raw PMC counters in that lane; [[pdf-pmc-x86]] (PDF study on x86 PMC/PMI; documentation archive for counter telemetry and Windows security research) provides background reference material beside that tooling stack. (source: wiki/sources/descriptions/marcusbotacin__BranchMonitoringProject.md) (source: wiki/sources/descriptions/gmh5225__pmctrace.md) (source: wiki/sources/descriptions/gmh5225__PMI-hpc.md) (source: wiki/sources/descriptions/gmh5225__Driver-intel-PEBs-LoopHPCs.md) (source: wiki/sources/descriptions/gmh5225__PDF-PMC-X86.md) (source: wiki/sources/descriptions/libiht__libiht.md) (source: wiki/sources/descriptions/intelpt__winipt.md) (source: wiki/sources/descriptions/intelpt__processor-trace.md) (source: wiki/sources/descriptions/intelpt__WindowsIntelPT.md) (source: wiki/sources/descriptions/intel__pcm.md) On AMD CPUs, Instruction-Based Sampling via [[amd-ibs-toolkit]] (hardware instruction subset sampling; cheat / Windows kernel explorer / AMD Sampling) offers a parallel low-overhead profiling lane for kernel and cheat hot-path study. (source: wiki/sources/descriptions/jlgreathouse__AMD_IBS_Toolkit.md) ## Obfuscation recovery | Layer | Concept | Recovery tools (corpus) | |-------|---------|-------------------------| | MBA | [[mixed-boolean-arithmetic]] | [[cobra]], [[mbased]], [[mba]], [[goomba]] (HexRaysSA; C++ Hex-Rays decompiler plugin; linear/non-linear MBA simplify; algebraic heuristics + optional fingerprint-oracle; Z3 soundness checks; source: wiki/sources/descriptions/HexRaysSA__goomba.md), [[gamba]] (DenuvoSoftwareSolutions; Python linear/nonlinear MBA simplifier + bitwise expression factory + NeuReduce/QSynth/Syntia datasets; source: wiki/sources/descriptions/DenuvoSoftwareSolutions__GAMBA.md), [[mba-wasm]], [[gnn-deobfuscation]], [[promba]], [[msynth]] (Python; oracle-backed AST simplification + Smir stochastic synthesis; Miasm + optional SMT verify; source: wiki/sources/descriptions/mrphrazer__msynth.md), [[qsynthesis]], [[drill-and-join]], [[mutaben]], [[mba-obfuscator]], [[mixed-boolean-transform]], [[limba]], [[obfuscation-analysis]] | | CFF | [[control-flow-flattening]] | [[idadeflat]], [[ollvm-unflattener]] (Miasm symbolic exec; BFS call following; deobfuscated binary output; Win/Linux x86/x64; JbvrgtonYT fork with graph viz + sample binaries; source: wiki/sources/descriptions/cdong1012__ollvm-unflattener.md; source: wiki/sources/descriptions/JbvrgtonYT__ollvm-unflattener.md), [[anti-ollvm]] (IIIImmmyyy; C# Arm64 simulated execution; dispatcher pattern ID + if-else CFG rebuild; Python IDA CFG extract + Keystone codegen; fake runtime; source: wiki/sources/descriptions/IIIImmmyyy__AntiOllvm.md), [[d810]] (CKCat; Python IDA Pro plugin; deobfuscate at decompilation time via Hex-Rays microcode rewrite; configurable extensible rule sets; malware/game-security RE; source: wiki/sources/descriptions/CKCat__d810.md), [[d810-ng]], [[hex-rays-deob]] (Hex-Rays microcode; expr simplify + CFF unflatten; RolfRolles; source: wiki/sources/descriptions/RolfRolles__HexRaysDeob.md), [[hrtng]] (KasperskyLab; C++ IDA/Hex-Rays plugin; CFF unflatten, de-inlining, API-hash scan, microcode sigs, string/data decrypt, patching; source: wiki/sources/descriptions/KasperskyLab__hrtng.md), [[emotet-deobfuscator]] (ElvisBlue; Python IDA Hex-Rays plugin; Emotet CFF via microcode API; dispatcher register/status ID + block transition rewrite; source: wiki/sources/descriptions/ElvisBlue__emotet-deobfuscator.md), [[obpo-plugin]], [[unflat]] (Python unflattener plugins; Fix OLLVM), [[obfuscation-detection]], [[ghidra-obfuscation-detection]] (Deatty; Java Ghidra script; heuristic function-body feature extraction flags obfuscated or unusually complex functions for triage; source: wiki/sources/descriptions/Deatty__Ghidra-Obfuscation-Detection.md), [[misc]] (Genshin CFG decode), [[genshinjumpfixer2]] (Genshin jump-target CFG simplify), [[anti-mihoyo-jcc-obfuscate]] (DNLINYJ; C++ x64dbg plugin; runtime JCC/jump-based control-flow deobfuscation for protected Unity/miHoYo code paths; monitors decryption ranges, tracks dynamic jumps, patches instructions during debug; build-offset-specific; unmaintained; source: wiki/sources/descriptions/DNLINYJ__Anti_miHoYo_Jcc_Obfuscate.md), [[deobfbr]] (Mrack; Python; Unicorn+Capstone+Keystone ARM64 branch-obfuscation deobf in ELF `.so`; function range in/out; libtprt.so; source: wiki/sources/descriptions/Mrack__DeObfBR.md), [[xrefgen]] (seifreed; Python IDA; indirect control-flow xref recovery + CFF/opaque-predicate detection; XRefer-compatible export; source: wiki/sources/descriptions/seifreed__xrefgen.md) | | Opaque predicates | invariant injection | [[opaque-predicates-detective]], [[opaque-predicate-patcher]] (Binary Ninja; Python; MLIL branch-condition analysis; patch always/never branch; iterative re-analysis; Vector35; source: wiki/sources/descriptions/Vector35__OpaquePredicatePatcher.md), [[native-predicate-solver]] (Binary Ninja; native C++; MLIL conditional-branch analysis; single-function/whole-binary passes; configurable limits; multithreaded; ScriptWare-Software; source: wiki/sources/descriptions/ScriptWare-Software__native-predicate-solver.md), [[drill-and-join]] (Drill & Join + Bitwuzla; 64-bit opaque-predicate / MBA simplification; source: wiki/sources/descriptions/fvrmatteo__DrillAndJoin.md), [[r2smt]] (radare2 + Z3/CVC5/Bitwuzla; fail-closed branch verdicts; reversible patches) (source: wiki/sources/descriptions/seifreed__r2SMT.md), Z3/SMT backends ([[stp]], [[smt-server]] (Rust QF_BV server; SMT-LIB 2; bit-blast→SAT; C++/Python clients; LLVMParty; source: wiki/sources/descriptions/LLVMParty__smt-server.md)) | | VM virtualization | VMProtect / Themida handlers; open x86 VM embed; Quake III `.qvm` bytecode | [[novmpy]], [[novmp]] (static VMProtect x64 3.x devirtualizer; VTIL lift/optimize; can1357; source: wiki/sources/descriptions/can1357__NoVmp.md), [[vmplift]] (emulation-first VMProtect 3.8–3.10+ x64 handler walker/lifter; VIP trace, rolling-key recovery, LLVM IR/pseudo-C/devirt emit; sexyiam; source: wiki/sources/descriptions/sexyiam__VMPLift.md), [[dragons-vs-vms]] (VMProtect x64 devirtualization lab; Binary Ninja VM trace; dragon-tales lift to IGNIL/LLVM IR; Z3 symbolic handler recovery; all 256 handler slots classified; serial-check sample + BN databases; Fare9; Cheat Fix VMP; source: wiki/sources/descriptions/Fare9__Dragons-vs-VMs.md), [[titan]] (VMProtect devirtualizer; Triton emulation/symbolic exec; AST handler matching; LLVM-oriented lift + CFG recovery; archercreat; source: wiki/sources/descriptions/archercreat__titan.md), [[vmprotect-devirtualization]] (experimental dynamic VMProtect 3.x pure-function deobfuscation; Intel Pin trace + Triton symbolic exec; LLVM IR lift for MBA simplification; JonathanSalwan; source: wiki/sources/descriptions/JonathanSalwan__VMProtect-devirtualization.md), [[vmp-devirtualization-lab]] (Android native VMP educational lab; mini-VM + dispatcher/handler recovery + symbolic lifting; QBDI/Unicorn/Triton/Frida; tomhamidi97-arch; source: wiki/sources/descriptions/tomhamidi97-arch__vmp-devirtualization-lab.md), tomhamidi97-arch/frida-vmp-bypass (Frida boundary-hook writeup for stacked Android VMProtect+OLLVM via libc/JNI/Java exit monitoring; spawn-mode injection; caller-address cross-ref; source: wiki/sources/descriptions/tomhamidi97-arch__frida-vmp-bypass.md), [[tde]], [[vmattack]] (IDA Pro Python plugin; dispatcher/handler-table trace + devirt assist for custom VM obfuscation; gmh5225; source: wiki/sources/descriptions/gmh5225__VMAttack.md), [[ida-zvm-disassembler]] (Duntss; IDA Pro processor module + loader; Zeus VM/ZVM custom bytecode; 69 instructions; XOR key-chain decrypt; branch-target xrefs + semantic auto-comments; OALabs ZVM lineage; source: wiki/sources/descriptions/Duntss__IDA-ZVM-Disassembler.md), [[magicmida-rs]], [[unlicense]] (Python 3 Frida dynamic unpacker; Themida/WinLicense 2.x/3.x OEP + IAT rebuild; native PE + .NET; source: wiki/sources/descriptions/ergrelet__unlicense.md), [[bobalkkagi]] (Python 3 Unicorn API-hook emulator; Themida 3.1.3 Tiger red64 unpack/unwrap; win10_v1903 DLL hooks; fast/hook_block/hook_code + optional OEP; planned devirt; source: wiki/sources/descriptions/bobalkkagi__bobalkkagi.md), [[ghidr-orean]] (Ghidra Python Oreans unvirtualizer; Deathway port; CISC complete + TIGER largely finished; RISC/FISH configs; main Orean script + configurable working directory; Themida/WinLicense/Code Virtualizer; Marisa-Chan; source: wiki/sources/descriptions/Marisa-Chan__GhidrOrean.md), [[themida-unmutate]] (Python 3 static mutation deobfuscator; Themida/WinLicense/Code Virtualizer 3.x; tested to Themida 3.1.9; source: wiki/sources/descriptions/ergrelet__themida-unmutate.md), [[themida-spotter-bn]] (Binary Ninja plugin; detect Themida/WinLicense/Code Virtualizer obfuscated code regions; x86/x64; Oreans ≤3.1.9; source: wiki/sources/descriptions/ergrelet__themida-spotter-bn.md), [[themidie]] (x64dbg plugin; C++ MinHook; neutralize Themida anti-debug/anti-VM/monitoring on x64 Windows; attach-and-debug workflow; not full unpack; VenTaz; source: wiki/sources/descriptions/VenTaz__Themidie.md), [[rumba]], [[vmpimportfixer]], [[vmp-vmp3-64bit-disasm-prerelease-]] (VMP3 x64 bytecode disasm; handler decode; gmh5225; source: wiki/sources/descriptions/gmh5225__VMP-Vmp3_64bit_disasm-prerelease-.md), [[vmp3-utils]] (Python VMP3 editor tooling; gmh5225; source: wiki/sources/descriptions/gmh5225__Vmp3_utils.md), [[vmp-helper]] (C++ VMP helper; networking / plugin / modding; Fix VMP; fjqisba; source: wiki/sources/descriptions/fjqisba__VmpHelper.md), [[vmprotect]] (software CPU VM obfuscation engine; gmh5225; source: wiki/sources/descriptions/gmh5225__VMProtect.md), [[vmpunpack]] (Python sogen emulation to OEP; PE rebuild; no devirt; source: wiki/sources/descriptions/milk-analyzer__vmpunpack.md), [[vmpunpacker]], [[vmp-unpacker]] (C++ dynamic VMProtect unpacker; Win32 debug attach; PEB/ntdll anti-debug bypass; OEP guards/snapshots; mutated IAT rebuild; passive import resolve; Lucyferek-nunu; source: wiki/sources/descriptions/Lucyferek-nunu__vmp-unpacker.md), [[vmprotect-dumper]] (whoamicrash; pure C WinAPI; live-memory VMProtect PE unpack; section-decrypt polling; OEP/IAT via thunk follow + API hooks; dynamic exec-region harvest; optional PE-sieve; IOC strings; password-protected artifact archive; source: wiki/sources/descriptions/whoamicrash__VMProtectDumper.md), [[themida-research]], [[phantasm-x86-virtualizer]], [[covirt]] (x86-64 stack-VM code virtualizer; PE MinGW + ELF; MBA + self-modifying code passes; marker-delimited regions; dmaivel; source: wiki/sources/descriptions/dmaivel__covirt.md), [[binary-shield]] (open-source bin2bin x86-64 code virtualizer; custom bytecode + purpose-built VM; connorjaydunn; source: wiki/sources/descriptions/connorjaydunn__BinaryShield.md), [[mk-pivm]] (process-independent PIVM obfuscation engine; x86/x64→custom IR→polymorphic VM bytecode with encrypted handlers; PE dispatcher embed; arbitrary shellcode input; D7EAD; source: wiki/sources/descriptions/D7EAD__mkPIVM.md), [[cerberus]] (ChaosVm Win32 PE bytecode VM; Qt GUI; source: wiki/sources/descriptions/gmh5225__cerberus.md), [[nocturne]], [[guardian-rs]] (Rust x86-64 code/PE virtualizer; three-component VM toolchain; source: wiki/sources/descriptions/felix-rs__guardian-rs.md), [[x64-virtualizer-rs]] (toy Rust x86-64 stack-VM obfuscator; iced-x86 lift; JIT vmenter/vmexit bridges; cursey; source: wiki/sources/descriptions/cursey__x64-virtualizer-rs.md), [[bytecodevm]] (Java JVM bytecode virtualizer; Gradle/ASM CLI; pure-Java interpreter; dispatch/threaded/polymorphic/register/FSM tiers; educational devirt study; NHCM-dev; source: wiki/sources/descriptions/NHCM-dev__BytecodeVM.md), [[vmpacker]] (Go ARM64 ELF VM code protector; native→custom bytecode; indirect dispatch, chained encryption, CRC integrity, function-split obfuscation; LeoChen-CoreMind; source: wiki/sources/descriptions/LeoChen-CoreMind__VMPacker.md), [[q3vm]] (embeddable AC dynamic-script VM; source: wiki/sources/descriptions/jnz__q3vm.md), [[minivm]] (small optimizing VM + JIT runtime; C11 + Cuik TB codegen; Lua tests/benchmarks; GNU Make; desktop + WASM; VM/compiler/runtime performance experimentation; FastVM; source: wiki/sources/descriptions/FastVM__minivm.md) | | Binary lifting | machine code → compiler IR | McSema, remill, [[retdec]] (retargetable decompiler; limited maintenance; Cheat → Decompiler), [[neverd]] (NeverSight; Capstone→four-stage IR→LLVM; 1:1 instruction lift; structured C + in-place rewrite; strict mode; `libneverd` C SDK; JSON automation; cheat / Decompiler), [[mergen]] (NaC-L; assembly→LLVM IR lift; symbolic exec + CFG recovery + deobfuscation/devirtualization; C/C++; protected game-binary RE; source: wiki/sources/descriptions/NaC-L__Mergen.md); BN MLIL/HLIL (source: wiki/sources/descriptions/gmh5225__retdec.md) (source: wiki/sources/descriptions/NeverSight__NeverD.md) | ## Anti-analysis & debugging **User-mode anti-debug:** `IsDebuggerPresent`, `NtQueryInformationProcess` (DebugPort/Flags/ObjectHandle), PEB.BeingDebugged/NtGlobalFlag, INT 2D/3 scans, RDTSC/QPC timing, TLS early callbacks, VEH chain inspection, parent-process checks, `ResumeThread` suspend-count anomalies such as [[anti-debug]] (Metick; C++ PoC; debugger attachment leaves elevated suspend count observable via WinAPI return; minimal single-signal study sample) (source: wiki/sources/descriptions/Metick__Anti-Debug.md). Technique catalogs such as [[antidbg-hackovert]] (HackOvert; C/C++ + x86/x64 asm; memory/CPU/timing/exception checks grouped by method; gauntlet sequential test app; RE education + software protection research; Anti Debugging) (source: wiki/sources/descriptions/HackOvert__AntiDBG.md). Integratable Windows library such as [[cpp-anti-debug]] (BaumFX; C++; PEB/API/exception/timing/CPU debug-register checks; granular functions + combined security-check entry for repeated runtime validation; anti-tamper prototyping and debugger-detection study; Anti Debugging) (source: wiki/sources/descriptions/BaumFX__cpp-anti-debug.md). Linux Rust anti-analysis library such as [[debugoff]] (0xor0ne; direct syscalls without libc; syscall-level obfuscation; chained/randomized ptrace checks with tamper termination; binary hardening against RE; Anti Debugging / Linux) (source: wiki/sources/descriptions/0xor0ne__debugoff.md). Hands-on exploration harness such as [[showstopper]] (CheckPointSW; large malware/research anti-debug check collection; exposes function addresses; attach debuggers and compare tools, plugins, and mitigations; anti-anti-debug validation; Anti Debugging) (source: wiki/sources/descriptions/CheckPointSW__showstopper.md). Educational game-facing daemon such as [[sentinel-anti-cheat]] (HEEAAP; C++ usermode AC; suspended launch + pre-resume attach; `NtQueryInformationProcess` / `ReadProcessMemory` / thread-context polling for remote debuggers, HWBP in debug registers, and INT 3 in executable sections; log/suspend/terminate policies; TaskDialog splash; early-process anti-debug reference) (source: wiki/sources/descriptions/HEEAAP__Sentinel-Anti-Cheat.md). Integratable client hardening libraries such as [[avanguard]] (GravitLauncher; Win32 C/C++ anti-intrusion; anti-debug, anti-injection, memory/call-stack analysis, integrity checks, callback filtering, module checks; game-client protection) (source: wiki/sources/descriptions/GravitLauncher__Avanguard.md). Go modular toolkit such as [[godefender]] (EvilBytecode; anti-debug, anti-VM, anti-DLL-injection, hook detection; reusable internal components; low-level WinAPI defensive signals; security-sensitive Go app hardening; Anti Debugging) (source: wiki/sources/descriptions/EvilBytecode__GoDefender.md). .NET managed protection toolkit such as [[anticrack-dotnet]] (AdvDebug; C#; anti-debug, anti-VM, anti-injection, hook detection; PEB/thread flags, sandbox heuristics, syscall probes, integrity hardening; detects anti-anti-debug user-mode hooks and runtime tamper; software hardening and AC component building; Anti Debugging) (source: wiki/sources/descriptions/AdvDebug__AntiCrack-DotNet.md). IDA triage via [[ida-plugin-antidebugseeker]] (LAC-Japan; Python/PyQt5; configurable rule files for Windows API + keyword anti-debug patterns; match highlighting, address annotation, quick navigation, in-IDE rule editor; Extract anti-debugging) (source: wiki/sources/descriptions/LAC-Japan__IDA_Plugin_AntiDebugSeeker.md). **Kernel-mode anti-debug:** `KdDebuggerEnabled`, DR0–DR7 monitoring, `KPROCESS.DebugPort` zeroing, NMI callbacks. **Working-set anti-tamper:** [[query-working-set-example]] (Midi12; C; `QueryWorkingSet` shared-page state in `.text` reveals debugger breakpoints/protection changes; lightweight memory integrity for RE/defenders) (source: wiki/sources/descriptions/Midi12__QueryWorkingSetExample.md). **Bypass/hide tooling:** [[titanhide]] (kernel SSDT tamper), [[hyperhide]] (Air14; hypervisor-based x64dbg/x32dbg anti-anti-debug plugin; kernel driver + Intel VT-x/EPT; sanitizes PEB, thread/process flags, and Nt* queries; 64-bit Windows; README [VT debuger]) (source: wiki/sources/descriptions/Air14__HyperHide.md), ScyllaHide plugins for x64dbg/IDA including [[scyllahide-for-ida9.0rc]] (IDA 9.0 SDK build; hook libs + injector + debugger plugins; masks debugger artifacts; TKazer) (source: wiki/sources/descriptions/TKazer__ScyllaHide-For-IDA9.0RC.md); defensive detection via [[scyllahidedetector2]], [[makin]]. Tutorial kernel anti-anti-debug drivers such as [[anti-anti-debugger-driver]] (AyinSama; C++ WDK driver; hooks native process/thread/handle/system-information syscall paths; disassembly helpers redirect anti-debug probes at kernel level; RE education / protected software analysis; README `[ETW Hook]`) (source: wiki/sources/descriptions/AyinSama__Anti-AntiDebuggerDriver.md). Windows kernel artifact-masking frameworks such as [[hidden]] (JKornev; driver + user-mode rules engine; hides files/directories/registry keys/processes and protects chosen processes from interference; CLI/library + WDK build; controlled RE-lab environment masking) (source: wiki/sources/descriptions/JKornev__hidden.md) extend that lane beyond debugger-focused hides. ARK-style kernel hook/injection demo collections such as [[ark-tools]] (ChengChengCC; C/C++ Visual Studio projects; debug-register hooks, IDT/GDT hooks, kernel APC injection, shadow SSDT inline hooking, registry driver ops, WOW64 cross-arch injection; rootkit technique / defensive detection study; Some kernel research) (source: wiki/sources/descriptions/ChengChengCC__Ark-tools.md) complement that offensive kernel RE lane. VEH-based stealth attach via [[ghostdebug]] (VollRagm; injected DLL + C# CLI over named pipe; INT3/single-step without Win32 Debug API; Iced disasm + JSON control; TestTarget anti-debug validation; cheat / debugging) (source: wiki/sources/descriptions/VollRagm__ghostdebug.md). Userland race-window anti-anti-debug PoC such as [[racecondition]] (Ahora57; C++ Visual Studio; native NT API probes of debug ports, hidden-thread behavior, and debugger artifacts; timing/state races against common userland hide mechanisms; anti-anti-debug technique research) (source: wiki/sources/descriptions/Ahora57__RaceCondition.md). Ghost opcodes (`0F 1A`/`0F 1B`) blind some disassemblers — [[hint-break]]. ## AI-assisted RE (MCP & summarization) Model Context Protocol servers expose RE tools to LLM agents: [[ida-pro-mcp]] / [[iida-mcp]] / [[ida-multi-mcp]] (MeroZemory; Python; IDA 8.5+; one MCP endpoint routes parallel requests to many GUI/idalib sessions; auto-discovery; decompile/memory/patch/survey tools; BCSD cross-binary function similarity via MinHash, import/string anchors, CFG, optional jTrans embeddings; Claude Code/Cursor; malware/AC variant comparison) (source: wiki/sources/descriptions/MeroZemory__ida-multi-mcp.md) / [[ida-mcp-server-plugin]] / [[ida-mcp-server]] (MxIris-Reverse-Engineering; Python standalone MCP server + IDA plugin; bidirectional disassembly-context queries and analysis workflows; MCP for IDA pro) (source: wiki/sources/descriptions/MxIris-Reverse-Engineering__ida-mcp-server.md) / [[ida-cli]] (cpkt9762; headless idalib MCP; AI-assisted binary analysis; Rust/C++) (source: wiki/sources/descriptions/cpkt9762__ida-cli.md) / [[ida-codex-mcp]] (Iamgublin; Python IDA plugin TCP JSON bridge + MCP stdio server; function listing, call graphs, pseudocode/disassembly, xrefs, strings, memory reads, rename/type helpers; AI-assisted RE automation) (source: wiki/sources/descriptions/Iamgublin__ida-codex-mcp.md) / [[ida-claude-code-plugins]] (HexRaysSA; official Python tooling + Markdown plugin/skill docs for Claude Code; plugin development guidance, automated scripting, optional sandboxed code-evaluation; repeatable automation-heavy binary analysis pipelines) (source: wiki/sources/descriptions/HexRaysSA__ida-claude-code-plugins.md) / [[ida-buddy]] (JustasMasiulis; Python WinDbg-style idalib CLI `idb`; persistent headless worker per database; compact stdout; disasm/decompile/xrefs/types + DB mutations with undo; agent-RE lane) (source: wiki/sources/descriptions/JustasMasiulis__ida_buddy.md) / [[headless-ida]] (DennyDai; Python headless IDAPython toolkit; scripts/one-liners/interactive sessions; RPyC remote server; idat64/idalib backends; scalable malware/binary/game-security RE automation) (source: wiki/sources/descriptions/DennyDai__headless-ida.md) / [[headless-ida-mcp-server]] (cnitlrt; headless IDA Pro MCP; function/variable management tools for LLM agents; Game Develop / MCP for IDA pro(headless)) (source: wiki/sources/descriptions/cnitlrt__headless-ida-mcp-server.md) / [[ida-mcp-rs]] (blacktop; Rust headless IDA Pro MCP; RE/modding/memory analysis; Game Develop / MCP server) (source: wiki/sources/descriptions/blacktop__ida-mcp-rs.md) / [[tenrec]] (axelmierczuk; headless extendable multi-session IDA Pro MCP; ida-domain + FastMCP; simultaneous multi-binary analysis; built-in plugins for functions/xrefs/naming/comments/strings/segments/patching/types/entry points; custom plugin entry points; Game Develop / MCP server) (source: wiki/sources/descriptions/axelmierczuk__tenrec.md) / [[ida-rpc]] (bkerler; IDA Pro JSON-RPC daemon; decompile, xrefs, types, patches; headless & GUI; ghidra-rpc-compatible CLI for LLM/agent RE) (source: wiki/sources/descriptions/bkerler__ida_rpc.md) / [[mcp-server-idapro]] (fdrechsler; AI-assistant bridge to IDA Pro; Game Develop / MCP for IDA pro) (source: wiki/sources/descriptions/fdrechsler__mcp-server-idapro.md) / [[binary-analysis-mcps]] (cycraft-corp; Python MCP collection; IDA Pro function analysis, xrefs, variable inspection, utility tools; LLM-driven RE; Binary analysis MCPs collections) (source: wiki/sources/descriptions/cycraft-corp__BinaryAnalysisMCPs.md) (IDA), [[ida-bridge]] (Cellebrite Labs CLI bridge — IDAPython/SQL on live UI or headless idalib; not MCP but same agent-RE lane; macOS IDA 9+) (source: wiki/sources/descriptions/cellebrite-labs__ida-bridge.md), [[idasql]] (allthingsida; virtual SQL tables over IDA DB + AI natural-language RE queries; CLI on `.i64` or in-IDA plugin; remote query for external agents; query-driven binary analysis without IDAPython) (source: wiki/sources/descriptions/allthingsida__idasql.md), [[re-harness]] (OpenCode plugin; read-only IDA 9.3 + IDASQL for Qwen 27B/35B; Windows PE static analysis without executing samples; NeverD/LLVM lift→O3→redecompile when Hex-Rays fails; FLIRT + Windows API semantics; OpenRouter/llama.cpp; macOS/Linux host) (source: wiki/sources/descriptions/thatskriptkid__re-harness.md), [[ida-nexus-docker]] (mrexodia; disposable Docker harness; IDA Pro 9.4+ with Pi agent + Hex-Rays IDA Nexus; ordered LLM prompt sessions in isolation; ZIP audit archive of Nexus traces, Pi transcripts, worker logs; runtime model credentials; hostile-sample safe; unpacking/API/string/config extraction/IDB markup; malware/game-security RE) (source: wiki/sources/descriptions/mrexodia__ida-nexus-docker.md), [[ida-nexus-events]] (mrexodia; Python 3.11+ Textual TUI; discovers locally published IDA Nexus databases; streams live `/idb_events` with timestamps, revisions, execution provenance, and color-coded renames/functions/segments/types/patches/comments/Python script ops; real-time Nexus Code Mode observability for game-security RE) (source: wiki/sources/descriptions/mrexodia__ida-nexus-events.md), [[ghidra-mcp]] (bethington; Java Ghidra extension + Python MCP bridge; 200+ tools; decompile/types/xrefs/BSim; GUI + headless HTTP; streamable HTTP/stdio; Windows live debug; Docker) (source: wiki/sources/descriptions/bethington__ghidra-mcp.md) / [[ghidramcp]] (LaurieWired; Java Ghidra plugin + Python MCP server; decompile, symbol/method enumeration, automated renaming; desktop AI client integration; MCP for Ghidra) (source: wiki/sources/descriptions/LaurieWired__GhidraMCP.md) / [[ghidra-headless-mcp]] / [[ghidrassist-mcp]] (Ghidra MCP; external agents → analysis APIs) (source: wiki/sources/descriptions/jtang613__GhidrAssistMCP.md), in-Ghidra LLM panel via [[ghidrassist]] (OpenAI v1-compatible local/cloud; Ollama/LM-Studio/OpenAI/Anthropic/Azure; cheat / Ghidra Plugins) (source: wiki/sources/descriptions/jtang613__GhidrAssist.md), OpenAI GPT decompiler assistant via [[ghidra-openai]] (Python/Java; decompiled-function purpose, rename suggestions, vuln hints in Ghidra UI; cheat / Ghidra Plugins / `[ChatGPT]`) (source: wiki/sources/descriptions/fmagin__ghidra-openai.md), ChatGPT selected-function explainer via [[gpthidra]] (Ghidra plugin; prints explanation of the selected function to the Ghidra console; cheat / Ghidra Plugins / `[ChatGPT]`) (source: wiki/sources/descriptions/evyatar9__GptHidra.md), [[binary-ninja-mcp]] (Python; disasm/decompile/xrefs/functions/types from BN databases; MCP for Binary_Ninja) (source: wiki/sources/descriptions/fosdickio__binary_ninja_mcp.md) / [[binja-lattice-mcp]] (Invoke-RE; Python BN plugin; authenticated HTTP bridge to external MCP servers; token auth + optional TLS; REST API; export disasm/pseudocode + controlled rename/comment edits; live BN database agent workflows; MCP for Binary_Ninja) (source: wiki/sources/descriptions/Invoke-RE__binja-lattice-mcp.md), [[bn]] (banteg; Python CLI for Binary Ninja agents; plugin development; Cheat Binary Ninja Plugins) (source: wiki/sources/descriptions/banteg__bn.md), [[radare2-mcp]] (C; r2pipe disasm/decompile/xrefs/binary analysis; CLI + plugin modes; sandbox/readonly/tool restrictions; MCP for radare2) (source: wiki/sources/descriptions/dnakov__radare2-mcp.md), in-debugger LLM assistant via [[x64dbg-rippy]] (WebView2 chat panel; LLM tool-use for memory read/disasm/breakpoints/single-step; Anthropic/OpenAI-compatible APIs; Cheat x64dbg Plugins / AI reverse engineering assistant) (source: wiki/sources/descriptions/dariushoule__x64dbg-rippy.md), external Python Automate client via [[x64dbg-automate-pyclient]] (x64dbg Automate RPC; ZeroMQ/msgpack; breakpoints/memory/registers/disasm/session/GUI; optional MCP server for LLM agents; scripted malware/RE/vuln-hunting workflows) (source: wiki/sources/descriptions/dariushoule__x64dbg-automate-pyclient.md), dedicated x64dbg MCP server via [[x64dbg-mcp]] (TypeScript; 23 mega-tools mapping 151 REST endpoints; native `.dp64`/`.dp32` plugin REST bridge; stepping/breakpoints/memory/disasm/tracing/anti-debug bypass/control-flow analysis/PE dump; Claude/Cursor/Windsurf; AI-augmented Windows user-mode debugging) (source: wiki/sources/descriptions/bromoket__x64dbg_mcp.md), C#/.NET Framework x64dbg MCP plugin via [[x64dbgmcpserver]] (AgentSmithers; MCP-compatible HTTP interface; self-hosted listener; modular command routing; memory reads, disassembly, register queries, labeling, automation; AI-assisted RE and scripted game security analysis) (source: wiki/sources/descriptions/AgentSmithers__x64DbgMCPServer.md), agent-native integrated RE lab via [[open-reverselab]] (LING71671; Python; 180+ technique articles + 100+ MCP tools; knowledge router maps signals to attack chains; Ghidra/Frida/x64dbg/jadx; web CTF, Android APK/DEX, Windows PE, crypto, game cheating/AC boards; authorized binary/malware/game-protection investigation) (source: wiki/sources/descriptions/LING71671__open-reverselab.md), LLDB MCP integration via [[lisa-py]] (ant4g0nist; Python LLDB plugin + MCP bridge; target creation, breakpoints, backtraces, disasm, memory reads, expression eval; Game Develop / MCP for LLDB) (source: wiki/sources/descriptions/ant4g0nist__lisa.py.md); integrated Bethesda Creation Engine toolchain [[bethesda-modding-starter]] (Ghidra + x64dbg MCP bridges; PowerShell bootstrap; address-library import; AI-assisted decompilation and live debugging for Fallout 4 / Skyrim / Starfield binaries) (source: wiki/sources/descriptions/rollingrock__bethesda-modding-starter.md); live process memory via [[cheatengine-mcp-bridge]] (CE Lua worker + Python FastMCP over named pipes; scan/read/pointers/RTTI/HWBP/DBVM; sub-2ms; miscusi-peek / beamstar forks) (source: wiki/sources/descriptions/miscusi-peek__cheatengine-mcp-bridge.md) (source: wiki/sources/descriptions/beamstar__cheatengine-mcp-bridge.md), DeepSeek Harness CE control via [[dsh-cheatengine]] (TindalosKorone; TypeScript TCP bridge; on-demand `ce_*` scan/debug/script tools with session audit/snapshot and gated writes; game-security RE / dynamic memory analysis) (source: wiki/sources/descriptions/TindalosKorone__dsh-cheatengine.md), DSH Ghidra/forensics/agent plugin bundle via [[dsh-plugins]] (GalaxyBatMan111; JavaScript + Python PyGhidra server; binary import/decompile/strings/xrefs; radare2/RetDec/tshark/mitmproxy forensics; Claude Code/OpenAI Codex/Tencent Marvis agent delegation with streaming jobs; Windows DSH bundle profiles; malware/game-binary/network-forensics RE) (source: wiki/sources/descriptions/GalaxyBatMan111__dsh-plugins.md), in-process CE MCP plugin [[ce-mcp-plugin]] (Eruditi; C + Lua; async TCP command channel; memory R/W/freeze, disasm/asm, process control, DLL injection; AI-assisted CE automation; MCP for Cheat Engine) (source: wiki/sources/descriptions/Eruditi__CE-MCP-Plugin.md), and standalone [[memmcp]] (Python CE-like MCP) / [[pcileech-memprocfs-mcp]] (Neverdecel; Linux-native MCP over PCILeech/MemProcFS via memprocfs/leechcorepyc; live DMA R/W, pattern/pointer-chain/xref scans, UE/Unity SDK dump helpers, FPGA TLP control; DMA-assisted agent RE) (source: wiki/sources/descriptions/Neverdecel__pcileech-memprocfs-mcp.md); in-game live-state MCP bridges such as [[sts2-kitlib]] (WRXinYue; STS2 mod toolkit; browser dev console + MCP bridge for automated game-state queries and scripted actions; Harmony IL patch analysis; mod dev / RE / stress-test automation) (source: wiki/sources/descriptions/WRXinYue__STS2-KitLib.md); utility hex↔decimal conversion via [[hex2dec-mcp]] (JavaScript/TypeScript; Game Develop / MCP) (source: wiki/sources/descriptions/gmh5225__hex2dec-mcp.md); Process Hacker–oriented runtime analysis via [[processhacker-mcp]] (C/C++; DLL plugins; Game Develop / MCP) (source: wiki/sources/descriptions/illegal-instruction-co__processhacker-mcp.md). Mobile Android RE agent skill set [[mobile-re-skill]] (decision-tree docs + composable Frida JS + ARM64 Python analysis; six-phase anti-detection pipeline; JADX/Ghidra integration) complements MCP decompile servers such as [[delamain]] and [[apktool-mcp-server]] and multi-format static-analysis MCP via [[glass]] (Rust; ARM64/x86-64; ELF/Mach-O/DEX/PE; disasm/CFG/xrefs/pattern match/patch; CLI+MCP on APK/IPA/AArch64; `glass mcp`) (source: wiki/sources/descriptions/azw413__Glass.md) and offline mobile IDE [[sako-restudio]] (Capstone disasm + IR decompiler + ptrace debugger + SakoScript plugins; APK/ELF/PE/DEX; Jetpack Compose; SQLite projects) (source: wiki/sources/descriptions/Maxamedxasa__SakoREStudio.md) for dynamic instrumentation workflows. (source: wiki/sources/descriptions/index-login__MobileRE-Skill.md) All-in-one Android control platform [[lamda]] (FIRERPA; Python client API; UI automation, MITM capture, built-in [[frida]], MCP agent support; root/non-root; multi-device fleet automation) sits in the same mobile agent-RE lane beside static MCP servers. (source: wiki/sources/descriptions/firerpa__lamda.md) LLM-native device automation via [[droidrun]] (Python; natural-language Android/iOS control via ADB + accessibility APIs; OpenAI/Anthropic/Gemini/Ollama/DeepSeek; scripter agents + custom tools; `[MCP for Android]`) extends that lane toward agent-driven mobile testing. (source: wiki/sources/descriptions/droidrun__droidrun.md) Upstream [[scrcpy]] (Genymobile; C/Java; USB/TCP Android mirror/control; audio, recording, virtual display, HID input; low latency; no root; app/game debugging) is the canonical scrcpy stack. (source: wiki/sources/descriptions/Genymobile__scrcpy.md) Low-latency Android screen mirroring via [[qtscrcpy]] (Qt GUI over scrcpy server; USB/TCP; keyboard/mouse input, recording, multi-device; no root) supports visual mobile RE sessions beside agent automation stacks. (source: wiki/sources/descriptions/barry-ran__QtScrcpy.md) Workflow: natural-language queries → rename, annotate, navigate, decompile. Whole-program summarization pipelines such as [[gpt-wpre]] (Python; `ghidra_bridge` decomp + call graphs → bottom-up GPT function summaries with callee-context compression) work around context-window limits for readable program analysis — pair with [[research-rigor]] when acting on agent or model output. (source: wiki/sources/descriptions/moyix__gpt-wpre.md) File-export workflows without MCP: [[ida-no-mcp]] (P4nda0s; Python IDA plugin + Rust idalib CLI `inp`; Hex-Rays decompilation/disasm fallback, caller/callee metadata, strings, imports/exports, optional memory hexdumps, call graphs, AGENTS.md for AI IDEs; per-function or consolidated layouts for large IDBs; Cursor/Claude Code) (source: wiki/sources/descriptions/P4nda0s__IDA-NO-MCP.md). Binary-to-source project export via [[tocode]] (buzzer-re; IDA Pro or radare2 backends; decompile functions, cluster by similarity, generate names, structured export + Semgrep integration; traversable source-like tree for coding agents on large binaries) offers another offline oracle corpus alongside live MCP servers. (source: wiki/sources/descriptions/buzzer-re__ToCode.md) Decompiler ChatGPT assistant via [[daila]] (cheat / IDA Plugins / `[ChatGPT]` lane) offers another LLM-in-decompiler path for game-security RE. (source: wiki/sources/descriptions/mahaloz__DAILA.md) WinDbg x64 LLM decompiler extension via [[windbg-decompile-ext]] (live function disasm → verified pseudocode; Cheat → WinDbg Plugins) extends that lane to live kernel/user attach. (source: wiki/sources/descriptions/kernullist__windbg-decompile-ext.md) ChatGPT PCode assistant via [[ida-plugin-pcodegpt]] (Chinese UI only; cheat / IDA Plugins / `[ChatGPT]` lane) adds LLM-assisted Hex-Rays microcode (p-code) workflows. (source: wiki/sources/descriptions/lzyddf__IDA_Plugin_PCodeGPT.md) Multi-provider IDA vulnerability analysis via [[vulchatgpt]] (**BinAIVulHunter**; OpenAI GPT / Google Gemini / Ollama; decompiled-function vuln analysis, code explanation, security assessment; cheat / IDA Plugins / `[ChatGPT]` lane). (source: wiki/sources/descriptions/ke0z__VulChatGPT.md) OpenAI-compatible IDA analysis assistant via [[wpechatgpt]] (Python IDAPython; explain function behavior, rename variables, Python routine reconstruction, vulnerability checks from decompiled views; automated function-tree traversal + summarization; cheat / IDA Plugins / `[ChatGPT]` lane). (source: wiki/sources/descriptions/WPeace-HcH__WPeChatGPT.md) ChatGPT-compatible IDAPython helper via [[ida-gpt]] (MayerDaniel; Python; plain-language function descriptions + automated rename suggestions for variables, locations, and symbols; writes comments and renamed identifiers into the IDA database; interactive unfamiliar-binary triage; cheat / IDA Plugins / `[ChatGPT]` lane). (source: wiki/sources/descriptions/MayerDaniel__ida_gpt.md) GPT-assisted IDA copilot via [[ida-copilot]] (Antelcat; Python IDAPython + Hex-Rays + LangChain; analyze pseudocode, inspect symbols, apply comments/renaming suggestions; menu actions + shortcut-driven semi-automated function-level investigation; cheat / IDA Plugins / `[ChatGPT]` lane). (source: wiki/sources/descriptions/Antelcat__ida_copilot.md) Gemini-powered semantic analysis via [[ida-semray]] (19h; Python IDA Pro plugin; AI-assisted semantic binary analysis; suggests function/variable names and detailed comments from decompiled code or assembly context; interactive context-aware analysis across callers, callees, and references; security analyst triage; cheat / IDA Plugins) (source: wiki/sources/descriptions/19h__ida-semray.md) C++ LLM rename/explain assistant via [[binarylens]] (Berk000x; bulk function rename, decompiler-context logic explain, local variable rename; IDA SDK + OpenSSL; multi-model backends; large game client / anti-cheat binary RE; cheat / IDA Plugins) (source: wiki/sources/descriptions/Berk000x__BinaryLens.md) RevEng.AI platform integration via [[reai-ida]] (RevEngAI; Python IDAPython + Qt; binary upload, similarity-based function matching, automated renaming, auto-unstrip, AI decompilation views; ML-assisted stripped-binary analysis; cheat / IDA Plugins / `[RevEng.AI]`) (source: wiki/sources/descriptions/RevEngAI__reai-ida.md). Ghidra-native RevEng.AI integration via [[plugin-ghidra]] (RevEngAI; Java Gradle Ghidra 11.4+/Java 21 extension; binary upload, code similarity, batch function matching/renaming, AI decompilation views; ML-assisted stripped-binary RE; cheat / Ghidra Plugins / `[RevEng.AI]`) (source: wiki/sources/descriptions/RevEngAI__plugin-ghidra.md). Integrated AI assistant via [[binoculars]] (Python; configurable model backends, command prompts, UI actions; function explain/rename + Go pclntab reconstruction helpers; cheat / IDA Plugins) sits in the same LLM-assistant lane. (source: wiki/sources/descriptions/Vis-Wing__Binoculars.md) Official VirusTotal IDA integration via [[vt-ida-plugin]] (Python; cloud malware intelligence + byte/string/function code-similarity search from disassembly; notebook panel with AI function summaries, editable notes, exportable collaboration artifacts; cheat / IDA Plugins / VirusTotal plugin lane) accelerates malware and unknown-binary RE triage. (source: wiki/sources/descriptions/VirusTotal__vt-ida-plugin.md) AI-powered IDA 9.0+ dockable panel via [[idassist]] (Python/PySide6; multi-provider LLM function explain/rename, semantic knowledge graph, RAG, MCP; cheat / IDA Plugins) extends in-IDA LLM RE for game-security workflows. (source: wiki/sources/descriptions/jtang613__IDAssist.md) IDA Pro 9.4 Windows AI console + MCP gateway via [[ida-pro-agent]] (built-in AI Console + external MCP clients; Hex-Rays pseudocode, bounded caller tracing, guard-evidence extraction, preview/apply/rollback IDB ChangeSets; malware/AC RE; cheat / IDA Plugins) extends that in-IDA + MCP lane. (source: wiki/sources/descriptions/ackwrap__ida-pro-agent.md) Embedded RE agent via [[rikugan]] (buzzer-re; Python plugin for IDA Pro and Binary Ninja; multi-provider LLM chat UI Ctrl+Shift+I; generator-based agentic loop with streaming, in-process tool orchestration, plan mode, and error recovery; cloud APIs + local Ollama) sits in the same in-disassembler LLM-assistant lane beside MCP bridges. (source: wiki/sources/descriptions/buzzer-re__Rikugan.md) Local Ollama-assisted HLIL renaming via [[binaryninja-ollama]] (ahaggard2013; Python BN plugin; bulk/targeted function and variable rename; configurable local server/port/model; offline semantic labeling without cloud APIs; Cheat Binary Ninja Plugins) sits in the same in-disassembler LLM-assistant lane beside [[rikugan]]. (source: wiki/sources/descriptions/ahaggard2013__binaryninja-ollama.md) OpenAI cloud-assisted HLIL analysis via [[binaryninja-openai]] (WhatTheFuzz; Python BN plugin; selected-function summarize from HLIL/pseudo-C + variable rename proposals; BN plugin settings/API key management; Cheat Binary Ninja Plugins / Integrates OpenAI) sits beside [[binaryninja-ollama]] for cloud vs local LLM triage. (source: wiki/sources/descriptions/WhatTheFuzz__binaryninja-openai.md) Program slicing for faster comprehension via [[tanto]] (Vector35; Python Binary Ninja plugin; variable/block relationship slices over HLIL instead of full-function views; analysts and vuln researchers; Cheat / [Slices Functions]) (source: wiki/sources/descriptions/Vector35__tanto.md) Agentic binary RE via [[kong]] (amruth-sn; LLM-orchestrated in-process [[ghidra]]; call-graph analysis; agentic deobfuscation including MBA-style expression recovery via algebraic simplification, pattern matching, or symbolic execution) extends the Ghidra-native agent lane beside [[ghidrassist]] and MCP bridges. (source: wiki/sources/descriptions/amruth-sn__kong.md) (source: wiki/sources/descriptions/miscusi-peek__cheatengine-mcp-bridge.md) Cross-domain MCP server discovery indexes such as [[awesome-mcp-servers]] (TensorBlock; category-organized catalog spanning security, gaming, and RE tooling; Markdown navigation; Awesome MCP) complement individual RE MCP bridges. (source: wiki/sources/descriptions/TensorBlock__awesome-mcp-servers.md); application-security MCP via [[mcp-server]] (PortSwigger; Burp Suite extension; MCP endpoint + stdio proxy; Kotlin/Java; AI-assisted Burp workflows; MCP for Burp Suite) (source: wiki/sources/descriptions/PortSwigger__mcp-server.md) Harbor-based agent benchmarks such as [[binaryaudit]] (QuesmaOrg; stripped C/Go/Rust binaries with injected backdoors, clean negatives, and timebomb tasks; Docker-isolated agents with Ghidra/Radare2; lighttpd/dnsmasq/Dropbear/Sozu/Caddy; YAML multi-model experiments; AI agent backdoor/malware RE evaluation) standardize scored evaluation of LLM reverse-engineering workflows. (source: wiki/sources/descriptions/QuesmaOrg__BinaryAudit.md) Decompiler recovery benchmarking via [[decbench]] (Noelo-Lab; Python compile→decompile→score pipeline; CFG GED, DWARF type match, recompilation bytematch; angr/Ghidra/IDA/Binja/r2dec/dewolf + LLM/agent backends; Debian/embedded/firmware/malware corpora; cheat / Decompiler) complements that lane with quantitative decompiler quality metrics. (source: wiki/sources/descriptions/Noelo-Lab__decbench.md) Agent-native unified static+dynamic RE via [[n0xis]] (LargoScript; Rust; x64 Windows game binaries; CFG/SSA decompilation + live memory scan, pointer paths, hooks, cheat tables; CLI + MCP with versioned JSON artifacts; Unity IL2CPP, Lua/LuaJIT; N0xHUD companion) bridges disassembler workflows and CE-style runtime manipulation for explainable agent RE. (source: wiki/sources/descriptions/LargoScript__n0xis.md); bundled read-only live-process MCP via [[apprentice]] (digital-dev; Electron/React trainer + C++ N-API; memory scan, pointer chains, Mono JIT introspection, Zydis disasm, HWBP write watching exposed to AI agents; offline cheat development; cheat / memory editor) (source: wiki/sources/descriptions/digital-dev__Apprentice.md); byte-level claim verification via [[reverify]] (2akouwu; Python; PE/ELF/Mach-O parse/disasm/emulate; Capstone/Unicorn/LIEF; deterministic VERIFIED/REFUTED/INCONCLUSIVE verifier + reconstruction-agent loop with established-facts ledger; Frida hook gen; MCP + CLI for coding agents; malware/CTF/interop RE) (source: wiki/sources/descriptions/2akouwu__reverify.md); headless .NET assembly MCP via [[dnspymcp]] (rabbanyhmm; C# .NET 8; dnlib + ICSharpCode.Decompiler; 31 tools—type listing, C# decompile, IL analysis, binary patch; Unity/IL2CPP offset+RVA lookup, struct export, dump.cs bridge, cross-refs, multi-DLL search; packet-handler/crypto/secret scans; stdio JSON-RPC for Cursor/Claude Code/Codex; no dnSpy GUI) (source: wiki/sources/descriptions/rabbanyhmm__DnSpyMCP.md) ## Binary diffing Graph- and structure-based differencing (BinDiff, [[diaphora]], [[ghidriff]], DarunGrim, [[turbodiff]]) supports patch analysis: track anti-cheat driver updates, isolate logic changes in obfuscated clients, and compare vulnerability fixes. Similarity scores and decompiled diffs are candidate evidence—corroborate semantic impact with [[binary-evidence]] reachability/observation checks and preserve both input hashes, tool versions, and unmatched functions. See [[binary-diffing]] for evidence limits. (source: wiki/sources/skills/reverse-engineering.md) MinHash-based cross-sample function similarity via [[mcrit-plugin]] (MCRIT server integration in IDA; upload samples, query matches, browse similarity scores) complements graph diffing for large-scale code recognition and malware/function identification. (source: wiki/sources/descriptions/danielplohmann__mcrit-plugin.md) Ghidra BSim corpus platform [[bsimvis]] (MISP; Python + JS; Kvrocks/Redis queues + optional Milvus vector search; REST API + web UI; score-filtered similarity search, function diffing, HDBSCAN family clustering, call-graph navigation, analyst notes, optional local LLM summaries; scalable cross-binary analysis beyond Ghidra built-in BSim DB) targets the same variant-tracking lane for malware and AC build comparison. (source: wiki/sources/descriptions/MISP__bsimvis.md) Cross-binary BCSD similarity via [[ida-multi-mcp]] (instruction MinHash + import/string anchors + control-flow structure + optional jTrans embeddings; multi-IDA parallel routing for comparing droppers, payloads, patches, and stripped/recompiled variants) targets the same variant-tracking lane for game-security and anti-cheat workflows. (source: wiki/sources/descriptions/MeroZemory__ida-multi-mcp.md) Function-level byte-pattern and instruction-trait extraction via [[binlex]] (C++/Rust; PE/ELF/raw; multi-arch disassembly; JSON for YARA rules and malware similarity) complements MinHash similarity and graph diffing for signature authoring and threat-intel pipelines. (source: wiki/sources/descriptions/c3rb3ru5d3d53c__binlex.md) Graph-embedding function similarity via [[gemini-genius]] (Jackiemin233; Python toolkit + IDA Python 3 plugin; CFG/ACFG extraction, dataset preprocessing, model training, embedding export, similarity search for cross-binary function matching; RE and vulnerability research) complements MinHash and BSim pipelines for stripped/obfuscated build comparison. (source: wiki/sources/descriptions/Jackiemin233__Gemini-Genius.md) Graph- and structure-based differencing (BinDiff, [[binexport]], [[diaphora]], [[turbodiff]], [[ghidriff]], DarunGrim) for patch analysis: track anti-cheat driver updates between builds, isolate logic changes in obfuscated clients, and compare patched vulnerability fixes. Pre-collected versioned driver binaries such as [[win32k-file-collection]] (multi-build **win32k.sys** and related GUI-subsystem binaries for patch diffing and vuln research) and [[win32k-file-collection2]] (Win10/11 **win32k.sys** corpus for offline build-to-build comparison before importing into BinDiff/Diaphora pipelines) reduce corpus-gathering friction for kernel GUI-subsystem patch research; runtime session-space hook resolution samples such as [[win32khooker]] (GetRektBoy724; kernel driver + runtime disassembly for win32k dispatch targets when pointers moved into opaque session-state; complements static corpora) extend that lane. (source: wiki/sources/descriptions/GetRektBoy724__Win32kHooker.md); compact call-path reference lists such as [[driver-communication-list]] (gmh5225; documented user→kernel transitions through win32u/win32k/dxgkrnl for tracing in debuggers/disassemblers) complement those static corpora when starting syscall-path RE; hands-on KM↔UM IPC pattern samples such as [[km-um-communication]] (adspro15; C/C++ driver↔usermode request dispatch, event coordination, cross-boundary data exchange) help when learning kernel-user boundaries. (source: wiki/sources/descriptions/gmh5225__win32k_file_collection.md) (source: wiki/sources/descriptions/gmh5225__win32k_file_collection2.md) (source: wiki/sources/descriptions/gmh5225__Driver-Communication-List.md) (source: wiki/sources/descriptions/adspro15__km-um-communication.md) A parallel **ntoskrnl** build corpus via [[ntoskrnl-file-collection]] supports executive-image version-diff workflows before BinDiff/Diaphora import. (source: wiki/sources/descriptions/gmh5225__ntoskrnl_file_collection.md) [[binexport]] is Google's C++ exporter plugin for IDA Pro, Ghidra, and Binary Ninja—serializes functions, basic blocks, instructions, xrefs, and call graphs to Protocol Buffer for BinDiff and other diff pipelines. (source: wiki/sources/descriptions/google__binexport.md) [[diaphora]] is the leading open-source IDA Pro Python plugin for function-level comparison—CFG matching, basic-block hashes, mnemonics, string refs, call-graph topology—with partial matching, symbol/comment porting between IDB versions, and detailed diff reports for vulnerability and patch analysts. (source: wiki/sources/descriptions/joxeankoret__diaphora.md) [[turbodiff]] (HelpSystems) is another IDA plugin focused on discovering and analyzing function-level differences between two binaries for game-security RE and patch tracking. (source: wiki/sources/descriptions/helpsystems__turbodiff.md) [[ghidriff]] (clearbluejar; Python CLI) automates headless Ghidra diffing—structural graph matching, version tracking, BSim similarity—with Markdown reports for decompiled diffs, call-graph changes, and metadata deltas; PE/Mach-O/ELF; Docker CI; documented **ntoskrnl**, **afd.sys** CVE, and iOS dylib workflows. (source: wiki/sources/descriptions/clearbluejar__ghidriff.md) Web-based cross-build Windows symbol/type/syscall diffing via [[windiff]] (Winbindex + Symbol Server pipeline → static JSON databases; Browse/Diff UI for kernel and usermode changes between OS builds) complements IDA-centric workflows for EDR/anti-cheat patch tracking. (source: wiki/sources/descriptions/ergrelet__windiff.md) ## Cross-platform plugin development Portable PyQt/PySide GUI scaffolding via [[gui-plugin-template]] (Python; harmonized API across IDA Pro, Ghidra, Binary Ninja, and Cutter; single GUI codebase for multi-host plugins) reduces per-disassembler UI duplication when shipping analysis tooling—complementary to Git-backed annotation sync via [[binsync]], live cursor/goto sync across IDA, Binary Ninja, x64dbg, WinDbg, and VS Code via [[retoolsync]] (mrexodia; Tornado WebSocket hub; Ctrl+click hex in terminal jumps all connected tools) (source: wiki/sources/descriptions/mrexodia__REToolSync.md), IDA-only partial IDB sync via [[labsync]] (Cellebrite Labs; YAML export on save; git push/pull with mergetool merge; MD5 input-file identity; lightweight team IDB sync without full database sharing) (source: wiki/sources/descriptions/cellebrite-labs__LabSync.md), and multi-host YARA generation via [[hyara]]. (source: wiki/sources/descriptions/danielplohmann__gui-plugin-template.md) IDA-only YARA signature authoring via [[yarka]] (AzzOnFire; Python; instructions/strings/raw bytes/decompiler output + function-level hunting; built-in editor with syntax highlighting and rule templates; malware/binary signature workflows) complements [[hyara]] and in-IDA scan tooling such as [[yara4ida]] and [[findyara-ida]]. (source: wiki/sources/descriptions/AzzOnFire__yarka.md) Ghidra Command Palette navigation via [[gfred]] (keyboard-driven action search; prebuilt Ghidra 9.2.0 extension in `dist/`; cheat / Ghidra Plugins / `[Command Palette]`) speeds manual and scripted RE workflows inside Ghidra. (source: wiki/sources/descriptions/danbrodsky__GFred.md) Cross-platform Ghidra toolchain management via [[ghidra-manager]] (Python CLI; release-pinned install, SHA-256-verified downloads, curated extension sets incl. [[ghidra-mcp]], project launch, MCP bridge, binary compare, rollback pair; Windows/Linux/macOS; alexbevi) standardizes repeatable Ghidra lab setup. (source: wiki/sources/descriptions/alexbevi__ghidra-manager.md) Archived [[ghidra-gradle-plugin]] (Java/Groovy Gradle plugin; local Ghidra classpath wiring, extension build scripts, IDE setup tasks; astrelsky; `[Gradle]`) streamlines packaging custom Ghidra extensions for plugin authors. (source: wiki/sources/descriptions/astrelsky__GhidraGradlePlugin.md) [[ghidra-cpp-class-analyzer]] (Java Ghidra extension; GCC/Clang/MSVC RTTI, vtables, ctors/dtors, inheritance reconstruction, class hierarchy views; astrelsky; native C++ game/client RE) complements IDA-side C++ RTTI tooling such as [[rtti-parser]], [[pyclassinformer]], and [[ida-medigate]]. (source: wiki/sources/descriptions/astrelsky__Ghidra-Cpp-Class-Analyzer.md) VS Code-based unified RE IDE [[hikarisystem-hexcore]] (AkashaCorporation; TypeScript + C++ Node-API; Capstone/Unicorn/Remill/Rellic lift-decompile pipeline, YARA/IOC/entropy, PE/ELF emulation, HQL anti-analysis queries, headless `.hexcore_job.json` batch automation + agent integration; malware/binary RE desktop environment) (source: wiki/sources/descriptions/AkashaCorporation__HikariSystem-HexCore.md) ## Key sub-areas - **Guides / indexes:** [[re4f]] Obsidian RE curriculum (x86/x64, NASM/MASM, Windows memory/PE, static/dynamic analysis with IDA/Ghidra/x64dbg/WinDbg/BN/DnSpy, anti-analysis packing/anti-debug; Cheat / Guide) (source: wiki/sources/descriptions/Coldzer0__RE4F.md); curated RE resource lists such as [[reverse-engineering]] (reversing + networking + editor tooling; cheat/guide lane) (source: wiki/sources/descriptions/wtsxDev__reverse-engineering.md); comprehensive tool-type-organized game hacking indexes such as [[game-hacking]] (dsasmblr; disassemblers / debuggers / hex editors / memory scanners / .NET decompilers / graphics debuggers / RE tutorials; cheat / guide) (source: wiki/sources/descriptions/dsasmblr__game-hacking.md); C++ external cheat framework scaffolds such as [[osmium]] (cragson; out-of-process cheat development; cheat / guide; offensive technique study—not a best-practices reference) extend that lane. (source: wiki/sources/descriptions/cragson__osmium.md); curated injection technique lists such as [[awesome-injection]] (offensive injection research; Cheat / injection:windows) (source: wiki/sources/descriptions/itaymigdal__awesome-injection.md); curated Android security learning index [[awesome-android-security]] (NetKingJ; theory/tools/write-ups/PoCs/CVE reports; kernel exploitation, app testing, Frida workflows; cheat / Android (Samsung) Security Research References) (source: wiki/sources/descriptions/NetKingJ__awesome-android-security.md); integrated assessment playbook [[android-security-wizard]] (savagedamage; SKILL.md + 20 companions; APK/DEX/native static+dynamic RE, Frida/Objection/Shizuku/Ghidra, DexGuard/Bangcle bypass, ARM64 kernel exploit triage, malware C2 attribution, Android 14–18 deltas; cheat / Guide) (source: wiki/sources/descriptions/savagedamage__android-security-wizard.md); AOSP/custom-ROM platform index [[awesome-android-aosp]] (build systems, kernels, device trees, Treble, SELinux, vendor workflows; cheat / Guide) (source: wiki/sources/descriptions/Akipe__awesome-android-aosp.md); curated obfuscation tooling index such as [[awesome-obfuscations]] (binary-code / compile-time / LLVM-GCC obfuscators; C/C++/Go/Rust/x86 assembly + VM protectors; anti-RE / anti-tamper / native binary protection) (source: wiki/sources/descriptions/killvxk__awesome-obfuscations.md); injectable DLL hot-reload dev tooling such as [[dll-hot-reload]] (ergrelet; develop/debug injected DLL payloads on disk update; cheat / injection:windows) complements those catalogs for iterative RE workflows. (source: wiki/sources/descriptions/ergrelet__dll-hot-reload.md); PE import-table shellcode staging via [[hintinject]] (Hint/Name Table chunks in fabricated import entries; loader IAT resolution rebuild; Hint/Name Table; frkngksl) (source: wiki/sources/descriptions/frkngksl__HintInject.md); PE infection / Cordyceps parasitic shellcode loaders such as [[super-mega]] (carrier shellcode integrated into legitimate EXE/DLL; web UI; anti-emulation; static-analysis evasion; dobin) (source: wiki/sources/descriptions/dobin__SuperMega.md); PE patching/infection framework such as [[peinjector]] (C PE parse/modify; Python/Java control; multiple infection methods; transfer-time patches; web remote config; preserves host behavior; JonDoNym) (source: wiki/sources/descriptions/JonDoNym__peinjector.md); minimal PIC C shellcode micro-framework such as [[tabby]] (cocomelonc; write shellcode in C; PEB/EAT + FNV-1a hashing; indirect NT syscalls; ~500 LOC teaching scaffold; shellcode engine & tricks / offensive training) (source: wiki/sources/descriptions/cocomelonc__tabby.md); modular malware-behavior emulator such as [[peekaboo]] (cocomelonc; reproducible threat artifacts for operator training, purple-team exercises, and defensive rule development; MITRE ATT&CK + Sigma/YARA generation + VT validation; malware/telemetry RE lane) (source: wiki/sources/descriptions/cocomelonc__peekaboo.md); curated executable packing/unpacking resource lists such as [[awesome-executable-packing]] (packers, protectors, unpackers, analysis tools, papers, tutorials; PE/ELF/Mach-O; Executable File Packing) (source: wiki/sources/descriptions/gmh5225__awesome-executable-packing.md); curated disassembler/debugger plugin indexes such as [[awesome-ida-x64-olly-plugin]] (IDA Pro, Ghidra, x64dbg, OllyDbg, GDB plugins/scripts; patching, diffing, deobfuscation, emulation, YARA, anti-anti-debug; fr0gger) (source: wiki/sources/descriptions/fr0gger__awesome-ida-x64-olly-plugin.md); Ghidra-focused ecosystem index [[awesome-ghidra]] (AllsafeCyberSecurity; scripts, plugins, extensions, automation, malware analysis, diffing, workflow enhancements; Java and Python; headless and interactive; cheat / List) (source: wiki/sources/descriptions/AllsafeCyberSecurity__awesome-ghidra.md); Vector35 curated official Binary Ninja plugin catalog via [[official-plugins]] (Python indexing scripts; structured metadata for descriptions, plugin types, API targets, licenses; plugin-management workflows; cheat / Binary Ninja plugin index) (source: wiki/sources/descriptions/Vector35__official-plugins.md); Vector35 community Binary Ninja plugin index via [[community-plugins]] (Python manifest validation + catalog generation; third-party licensing, compatibility, and update metadata; discover/install community extensions; cheat / Binary Ninja plugin index) (source: wiki/sources/descriptions/Vector35__community-plugins.md); curated WinDbg extension index such as [[awesome-windbg-extensions]] (kernel analysis, IR, rootkit hunting, memory inspection, debugger workflow automation; Markdown reference index; anhkgg) (source: wiki/sources/descriptions/anhkgg__awesome-windbg-extensions.md); game-specific RE learning material indexes such as [[game-reversing]] (personally curated resources; Windows PC games; x86-assembly-first over x64 for beginners; cheat/guide lane) (source: wiki/sources/descriptions/kovidomi__game-reversing.md); curated game-hacking/cracking learning link lists such as [[thezong-game-hacking]] (TheZong; tutorials/forums/RE refs/dumpers/mappers; title-specific starter bases; cheat/guide lane) (source: wiki/sources/descriptions/TheZong__Game-Hacking.md); Chinese-language Cheat Engine guide documentation such as [[game-reversed-study]] (documentation/reference; cheat / guide) (source: wiki/sources/descriptions/januwA__game-reversed-study.md); long-form RE writeup archives such as [[batteryshark-github-io]] (Jekyll GitHub Pages; game hacking / classic PC compatibility patching / Windows internals / arcade hardware teardowns; IDA disassembly + Python snippets; Masterpiece consolizing series; QEMU-GDB kernel debugging; cheat / guide) (source: wiki/sources/descriptions/batteryshark__batteryshark.github.io.md); Dark Souls III Cheat Engine guide documentation such as [[dark-souls-iii-cheat-engine-guide]] (The Grand Archives table; cheat / game:dark souls [Cheat Engine]; online invalid-data EULA note) (source: wiki/sources/descriptions/igromanru__Dark-Souls-III-Cheat-Engine-Guide.md); historical Windows NT5 source reference via [[winnt5-src-20201004]] (Windows 2000/XP/Server 2003 era; large `NT/` tree for kernel, Win32, and subsystem RE) (source: wiki/sources/descriptions/jiubanlo__WinNT5_src_20201004.md); remote Windows kernel debugging guides such as [[windows-kernel-debugging-guide]] (documentation/reference; cheat / guide lane) (source: wiki/sources/descriptions/konstantin89__windows-kernel-debugging-guide.md); VT-x hypervisor debugger research such as [[erisdbg]] (C/C++; kernel drivers / modding; cheat / debugging lane) (source: wiki/sources/descriptions/kkpwn__ErisDbg.md); Intel VT-x thin-hypervisor stealth debugger [[vt-debuger]] (VM-exit breakpoints/single-step/memory watch; evades standard anti-debug checks; protected-software RE) (source: wiki/sources/descriptions/gmh5225__vt-debuger.md); Unreal Engine–targeted VT-x/EPT kernel debugging via [[unreal-vtdbg]] (Delphi UI + DbgkSys/VMX driver, EPT hooks, stealth breakpoints; authorized AC/RE) (source: wiki/sources/descriptions/xhscfq__UnrealVTDbg.md); category-organized RE/security tool catalogs such as [[retools]] (disassemblers / debuggers / decompilers / hex editors / network / binary analysis / sandbox / malware analysis) for building a toolkit (source: wiki/sources/descriptions/stevemk14ebr__RETools.md); Windows all-in-one RE installer bundles such as [[retoolkit]] (Inno Setup; 80+ tools: x64dbg/HyperDbg, Ghidra/Cutter, dnSpyEx/ILSpy/de4dot, [[pe-bear]]/pestudio/DIE, ImHex/HxD, FakeNet/nmap, YARA/YARA-X) for one-shot lab setup (source: wiki/sources/descriptions/mentebinaria__retoolkit.md); Scoop-based AI-agent RE lab installer [[rev-tools-setup]] (PowerShell; CE/Ghidra/x64dbg/DynamoRIO/Wireshark/YARA/ReClass.NET + Frida/Scapy/PyTorch/OpenCV; read-only CE MCP server + OpenCode/Claude Desktop client config; Win10/11) (source: wiki/sources/descriptions/lilyco-42__rev-tools-setup.md); Mandiant Chocolatey/Boxstarter Windows analysis VMs such as [[flare-vm]] (customizable malware/IR/RE distribution; IDA/Ghidra/x64dbg, network/forensic utils, Python/Ruby) for reproducible lab provisioning (source: wiki/sources/descriptions/mandiant__flare-vm.md); CAPE/Cuckoo sandbox host setup and malware-analysis utilities via [[tools]] (doomedraven; KVM/QEMU provisioning, IDA string deobfuscation, Volatility3 plugins, flare-emu deobfuscation, libguestfs Docker; `[QEMU Script]`) complement those lab bundles for automated dynamic-analysis infrastructure (source: wiki/sources/descriptions/doomedraven__Tools.md); historical local-privilege-escalation PoC archive [[localroot-all-cve]] (Snoopy-Sec; CVE/year-organized C/shell/Python exploit samples with notes; exploit-development study and vulnerability timeline reference; README [Root CVE]) (source: wiki/sources/descriptions/Snoopy-Sec__Localroot-ALL-CVE.md); multi-database CVE/exploit search CLI such as [[cve-maker]] (Python; keyword/product/CVE ID; severity + exploit links) (source: wiki/sources/descriptions/msd0pe-1__cve-maker.md); per-CVE PoC aggregation via [[cve2poc]] (0liverFlow; Python; GitHub/ExploitDB/Nuclei/Metasploit; CVSS/EPSS/CISA KEV; Docker labs, bug-bounty write-ups, CVE↔CPE mapping, JSON/HTML reports; cheat / RE Tools) (source: wiki/sources/descriptions/0liverFlow__CVE2PoC.md); Grafana vulnerability scanner such as [[grafana-final-scanner]] (public CVE checks incl. path traversal/SSRF/auth bypass/info disclosure; version fingerprinting + config analysis; parallel scan + auth; HTML/CSV/JSON reports; Cheat / RE Tools) (source: wiki/sources/descriptions/Zierax__Grafana-Final-Scanner.md); broader infosec reference wikis with a Games / Game Hacking draft such as [[infosec-reference]] (`Draft/Games.md`) (source: wiki/sources/descriptions/rmusser01__Infosec_Reference.md); practical game-hacking RE cheatsheets such as [[gamehacking-cheatsheet]] (memory editing, injection, IDA/Ghidra, Unity/Unreal, anti-cheat topics) (source: wiki/sources/descriptions/ridpath__gamehacking-cheatsheet.md); free multi-arch RE tutorials such as [[mytechnotalent-reverse-engineering]] (x86/x64/ARM/AVR/RISC-V; static + dynamic analysis) (source: wiki/sources/descriptions/mytechnotalent__Reverse-Engineering.md); Windows-focused RE/debugging guides such as [[hacking-windows]] (C; cheat / guide) (source: wiki/sources/descriptions/mytechnotalent__Hacking-Windows.md); Rust binary RE courses such as [[hacking-rust]] (PDF + per-chapter Cargo labs; x64/ARM64/ARM32; write/debug/disassemble) (source: wiki/sources/descriptions/mytechnotalent__hacking-rust.md); Go binary RE courses such as [[go-hacking]] (PDF + per-chapter Go source and IDA `.idb` labs; x64/ARM64/ARM32; write/debug/analyze or patch) (source: wiki/sources/descriptions/mytechnotalent__go-hacking.md); embedded firmware RE courses such as [[embedded-hacking]] (RP2350/Pico 2; Pico SDK/CMake labs; GPIO→inline ARM assembly; GDB/Ghidra/OpenOCD; Python ARM Thumb FP firmware patcher; IoT / hardware hacking) (source: wiki/sources/descriptions/mytechnotalent__embedded-hacking.md); action-camera / IoT firmware RE toolkit such as [[sjcam]] (SJ4000 Air / Allwinner V3; AVIOCTRL TCP client; Lelouch Android ARM custom CFW; EGON/IMAGEWTY + BCL1 parsers; CVE-2026-52656 PoC) (source: wiki/sources/descriptions/keowu__sjcam.md); structured AC/kernel/VT-x/graphics-integrity research index [[anti-cheat-research-index]] (Anti Cheat / guide lane; shellcode/attach/present-hook/hardware-trace refs) (source: wiki/sources/descriptions/xhscfq__anti-cheat-research-index.md); Cheat Engine register tutorials such as [[ce-tutorial]] (CE register roles; cheat / guide) (source: wiki/sources/descriptions/krampus-nuggets__ce-tutorial.md); step-by-step game-hacking labs such as [[intro-to-gamehacking]] (memory scan / pointer chains / injection / hooking / pattern scan; CE → C++ cheats; practice binaries; cheat / guide) (source: wiki/sources/descriptions/kotae4__intro-to-gamehacking.md); IDA-database cheat decompilation reconstructions such as [[ezfrags]] (ALittlePatate; C++; legacy FPS cheat incremental reimplementation—glow ESP, radar, no-flash, bunny hop, memory/signature utilities; obfuscation-pattern and practical reversing study; cheat / guide) (source: wiki/sources/descriptions/ALittlePatate__ezfrags.md); No Starch Press *Game Hacking* companion chapter demos such as [[game-hacking-code]] (GameHackingBook; Visual Studio Win32 C++; memory/injection/hook/Present-overlay samples + Lua forensics scripts; cheat / guide) (source: wiki/sources/descriptions/GameHackingBook__GameHackingCode.md); gamified 2D platformer training such as [[squally]] (Squalr; C++ Cocos2d-x; values/operators/logic for memory reasoning through gameplay; Windows/macOS/Linux; cheat / guide) (source: wiki/sources/descriptions/Squalr__Squally.md); AssaultCube C++ cheat samples such as [[assault-cube-cheat]] (gmh5225; modding / memory analysis; cheat / game:assault cube) sit beside [[simple-ac-internal-cheat]] and [[external-esp-hack-assaultcube]] on the same beginner learning title. (source: wiki/sources/descriptions/gmh5225__AssaultCubeCheat.md); Title-specific Apex Legends hooking + memory-analysis samples such as [[apex-apex-cheat]] (gmh5225; C/C++; hooking / memory analysis; cheat / game:apex legends) sit beside [[apex-legends-sdk]] and [[apex-cheat-fixed]] under [[easy-anti-cheat]]. (source: wiki/sources/descriptions/gmh5225__Apex-ApexCheat.md); C source→executable linking/loading/format primer such as [[underthehoodofexecutables]] (compile/link/load/PE-ELF fundamentals; cheat/guide + AC engineer literacy) (source: wiki/sources/descriptions/gmh5225__underTheHoodOfExecutables.md); textbook exercise solutions such as [[practical-reverse-engineering-solutions]] (Bruce Dang et al. *Practical Reverse Engineering*; x86/x64 disassembly, ARM assembly, Windows kernel analysis, rootkit challenges; annotated assembly + explanations; cheat / guide; DPC+APC) (source: wiki/sources/descriptions/gmh5225__Practical-Reverse-Engineering-Solutions.md); educational CS2/Source 2 internals wiki such as [[cs2-internals]] (PE/VM fundamentals → Source 2 modules, Schema/Entity, static RE methodology; MkDocs labs on public dumps/demos; excludes AC evasion/operational cheat dev; cheat/guide; ianveig29) (source: wiki/sources/descriptions/ianveig29__cs2-internals.md); CS2 function-signature anchor notes such as [[cs2-signature-list]] (Salvatore-Als; Markdown + IDC helper; string anchors and per-build search guidance for internal routines—team switch, item give, chat, damage; cheat / `[Signature]`) sit in the same Source 2 RE lane beside automated dumpers. (source: wiki/sources/descriptions/Salvatore-Als__cs2-signature-list.md); automated CS2 signature/gamedata pipelines such as [[cs2-vibe-signatures]] (HLND2T; Python generation + C++ depot-binary verification; outputs for [[cs2fixes]], CounterStrikeSharp, cs2kz, cs2surf; ida-pro-mcp Agent SKILLS workflow; cheat / game:cs2 `[Signature]`) extend that lane for mod-framework maintainers after patches. (source: wiki/sources/descriptions/HLND2T__CS2_VibeSignatures.md); generated CS2 SDK header packs such as [[sdk-cs2]] (FrySimpl3; C++ engine types, enums, and subsystem interfaces for client, rendering, networking, schema, panorama, particles, and physics; reference definitions for RE tooling and CS2 analysis tools; cheat / game:cs2 [SDK]) complement signature and offset lanes as typed layout groundwork. (source: wiki/sources/descriptions/FrySimpl3__SDK_CS2.md); CS:GO five-part offensive-technique guide such as [[master-guide]] (csgohacks; cheat / guide) complements that Source 1 learning lane beside runnable CS:GO samples. (source: wiki/sources/descriptions/csgohacks__master-guide.md); lightweight educational external CS:GO PoC such as [[le-chiffre]] (Blaumaus; C++; bunnyhop, triggerbot, aimbot, glow ESP, radar; memory-based manipulation + RE fundamentals; cheat / game:csgo [External]) complements that lane beside tutorial samples like [[csgo-cheats]]. (source: wiki/sources/descriptions/Blaumaus__le_chiffre.md); reverse-engineered CS:GO animation subsystem code such as [[csgo-animation-code-reversed]] (click4dylan; C++; animation code RE; cheat / game:csgo) complements that Source 1 learning lane for bone-matrix and pose/sequence study. (source: wiki/sources/descriptions/click4dylan__CSGO_AnimationCode_Reversed.md); CS2 in-binary anticheat RE such as [[cs2-anticheat]] (danielkrupinski; anticheat code extracted from CS2 binaries; June 2023 update baseline; modding/debugging; explore anticheat:cs2) (source: wiki/sources/descriptions/danielkrupinski__cs2-anticheat.md); decompiled VAC module internals such as [[vac]] (detection modules, signature/memory/integrity scanning, Steam comms; annotated module RE; explore anticheat:vac); VAC module delivery/dump PoCs such as [[dumpvac]] (RenardDev; hooks Steam/module-loading paths; disables module execution; captures and decrypts received modules for offline inspection; C/C++; explore anticheat:vac) (source: wiki/sources/descriptions/RenardDev__DumpVAC.md) ; curated game file-format/asset reversing resources via [[awesome-game-file-format-reversing]] (VelocityRa; models/textures/animations/archives/scripts/level data; general tools + Unity/Unreal/Source/CryEngine sections; communities/wikis/middleware docs; cheat / RE Tools) (source: wiki/sources/descriptions/VelocityRa__awesome-game-file-format-reversing.md); title-specific DOS retail-data archaeology via [[pc-wackywheels-doc]] (vs-sr-dev; Wacky Wheels 1994; WACKY.DAT archive, track/sprite formats, pseudo-3D floor-renderer fixed-point LUTs, audio/save/config; Python 3 + numpy/Pillow extractors; Skunny Kart cross-ref; cheat / RE Tools) (source: wiki/sources/descriptions/vs-sr-dev__pc-wackywheels-doc.md); from-scratch late-1990s engine reimplementation via [[omikron-tns-omk-engine]] (sosso33; Omikron: The Nomad Soul 1999; C++20 Runtime.exe replica + 153-opcode script VM, 8192-byte game state, cutscene/UI/audio/3D format docs; Python verification via announcement-trace diff against original binary; optional SDL/Vulkan; user-supplied retail data; cheat / RE Tools) (source: wiki/sources/descriptions/sosso33__omikron-tns-omk-engine.md); curated game technology analysis resources via [[awesome-game-analysis]] (OTFCG; Markdown index by game title, engine, developer, year, and topic; engine internals and production techniques; README Video game tech analysis resources) (source: wiki/sources/descriptions/OTFCG__Awesome-Game-Analysis.md)(source: wiki/sources/descriptions/danielkrupinski__VAC.md) - **Network / NDIS:** user-mode packet-filter APIs such as [[ndisapi]] (Windows Packet Filter; NDIS-level inspect/modify) for cheat / packet-sniffer RE. (source: wiki/sources/descriptions/wiresock__ndisapi.md) C/C++ packet logger/decryptor tooling such as [[packet-sniffer]] (cheat / Packet Sniffer&Filter; networking + debugging) targets encrypted game traffic RE. (source: wiki/sources/descriptions/hercul3s__Packet-Sniffer.md) In-IDA packet handler analysis such as [[spirit-ida-plugin]] (Bratah123; Python IDAPython; MapleStory packet structure/header extraction, function output generation, text export for protocol docs; cheat / IDA Plugins) complements wire capture with static client-binary workflows. (source: wiki/sources/descriptions/Bratah123__SpiritIDAPlugin.md) In-IDA Protocol Buffer schema recovery such as [[protobuf-finder]] (Accenture; Python IDAPython; Google protobuf runtime + IDA APIs; decodes embedded descriptors from compiled binaries; dedicated search action and custom result views; recover network/serialization `.proto` definitions; README [Protobuf]) complements published schema dumps such as [[protobufs]]. (source: wiki/sources/descriptions/Accenture__protobuf-finder.md) MapleStory v176 runtime pointer/offset economy reads such as [[battleanalysis176]] (Bratah123; C++ console; mesos/NX hourly projection from live client values; private-server RE; cheat / game:maplestory [Battle Analysis]) (source: wiki/sources/descriptions/Bratah123__BattleAnalysis176.md) Python PTCGO private-server stacks such as [[spirit-ptcgo]] (Bratah123; protobuf client protocol, HTTP/game server, card-bundle RE helpers; Private Server / Pokemon TCG Online) complement wire capture with self-hosted authoritative backends for protocol and game-logic study. (source: wiki/sources/descriptions/Bratah123__Spirit-PTCGO.md) Python Konami BEMANI arcade RE toolkit such as [[bemaniutils]] (DragonMinded; IFS/2DX/AFP asset unpack-repack, encrypted NVRAM, eAmusement wire protocol, packet sniff/MITM/replay, hobby server backends for IIDX/DDR/Pop'n/SVDX; legacy arcade networking + asset format RE) extends that lane for rhythm-game protocol and preservation workflows. (source: wiki/sources/descriptions/DragonMinded__bemaniutils.md) Official Valve [[game-networking-sockets]] (cross-platform C++/C transport; reliability/ack vectors, bandwidth lanes, network simulation, encrypted transport, P2P NAT traversal; Steam multiplayer backend reference; README [Steam]) gives open transport internals for studying game networking stacks. (source: wiki/sources/descriptions/ValveSoftware__GameNetworkingSockets.md) Souls-series private-server emulators such as [[ds3os]] (Dark Souls 2/3; Protobuf multiplayer protocol; Docker; matchmaking/co-op/invasions/messages; game-server RE) expose title-specific online-service architecture for protocol study. (source: wiki/sources/descriptions/TLeonardUK__ds3os.md) Genshin Impact open-source server emulators such as [[grasscutter]] (Grasscutters; Java; server-side logic, progression, world simulation, client–server protocol; quests/gacha/dungeons/multiplayer; MMORPG server-architecture RE; Private Server) extend that lane for HoYoverse protocol study. (source: wiki/sources/descriptions/Grasscutters__Grasscutter.md) Tracked Steam/Valve protobuf schema dumps such as [[protobufs]] (SteamDatabase; continuously updated `.proto` files from update pipelines and automated dumpers; CS:GO and Steam client message schemas; protocol analysis and tooling maintenance; README [Protobuf]) complement transport-level references for Steam ecosystem wire-format RE. (source: wiki/sources/descriptions/SteamDatabase__Protobufs.md) The deprecated [[ds2os]] repo is a README-only migration pointer with no remaining implementation. (source: wiki/sources/descriptions/TLeonardUK__ds2os.md) CLI network protocol craft/inject/sniff tooling such as [[inject]] (fksvs; command-line; wide protocol coverage; cheat / Packet Sniffer&Filter) complements generic capture stacks for wire-level protocol RE. (source: wiki/sources/descriptions/fksvs__inject.md) Python/Scapy game packet sniffer/parser such as [[sniparinject]] (airvzxf; YAML-driven opcode mapping; struct rules for host/node traffic; inject planned; cheat / Packet Sniffer&Filter) extends declarative wire-level game protocol RE beside generic capture stacks. (source: wiki/sources/descriptions/airvzxf__sniparinject.md) Akebi-framework packet sniffer samples such as [[akebi-packet-sniffer]] (gmh5225; driver development; DirectX/OpenGL; cheat / Packet Sniffer&Filter) complement generic capture stacks for encrypted game traffic RE. (source: wiki/sources/descriptions/gmh5225__Akebi-PacketSniffer.md) Lost Ark–focused protocol loggers such as [[lost-ark-logger]] (gmh5225; captures/decodes client–server traffic; events, items, combat) extend title-specific wire RE beside generic capture stacks. (source: wiki/sources/descriptions/gmh5225__LostArkLogger.md) Killing Floor UE2.5 headless clients such as [[killingfloor-bot-client]] (Node.js; native UE2 bitstream/handshake RE via Ghidra; Steam ticket validation; UDP MITM relay + disassembly; authorized/self-hosted servers) extend legacy UE2 wire RE beside generic capture stacks. (source: wiki/sources/descriptions/geekrainian__killingfloor-bot-client.md) Multiplatform C++ packet capture/parse/craft libraries such as [[pcapplusplus]] (100+ protocols; libpcap/WinPcap/Npcap + PCAP/PCAPNG) sit in the adjacent Packet Capture&Parse lane for protocol RE. (source: wiki/sources/descriptions/seladb__PcapPlusPlus.md) Windows Npcap ([[npcap]]; Nmap Project WinPcap successor; capture + inject) underpins many of those live-capture paths on Windows. (source: wiki/sources/descriptions/nmap__npcap.md) No-root Android USB Wi-Fi monitor/inject tooling such as [[rtl8852au-userspace]] (RTL8852AU userspace libusb driver; radiotap pcap + channel hopping + 802.11 frame injection; cheat / Android Network Explorer) extends that lane for raw wireless RE without kernel modules. (source: wiki/sources/descriptions/damanoreshkan-beep__rtl8852au-userspace.md) Cross-platform transparent proxy / interception tooling such as [[gecit]] (Go; eBPF sock_ops redirect on Linux; TUN routing + DNS manipulation on macOS/Windows; fake TLS ClientHello desync + built-in DoH for DPI-bypass research) complements generic capture stacks for wire-level protocol RE under filtered networks. (source: wiki/sources/descriptions/boratanrikulu__gecit.md) Frida named-pipe interceptors such as [[thats-no-pipe]] hook `NtReadFile`/`NtWriteFile` (and related waits/IoQueue) and relay IPC to an HTTP proxy over WebSocket for protocol analysis and fuzzing. (source: wiki/sources/descriptions/synacktiv__thats_no_pipe.md) Windows named-pipe enumeration GUIs such as [[pipeviewer]] (CyberArk; C#; security descriptors, connected clients, access modes, owning process; filter/search + real-time create/delete monitoring; Windows IPC attack-surface RE) complement interceptors for pre-traffic endpoint discovery. (source: wiki/sources/descriptions/cyberark__PipeViewer.md) macOS USB traffic sniff/dump via Frida such as [[frida-usb-dump]] (Big Sur-era offsets) covers host/device USB I/O RE. (source: wiki/sources/descriptions/piotrbania__frida_usb_dump.md) Windows DualShock 4 HID tooling such as [[ds4-tools]] (gmh5225; input/LED/touchpad/motion/rumble protocol RE on PC; cheat / peripheral RE) complements that USB/peripheral lane for gamepad feature study. (source: wiki/sources/descriptions/gmh5225__ds4-tools.md) C++ Minecraft Java server backends such as [[minecpp]] (gmh5225; **1.19**; authoritative server stack for protocol and offensive-technique RE in cheat / game:minecraft) complement packet-capture tooling for server-side traffic study. (source: wiki/sources/descriptions/gmh5225__minecpp.md) Rust external CS:GO modding / SDK-generation samples such as [[memcs]] (gmh5225; External tag; cheat / game:csgo) complement usermode RPM tooling for out-of-process structure recon. (source: wiki/sources/descriptions/gmh5225__memcs.md) - **Tools:** IDA/[[ghidra]]/Binary Ninja (full NSA Ghidra framework source; Java decompiler, debugger integrations; gmh5225 mirror) (source: wiki/sources/descriptions/gmh5225__ghidra.md), [[x64dbg]]/WinDbg/[[hyperdbg]] (Windows x86/x64 debugger + plugins; VT-x/EPT hypervisor-assisted user/kernel debugger — stealth breakpoints, hidden hooks, memory-access monitoring; README [VT debuger]) (source: wiki/sources/descriptions/x64dbg__x64dbg.md) (source: wiki/sources/descriptions/HyperDbg__HyperDbg.md); Windows kernel driver framework [[kernel-bridge]] (HoShiMin; C++ template; VT-x/AMD-V HV components; memory/IOCTL/hook/CPUID/MSR primitives; debugging / AC kernel research) (source: wiki/sources/descriptions/HoShiMin__Kernel-Bridge.md); VTL1 IUM trustlet debugging via [[ium-debugger]] (.NET; Hyper-V hypercalls + LiveCloudKd host patch for guest WinDbg attach to VSM secure enclaves) (source: wiki/sources/descriptions/ReverseWarrior__IUM-Debugger.md), [[syser]] (C/C++ Windows x86/x64 debugger; RE / plugin / modding; cheat / debugging) (source: wiki/sources/descriptions/marakew__syser.md), [[xdv]] (C/C++ disassembler/debugger; extension-plugin architecture; RE / plugin / modding / SDK generation; cheat / debugging) (source: wiki/sources/descriptions/imugee__xdv.md), [[hyperion-disassembler]] (Sidenai; native C++ multi-arch disassembler/decompiler; PE/ELF/Mach-O/.NET; x86/x64/ARM/AArch64/MIPS/PPC; CFG, FLIRT, PDB, BinDiff, RTTI recovery, SSA decompiler, packer detection, Lua scripting, ImGui UI; cheat / RE tools) (source: wiki/sources/descriptions/Sidenai__hyperion-disassembler.md), [[koidbg]] (Windows ARM64 debugger; EN/PT docs; cheat / debugging) (source: wiki/sources/descriptions/keowu__koidbg.md), [[farm64]] (pure-Rust `no_std` AArch64 disassembler/encoder; iced-x86-shaped API; zero-heap decode; SVE/SME/SIMD/FP; semantic round-trip encode; wasm/bare-metal friendly; cheat / RE tools) (source: wiki/sources/descriptions/binsnake__fARM64.md), [[cheat-engine]] (open-source memory scan/debug/disasm IDE; Lua scripting, speedhack, code injection, cheat tables; user-mode + kernel DBVM; Delphi/Pascal + C) (source: wiki/sources/descriptions/cheat-engine__cheat-engine.md), C#/.NET Windows memory editor [[squalr-sharp]] (Squalr; SIMD scan, pointer chains, NASM asm/disasm, process debug, .NET object inspection; game-hacking / memory RE) (source: wiki/sources/descriptions/Squalr__Squalr-Sharp.md), [[mhsx]] (L-Spiro; C++ Windows memory searcher/debugger; MHS successor; expression/regex/string scans, hex editor, disasm, PE inspect, speedhack; live attach x86/x64; cheat / memory analysis) (source: wiki/sources/descriptions/L-Spiro__MhsX.md), [[dnspy]] (.NET assembly debugger/decompiler/editor; C#/VB/IL; live edit + breakpoints; Unity Mono via patched runtimes; For Unity) (source: wiki/sources/descriptions/dnSpy__dnSpy.md); dnSpyEx extension [[dnspy-extension-holly]] (HoLLy-HaCKeR; C#; source-map-style renaming, managed DLL injection while debugging, native disassembly, CFG visualization; obfuscated .NET/Unity RE; For Unity) (source: wiki/sources/descriptions/HoLLy-HaCKeR__dnSpy.Extension.HoLLy.md), GUI .NET patch automation [[acepatcher]] (BataBo; C#; dnlib + Harmony; map patch methods to targets across method types; import/export password-protected patch sets; packed/obfuscated managed binaries; repeatable .NET patch automation; [.NET Patcher]) (source: wiki/sources/descriptions/BataBo__ACEPatcher.md), [[frida]]; Cheat Engine–like MCP memory tooling via [[memmcp]] (Python; Game Develop / MCP) (source: wiki/sources/descriptions/un4ckn0wl3z__MemMCP.md); usermode process-memory / RPM research libs such as [[umpmlib]] (C/C++; cheat / RPM) (source: wiki/sources/descriptions/waryas__UMPMLib.md); related memory-analysis samples such as [[eupmaccess]] (C/C++; cheat / RPM) (source: wiki/sources/descriptions/waryas__EUPMAccess.md); AVX2 VPGATHER + VEH address-validity probes such as [[vpgather]] (Peribunt; user-mode PoC; infer whether a virtual address would fault before dereference; reduced memory-state side effects; stealth memory probing for RE / AC bypass research) (source: wiki/sources/descriptions/Peribunt__VPGATHER.md); [[reclass-net]] (ReClassNET; .NET memory class reconstruction + remote process inspection; x86/x64 node types, scanners, debuggers, legacy ReClass import/export; C# UI + native C++ core; C++/C# layout export; cheat / debugging) (source: wiki/sources/descriptions/ReClassNET__ReClass.NET.md); ReClass.NET kernel-driver memory plugins such as [[reclass-net-driverreader]] (C#/C++; RPM → driver reads for AC-blocked structure recon) (source: wiki/sources/descriptions/niemand-sec__ReClass.NET-DriverReader.md); ReClass.NET DMA plugins such as [[reclass-dma]] (C/C++ plugin; structure recon via external DMA; cheat / debugging) (source: wiki/sources/descriptions/gmh5225__ReClass-DMA.md); standalone extended ReClass tools such as [[reclass-ex]] (ajkhoury; C++; RTTI, PDB symbols, module targeting, plugins; interactive class layout recon; cheat / debugging) (source: wiki/sources/descriptions/ajkhoury__ReClassEx.md); kernel-memory structure recon via [[kreclassex]] (BeneficialCode; C++; WinDbg extension + desktop GUI; debug-session attach, kernel layout inspection, function-pointer resolve, reconstructed type views; networking/config + editor integrations; Windows kernel RE + game anti-cheat research) (source: wiki/sources/descriptions/BeneficialCode__KReClassEx.md); modern Qt structured binary editor [[reclass]] (IChooseYou; C++17/Qt 6/QScintilla; structs/arrays/pointers/primitives; inline edit, foldable views, hex/ASCII preview; process-memory + WinDbg plugins; MCP; cheat / debugging) (source: wiki/sources/descriptions/IChooseYou__Reclass.md); cross-platform process-memory / hook libraries such as [[libmem]] (Win/Linux/FreeBSD; enum / scan / VMT hook / Capstone·Keystone JIT; C/C++ + Rust/Python/Lua) (source: wiki/sources/descriptions/rdbo__libmem.md); header-only Windows memory helpers such as [[remem]] (0xenia; typed RPM/WPM, pointer validation, optional exception handling/logging, pattern scan, calling-convention wrappers; RE tooling / game memory research; cheat / RPM for Windows) (source: wiki/sources/descriptions/0xenia__remem.md); Rust Windows game-hacking libraries such as [[apwil]] (inline/IAT/VMT/VEH/HWBP hooks; PE/PEB; process/thread hijack; DirectX overlay; internal & external) (source: wiki/sources/descriptions/april-ivy__Apwil.md); Windows memory-analysis / process-manipulation C++ frameworks such as [[memwars]] (gmh5225; scan / pattern search / module enum / injection / memory edit; Testing Framework; cheat-dev library) (source: wiki/sources/descriptions/gmh5225__MemWars.md); streamlined RE utility toolkit such as [[easyre]] (gmh5225; pattern scan, memory dump, structure reconstruction; Trace Execution; cheat / RE tools) (source: wiki/sources/descriptions/gmh5225__EasyRe.md); Windows C# WinForms in-process assembly dumper [[mega-dumper]] (CodeCracker-Tools; native + managed PE dump; module inspection, anti-dump/hook detection, virtual memory/heap/process exploration, AppDomain enum, managed injection + minidump; malware/.NET RE; cheat / [Dump native and .NET assemblies]) (source: wiki/sources/descriptions/CodeCracker-Tools__MegaDumper.md); official Microsoft inline-hook / API-instrumentation via [[detours]] (Windows monitoring package; upstream to [[detoursnt]] and NTDLL-only MinHook fork [[ntminhook]] (gmh5225; cheat / hook research) and Detours-linked overlay samples such as [[hydrahook]]) (source: wiki/sources/descriptions/microsoft__Detours.md) (source: wiki/sources/descriptions/gmh5225__ntminhook.md); minimal cross-platform inline hooking via [[subhook]] (C/C++; Windows/Linux/macOS; x86 32/64; super-simple trampoline API; gmh5225) (source: wiki/sources/descriptions/gmh5225__subhook.md); modern Windows x86/x86-64 inline hooking via [[renhook]] (C++; Zydis disassembly; safe trampoline APIs + examples; WopsS) (source: wiki/sources/descriptions/WopsS__RenHook.md); single-header x86-64 hooking via [[light-hook]] (SamuelTulach; pure C; Windows/Linux/EFI; user/kernel/firmware examples; platform memory shims; no heavy disassembler; lightweight instrumentation; cross-platform hook library) (source: wiki/sources/descriptions/SamuelTulach__LightHook.md); cross-platform PLT/GOT/IAT hooking via [[plthook]] (Linux/macOS/Windows; ELF/Mach-O/PE; dynamic-link entry replacement for profiling and interception RE) complements inline-hook packages (source: wiki/sources/descriptions/kubo__plthook.md); Win32 API trace workstations such as [[kn-win32-api-monitor]] (Tauri 2 UI; IAT hooks + shared-memory transport; ~30k APIs incl. `GetProcAddress`/`LdrGetProcedureAddress` resolver substitution; durable `.knapm` replay with metadata decode; security/RE/anti-cheat research; kernullist) extend that lane with session capture and timeline search (source: wiki/sources/descriptions/kernullist__KnWin32ApiMonitor.md); Ghidra native-code metrics via [[ghidrametrics]] (cyclomatic complexity / function size / call depth; headless + JSON export) (source: wiki/sources/descriptions/westfox-5__GhidraMetrics.md); CTF-oriented GhidraScript automation via [[ghidra-scripts]] (competition scripts for common RE challenge patterns; cheat / Ghidra Scripts) (source: wiki/sources/descriptions/ghidragolf__ghidra_scripts.md); maintained ATR GhidraScript toolkit via [[ghidrascripts]] (Java automation; AI rename, complexity viz, Golang, BSim/FunctionID, SHAREM/Malpedia enrichment; malware/RE scale; cheat / Some scripts) (source: wiki/sources/descriptions/advanced-threat-research__GhidraScripts.md); Python Ghidra analysis automation via [[pagalaxylab-ghidra-scripts]] (P-Code parameter tracing, Objective-C msgSend analysis, error-print rename, OLLVM CFF deobfuscation; shared helpers + docs; firmware/binary RE; PAGalaxyLab; cheat / Scripts) (source: wiki/sources/descriptions/PAGalaxyLab__ghidra_scripts.md); Windows 9x VxD INT 20h annotation via [[ghidra-vxd-tools]] (Jython Ghidra scripts; VxDCall struct + VMDisp9x service decode; legacy kernel driver / historical game-protection RE; Windows9x category) (source: wiki/sources/descriptions/andrew-hoffman__ghidra-vxd-tools.md); improved string analysis via [[better-string-analyzer]] (Java Ghidra plugin; modding / literal triage; cheat / Ghidra Plugins) (source: wiki/sources/descriptions/fuzzypickles14__BetterStringAnalyzer.md); headless Ghidra MCP server [[ghidra-headless-mcp]] (40+ tools; disasm/decompile/xrefs/types/scripting; fake backend + CLI; JSON-RPC stdio for Cursor/Claude agents) (source: wiki/sources/descriptions/mrphrazer__ghidra-headless-mcp.md); Python 3 ↔ Ghidra scripting bridge [[ghidra-bridge]] (CPython client outside in-Ghidra Jython; external automation for plugins and batch RE) (source: wiki/sources/descriptions/justfoxing__ghidra_bridge.md); JVM-free Ghidra decompiler library [[libghidra]] (C++/Rust/Python; SLEIGH + Pcode; disassembly, decompilation, CFG, types, xrefs; LibGhidraHost HTTP or offline Sleigh backend; 0xeb) (source: wiki/sources/descriptions/0xeb__libghidra.md); live GDB ↔ Ghidra debugger bridge [[gdbghidra]] (Python GDB client + Java Ghidra extension; cursor/stack sync, register propagation for decompilation, breakpoint control, relocation handling; interactive static+dynamic RE) (source: wiki/sources/descriptions/Comsecuris__gdbghidra.md); RESim/Simics simulation-backed debugging via [[resim-ghidra-plugins]] (mfthomps; Java Ghidra Debugger extension; gdb-multiarch remote to RESim targets incl. Simics full-system on port 9123; bookmarks/watchmarks/stack console/listing hovers; mirrors RESim IDA Pro plugins; dynamic simulation-backed RE) (source: wiki/sources/descriptions/mfthomps__RESimGhidraPlugins.md); Ghidra↔Frida static+dynamic bridge via [[dragonhook]] (Java plugin; localhost HTTP API exposes GhidraDB functions/comments/xrefs to Frida agents; GUI session launcher; runtime indirect-call resolution, live xref/comment sync, symbol backtraces, call tracing, string xref resolution, experimental HW watchpoints; mitros123) (source: wiki/sources/descriptions/mitros123__DragonHook.md); Ghidra→Frida hook script generator via [[ghidra-frida-hook-gen]] (CENSUS; Java extension; right-click actions emit full Frida hook scripts, reusable snippets, and advanced hook configs from disassembly context; function-level and arbitrary address hooks; static→dynamic setup accelerator; cheat / Ghidra Plugins) (source: wiki/sources/descriptions/CENSUS__ghidra-frida-hook-gen.md); Binary Ninja↔Frida static+dynamic bridge via [[frinja]] (Frida plugin for Binary Ninja; continuation of BinRida; cheat / Binary Ninja plugins) (source: wiki/sources/descriptions/dzervas__frinja.md); whole-program Ghidra+GPT summarization via [[gpt-wpre]] (Python; `ghidra_bridge` decomp/call-graph extract → bottom-up callee-context summaries; ChatGPT lane) (source: wiki/sources/descriptions/moyix__gpt-wpre.md); GBA ROM loader [[gba-ghidra-loader]] (memory/IO map + cartridge-header entry point; Cheat Ghidra Plugins / `GameBoy`) (source: wiki/sources/descriptions/pudii__gba-ghidra-loader.md); runtime-loadable decompiler plugins via [[ghidra-decompiler-plugins]] (Bazel shared libs + plugin manager patch; RISC-V vector Rules/Actions lift to `vector_memcpy`/`vector_memset`/`vector_strlen`; datatest framework; embedded/firmware RE) (source: wiki/sources/descriptions/thixotropist__ghidra_decompiler_plugins.md); programmatic Ghidra decompilation via [[ghiradec]] (integration or standalone tool on Ghidra's analysis engine; automated binary analysis / batch RE; Cheat → Ghidra Decompiler) (source: wiki/sources/descriptions/gmh5225__GhidraDec.md); browser-based Ghidra decompilation via [[pyre]] (WASM SLEIGH decompiler; multi-arch pseudocode in-browser; no server; ant4g0nist; cheat / Decompiler) (source: wiki/sources/descriptions/ant4g0nist__pyre.md); native standalone Ghidra decompiler via [[enigma]] (C++; SLEIGH/Pcode from Ghidra SoftwareModeling + Utility; no JVM; BFD multi-arch; Capstone pipelines; embeddable for AI/agents; adam-040; cheat / Decompiler) (source: wiki/sources/descriptions/adam-040__Enigma.md); agent-first Rust Ghidra decompiler via [[kuna]] (Noelo-Lab; Rust Ghidra decompiler + SLEIGH port; CLI, WASM, Ghidra plugin; tunable phase pipeline for LLM agent refinement; cheat / Decompiler) (source: wiki/sources/descriptions/Noelo-Lab__kuna.md); stripped Rust binary analysis in Ghidra via [[ghidrust]] (DMaroo; Java Ghidra extension; Rust detection heuristics, Function ID stdlib matching, experimental C→Rust decompiler output translation; paused maintenance; cheat / Rust decompiler) (source: wiki/sources/descriptions/DMaroo__GhidRust.md); symbolic-execution decompiler via [[ouroboros]] (Hexorg; Rust; constraint tracking, expression rewriting, structured control-flow recovery beyond SSA-only; processor specs + interactive frontend; advanced decompilation research; cheat / Decompiler) (source: wiki/sources/descriptions/Hexorg__Ouroboros.md); interactive Ghidra angr symbolic execution via [[angry-ghidra]] (Java extension + Python angr/claripy; set start/find/avoid addresses, launch symbolic exploration, apply patched bytes to program state; CTF/malware/game RE; Nalen98; cheat / Use angr in Ghidra) (source: wiki/sources/descriptions/Nalen98__AngryGhidra.md); IDA Pro Ghidra decompiler integration via [[blc]] (Binary Lifting Contraption; embed Ghidra decompiler in IDA UI; cheat / IDA Plugins; cseagle) (source: wiki/sources/descriptions/cseagle__blc.md); Vivisect↔Ghidra symbolic decompilation bridge via [[viv-ghidra-decompiler]] (Python/Java; Vivisect symbolik → Ghidra p-code; headless JSON-RPC/TCP backend; Qt dock C pseudocode; cheat / Ghidra Decompiler) (source: wiki/sources/descriptions/atlas0fd00m__viv-ghidra-decompiler.md); Security Joes IR/malware RE toolkit [[threatresearch]] (Ghidra/IDA plugins, deobf scripts, YARA; Python/Java report companions) (source: wiki/sources/descriptions/securityjoes__ThreatResearch.md); host process/system explorers such as [[systeminformer]] (formerly Process Hacker; Cheat Windows kernel explorer) (source: wiki/sources/descriptions/winsiderss__systeminformer.md); JS WinDbg kernel scripts such as [[windbg-scripts]] (Cheat → WinDbg Plugins) (source: wiki/sources/descriptions/yardenshafir__WinDbg_Scripts.md); KasperskyLab dump-triage JS scripts [[windbg-js-scripts]] (exception records, STL map walk, broken noexcept stacks, x86-in-x64 kernel dump stacks; manifest XML + Python helper; anti-cheat/malware analysis; Cheat → JS Scripts) (source: wiki/sources/descriptions/KasperskyLab__WinDbg-JS-Scripts.md); WinDbg automation cookbook [[windbg-cookbook]] (TimMisiak; JS data-model scripts + `dx` query recipes; dependency inspection, stack collection/corruption detection, time-travel debugging analysis; README [WinDbg]) (source: wiki/sources/descriptions/TimMisiak__WinDbgCookbook.md); WinDbg command extension [[swishdbgext]] (comaeio; Matt Suiche; expands commands and fixes/improves built-ins; Cheat → WinDbg Plugins) (source: wiki/sources/descriptions/comaeio__SwishDbgExt.md); WinDbg COM trace extension [[comon]] (class creation + interface querying; Cheat → WinDbg Plugins) (source: wiki/sources/descriptions/lowleveldesign__comon.md); WinDbg token/heap pointer viz extension [[dk]] (refactored tokenext; local-buffer / symbol / heap-allocation overlays + allocation history; Cheat → WinDbg Plugins) (source: wiki/sources/descriptions/long123king__dk.md); CDB/WinDbg MCP server [[mcp-windbg]] (Python; dump triage + remote sessions for LLM clients) (source: wiki/sources/descriptions/svnscha__mcp-windbg.md); Windows CLI + MCP [[windbg-tool]] (Devolutions; Rust; TTD `.run` replay, crash-dump triage, live probes; JSON + MCP for AI agents) (source: wiki/sources/descriptions/Devolutions__windbg-tool.md); Windows process-tree memory profiler [[onlooker]] (DenuvoSoftwareSolutions; C++/CMake/Qt; records process-tree memory stats like Linux time; Qt GUI trace inspector + JSON conversion; memory growth/OOM/performance regression diagnosis in native toolchains) (source: wiki/sources/descriptions/DenuvoSoftwareSolutions__Onlooker.md); Agentic WinDbg copilot [[windbg-copilot]] (0xeb; C++ extension; AI Q&A, auto command execution with explanations, multi-provider models, persistent context, decompilation help, HTTP/MCP + CLI; crash triage, exploit debugging, Windows security analysis) (source: wiki/sources/descriptions/0xeb__windbg-copilot.md); WinDbg x64 LLM decompiler extension [[windbg-decompile-ext]] (live function disasm → verified pseudocode; Cheat → WinDbg Plugins) (source: wiki/sources/descriptions/kernullist__windbg-decompile-ext.md) pykd PEDA-like WinDbg UI [[twindbg]] (bruce30262; register/disasm/stack pane + smart stack deref; PEDA-style memory/symbol commands; Cheat → WinDbg Plugins) (source: wiki/sources/descriptions/bruce30262__TWindbg.md); IDA Pro TTD trace replay via [[ttddbg]] (loads WinDbg-recorded `.run` files; forward/backward stepping; syscall/memory/register replay; cheat / Time Travel Debugging) (source: wiki/sources/descriptions/gmh5225__ttddbg.md); IDA Pro execution-trace explorer [[tenet]] (trace timeline; forward/backward stepping; register/memory state; multiple trace formats; disasm integration; malware/vuln RE; cheat / Execution Traces) (source: wiki/sources/descriptions/gmh5225__tenet.md); IDA Pro 9.0 Tenet port [[tenet-ida9.0]] (same trace timeline/stepping; IDA 9.0 SDK APIs; cheat / Execution Traces) (source: wiki/sources/descriptions/gmh5225__Tenet-IDA9.0.md); LiveKD-style kernel live debugging via [[kn-live-dbg]] (driver memory primitives + user-mode TUI; symbols/types/disassembly without traditional kernel debugger setup) (source: wiki/sources/descriptions/kernullist__kn-live-dbg.md); kernel debugging toolkit [[kdbg]] (driver backend + CLI; user/kernel memory R/W, module/thread enum, tracing; x64; driver-signing setup; cheat / Tool) (source: wiki/sources/descriptions/allogic__KDBG.md); stealth KD attach via [[nokd]] (kernel debugger protocol without ntoskrnl KD variable setup; local `KdDebuggerDataBlock` decode → WinDbg) (source: wiki/sources/descriptions/irql__nokd.md); [[kdbgdecryptor]] driver sample for KDBG decryption (`KdDecodeBlockData` or manual `KiWaitNever`/`KiWaitAlways`; kernel RE / AC memory-analysis study) (source: wiki/sources/descriptions/Air14__KDBGDecryptor.md); Linux-host KVM/QEMU WinDbg-style kernel debugger via [[ntoseye]] (Win10/11 guest; GDB stub; WinDbg-like CLI, PDB symbols, breakpoints; Kernel Debugger) (source: wiki/sources/descriptions/dmaivel__ntoseye.md); autonomous Windows PoC generation via [[pocsmith]] (Claude agent + MCP Hyper-V/kd/Ghidra; patchwatch diffs → write/build/verify on pre-patch VMs) (source: wiki/sources/descriptions/originsec__pocsmith.md); GDB MCP servers [[mcp-gdb]] (GDB MI; signal-slot) and [[gdb-mcp]] (FastMCP + SSE; gdb-command proxy; breakpoints / memory / registers / step) (source: wiki/sources/descriptions/signal-slot__mcp-gdb.md) (source: wiki/sources/descriptions/jtang613__gdb-mcp.md); LLDB MCP bridge [[lisa-py]] (Python plugin + MCP server; breakpoints, backtraces, disasm, memory reads; Game Develop / MCP for LLDB) (source: wiki/sources/descriptions/ant4g0nist__lisa.py.md); primitive GDB RSP stub [[gdbserver9x]] for 32-bit exes on Win98SE/XP (VC6; Binary Ninja GDB adapter) (source: wiki/sources/descriptions/robert-yates__gdbserver9x.md); portable Windows GDB builds such as [[gdb-windows-binaries]] (mingw-w64 v12.2.0; all arches; TUI + Python; no extra DLL deps) (source: wiki/sources/descriptions/noword__GDB-Windows-Binaries.md); PE triage viewers such as [[totalpe2]] (headers/imports/exports/.NET metadata) (source: wiki/sources/descriptions/zodiacon__TotalPE2.md) and [[pe-bear]] (Qt GUI PE viewer/editor; hex edit, section manipulation, overlay extract, side-by-side compare) (source: wiki/sources/descriptions/hasherezade__pe-bear.md); Python PE analyzer + Wine launcher [[runexe]] (CDJuaum; static import/manifest/.NET triage; flags [[easy-anti-cheat]]/[[battleye]] import signatures; Wine prefix + Winetricks provisioning; Linux game-security RE) (source: wiki/sources/descriptions/CDJuaum__RunEXE.md); cross-platform hex workbench [[hexwalk]] (Capstone disasm, entropy, binwalk scan, file diff, YAML PE/ELF overlays; Hex Viewer/Editor/Analyzer) (source: wiki/sources/descriptions/gcarmix__HexWalk.md), RE-oriented hex editor / binary analysis platform [[imhex]] (C++; pattern-language parsing/visualization, integrated disassembly, diff/hash, plugin extensibility; firmware/file/memory/game binary triage) (source: wiki/sources/descriptions/WerWolv__ImHex.md), Java format inspector [[binaryinternals]] (field/bit-level BMP/class/JPEG/PNG/ZIP; OpenJDK/Maven; reusable format libs; RE education / parser dev) (source: wiki/sources/descriptions/amosshi__binaryinternals.md); export-table dumpers that generate proxy-DLL forwarding stubs for hijack research such as [[dll-hijack-export-dumper]] (gmh5225; PE export dump → sideload proxy source; Cheat / DLL Hijack) (source: wiki/sources/descriptions/gmh5225__DLL-Hijack-ExportDumper.md); PE parse/edit for headers, sections, imports/exports, relocations, resources, and binary patching via [[kitsupe]] (gmh5225; cheat / PE) (source: wiki/sources/descriptions/gmh5225__KitsuPE.md); MSVC Rich Header compiler toolchain triage via [[compiler-binary-richprint]] (gmh5225; prints compiler info stored between DOS stub and PE header; cheat / RE tools) (source: wiki/sources/descriptions/gmh5225__compiler-binary-richprint.md); PE metadata stripping via [[pecleaner]] (C#; zeros Rich header, debug info, PDB path, linker/timestamp fields on x86/x64 PE; cheat / RE tools) (source: wiki/sources/descriptions/colinsenner__PECleaner.md); Win32 resource editing via [[risoh-editor]] (dialogs, menus, icons, string tables, RC import/export; 32/64-bit PE/DLL) (source: wiki/sources/descriptions/katahiromz__RisohEditor.md); Go static workbench [[retract]] (PE/ELF/Mach-O; x86/x64 disasm, CFG, pseudocode, YARA, `--serve` browser UI; malware triage) (source: wiki/sources/descriptions/kernelstub__Retract.md); kernel-driver static analysis via [[cognitor]] (Go; IDA/Ghidra exports → IOCTL/access-check/ALPC/COM/native-API rule scan; Patch Tuesday PE/driver diff, SARIF/MD/JSON) (source: wiki/sources/descriptions/kernelstub__Cognitor.md); kernel-mode IRP/IOCTL live tracing via [[cfb]] (filter driver hooks IRP dispatch; logs parameters/buffers/returns; Python client; driver comm protocol RE / IOCTL fuzzing) (source: wiki/sources/descriptions/hugsy__CFB.md) and [[drvtrace]] (eversinc33; filter driver on selected targets; IRP major/minor codes, buffers, completion status; IOCTL/device-protocol RE) (source: wiki/sources/descriptions/eversinc33__drvtrace.md); Authenticode embedded-signature metadata extraction via [[pesign-analyzer]] (Windows PE with embedded code-signing certs; Anti Cheat → Sign Tools) (source: wiki/sources/descriptions/leeqwind__PESignAnalyzer.md); kernel-mode Authenticode cert metadata extraction via [[driver-soul-extraction]] (gmh5225; in-kernel PE signature-directory walk; signer name + validity timestamps; complements usermode [[pesign-analyzer]] and digest work [[pedigest]]) (source: wiki/sources/descriptions/gmh5225__Driver-SoulExtraction.md); CLI Authenticode signature stripper [[unsign]] (SV-Foster; C; 32/64-bit; removes security-directory blobs from PE for re-signing or unsigned-binary RE workflows) (source: wiki/sources/descriptions/SV-Foster__UnSign.md); comprehensive Authenticode manipulation toolkit [[trustmebro]] (KriyosArcane; Python/C++; signature steal/clone, PKCS#7 SigStash embedding, SIP hijack across 19 file types, WinVerifyTrust FinalPolicy bypass, Smart App Control evasion, SIPExec/FormatGhost persistence; YARA/Sigma + SigStash extraction; authorized red-team trust-control research) (source: wiki/sources/descriptions/KriyosArcane__TrustMeBro.md); .NET NativeAOT symbol/type recovery in IDA via [[dotniet]] (Import .NET Symbol; reconstruct types/methods lost to Native AOT) (source: wiki/sources/descriptions/synacktiv__dotNIET.md); Ghidra .NET Native AOT analysis via [[ghidra-nativeaot]] (Java analyzer/UI plugin; type hierarchy from method tables, frozen-object annotation, vtable redirection detection, ReadyToRun metadata recovery, metadata browser + virtual-method rename refactor; .NET 8+ stripped NativeAOT; malware/CTF/security RE; Washi1337) (source: wiki/sources/descriptions/Washi1337__ghidra-nativeaot.md); Ghidra Qualcomm Hexagon QDSP6 SLEIGH processor module [[ghidra-hexagon-sleigh]] (CUB3D; Hexagon v81 p-code decompilation, hardware loops/predicates, System/Monitor+Guest modes; Java analyzers, QDB log viewer, Python QMI/QuRT/RTTI scripts, Q6Zip/DLPager emulation decompression; Qualcomm firmware/binary RE; game security + mobile security research) (source: wiki/sources/descriptions/CUB3D__ghidra-hexagon-sleigh.md); Python CIL disassembly for .NET PE via [[dncil]] (Mandiant; metadata + method-body parse; operand/token resolution; YARA/detection pipelines; game engine explorer:Unity) (source: wiki/sources/descriptions/mandiant__dncil.md); runtime JIT-intercept CIL method-body dump via [[jit-dumper]] (Anonym0ose; C# analysis app + C++ Detours hook; symbol/PDB data; multi-generation .NET; metadata reconstruction for compiled-method inspection; managed-code RE / software-protection analysis; README A CIL method body dumper) (source: wiki/sources/descriptions/Anonym0ose__JitDumper.md); open-source .NET assembly browser/decompiler via [[ilspy]] (tree browser; C#/VB.NET/IL; .NET Framework/Core/5+; async/LINQ/generics; plugin extensibility; README For Unity) (source: wiki/sources/descriptions/icsharpcode__ILSpy.md); Go pclntab/moduledata symbol+type recovery for stripped Go PE via [[goresym]] (Mandiant; IDA-compatible export) (source: wiki/sources/descriptions/mandiant__GoReSym.md); in-IDA Go runtime metadata recovery via [[golang-loader-assist]] (parse pclntab/moduledata; apply function names, source refs, and types IDA misses on stripped Go PE; cheat / GO Reversed) (source: wiki/sources/descriptions/gmh5225__golang_loader_assist.md); stepwise IDAPython Go analysis workflow via [[alphagolang]] (SentineLabs; binary ID, pclntab recovery, function discovery, strings, types; YARA for Go PE/ELF/Mach-O; stripped/optimized Go malware RE; cheat / Analyzing Golang Binaries) (source: wiki/sources/descriptions/SentineLabs__AlphaGolang.md); nonstandard calling-convention retagging + tuple-like multi-return structures for Swift/Golang/fastcall via [[swift-ida]] (Python IDA plugin; context-menu convention retag; modern language runtime/ABI RE; ViRb3; cheat / IDA Plugins) (source: wiki/sources/descriptions/ViRb3__swift-ida.md); browser WASM DIE (Detect It Easy) via [[die-engine-web]] (PE/ELF/Mach-O format / packer / compiler ID) (source: wiki/sources/descriptions/t0asts__DIE-engine-web.md); static packer/protector fingerprinter [[packpeek]] (C CLI; UPX/ASPack/Themida/VMProtect markers + Shannon entropy; PE/ELF/Mach-O/firmware; JSON + YARA/SARIF; cognis-digital) (source: wiki/sources/descriptions/cognis-digital__packpeek.md); WebAssembly memory analysis via [[wasm-ceserver]] (Python/JavaScript; Cheat Engine ceserver-style remote debug; Analyzing WebAssembly lane) (source: wiki/sources/descriptions/gmh5225__wasm-ceserver.md); browser-native WASM memory tooling via [[webcheat]] (Chrome MV3 extension; CE-style scan/narrow/freeze + virtual clock; Unity/Godot/Emscripten WebGL) (source: wiki/sources/descriptions/hasaneyldrm__webcheat.md); file-suspicion analysis framework [[pandora]] (convenient results UI; Anti Cheat → Analysis Framework; Ubuntu 24.04 recommended) (source: wiki/sources/descriptions/pandora-analysis__pandora.md); Android APK/DEX packer·obfuscator·anti-analysis ID via [[apkid]] (YARA; “PEiD for Android”; ProGuard/DexGuard/Bangcle+) (source: wiki/sources/descriptions/rednaga__APKiD.md); dumped-PE header repair for decompiler load via [[unmapper]] (Anti Cheat → Dump Fix) (source: wiki/sources/descriptions/t3ssellate__unmapper.md); UWP runtime package dump/inject tooling such as [[uwp-dumper]] (Wunkolo; C++ DLL + injector; Windows 10 SDK; inject into UWP process to extract package data gated by the UWP file-system model; Microsoft Store / protected game-build RE; Cheat / Explore UWP) complements dump-fix workflows for sandboxed Windows apps. (source: wiki/sources/descriptions/Wunkolo__UWPDumper.md); UWP WinRT interface hook/spy tooling such as [[uwpspy]] (Francesco149; C++ DLL; hooks selected UWP/WinRT interfaces; console runtime logging; hook scaffolding for UWP behavior instrumentation; Cheat / Explore UWP) complements dump workflows for sandboxed Windows apps. (source: wiki/sources/descriptions/Francesco149__uwpspy.md); UWP early-startup CLI injectors such as [[uwpinject]] (Francesco149; C; Win32 + AppModel APIs; suspended debugger-like launch injects DLLs at very early startup; DLL drop-in workflow; UWP RE, runtime instrumentation, and debugging; Cheat / Explore UWP) supply the launch/inject stage for [[uwpspy]] hook payloads and [[uwp-dumper]] package extraction. (source: wiki/sources/descriptions/Francesco149__uwpinject.md); Arxan PE protector dump/decrypt research via [[fix-arxan]] (loader info + decrypted working image; Dump Fix) (source: wiki/sources/descriptions/pr701__fix-arxan.md); Windows PDB parse/merge via [[pdb]] (C++ DIA SDK; old formats + `pdb.cfg`; symbol RE / debugger tooling) (source: wiki/sources/descriptions/sonyps5201314__pdb.md); visual PDB symbol/property inspection via [[diasymbolview]] (Delphi GUI; MSDIA; navigable symbol hierarchy with 200+ property enumeration and register-name resolution) (source: wiki/sources/descriptions/diversenok__DiaSymbolView.md); standalone PDB symbol extraction via [[pdbr]] (Python + Rich; parses PDB streams for functions, types, globals, and source refs; no Visual Studio or DIA SDK) (source: wiki/sources/descriptions/cansarigol__pdbr.md); UE5 engine PDB symbol mirrors such as [[unreal-engine-5-pdb]] (gmh5225; function/type/struct layouts for IDA Pro / x64dbg; UE5 game binary RE) (source: wiki/sources/descriptions/gmh5225__Unreal-Engine-5-PDB.md); Unity symbol-server PDB download in IDA via [[ida-unity-pdb-downloader]] (SamuelTulach; C++ IDA plugin; automates matching debug-symbol retrieval for Unity-related binaries during interactive RE) (source: wiki/sources/descriptions/SamuelTulach__ida-unity-pdb-downloader.md); synthetic PDB generation from IDA analysis via [[fakepdb]] (gmh5225; fake Program Database files for stripped executables; source-level debugging + symbol resolution in PDB-consuming tools; PDB Generation From IDA) (source: wiki/sources/descriptions/gmh5225__FakePDB.md); in-driver PDB parsing via [[kpdb]] (GetRektBoy724 pure C with symbol+type streams; rbmm C++; runtime parse avoids brittle offsets/sig scans; Some Tricks / Windows Ring0) (source: wiki/sources/descriptions/GetRektBoy724__KPDB.md) (source: wiki/sources/descriptions/rbmm__KPDB.md); PDB download manifest generation via [[pdblister]] (Rust CLI; directory PE scan → CodeView GUID/age → Symbol Server URLs; faster symchk /om; blocking + async batch) (source: wiki/sources/descriptions/microsoft__pdblister.md); pre-downloaded Microsoft kernel PDB bundles via [[mssymbolscollection]] (gmh5225; ntoskrnl, CI.dll, other kernel-mode binaries; Kernel Symbols offline cache) (source: wiki/sources/descriptions/gmh5225__MSSymbolsCollection.md); native Rust PDB read/write via [[pdb-rs]] (MSF container, CodeView symbol/type records, DBI/TPI/IPI streams, COFF metadata; x86/AMD64/ARM64 register maps) (source: wiki/sources/descriptions/microsoft__pdb-rs.md); ELF/DWARF debug-info browsing via [[dwex]] (DWARF Explorer; pyelftools GUI tree of CUs/types/functions/line maps) (source: wiki/sources/descriptions/sevaa__dwex.md); debug-info stripping via [[debug-remover]] (C/C++; remove debug sections/symbols before ship; Binary Packer / anti-RE hardening) (source: wiki/sources/descriptions/iArtorias__debug_remover.md); ntoskrnl offset/gadget/symbol resolution via [[ntoskrnlwalker]] (kernel structure navigation for target builds; cheat / RE tools) (source: wiki/sources/descriptions/jsacco__ntoskrnlwalker.md); live ntoskrnl memory viewer via [[ntoskrnl-viewer]] (IcEy-999; custom driver + UM client; WinDbg-like dump/examine commands by symbol or address; exported/unexported kernel symbols; x64 kernel RE / troubleshooting) (source: wiki/sources/descriptions/IcEy-999__Ntoskrnl_Viewer.md); live Object Manager inspection via [[object-explorer]] (driver-backed namespace/handle/type browse; PDB/DIA in-memory kernel structure decode; security descriptors + access masks; zodiacon) (source: wiki/sources/descriptions/zodiacon__ObjectExplorer.md); PHNT/SDK struct layout introspection via [[bb]] (Benowin Blanc; libclang parse of Windows SDK + PHNT; `dt`-like layouts/enums/constants without WinDbg; CLI+TUI+JSON; cheat / windows kernel explorer) (source: wiki/sources/descriptions/cristeigabriela__bb.md); web explorer for [[bb]] output via [[bb-viewer]] (SDK/PHNT functions, typedefs, constants, type graphs; IRQL annotations; multi-arch dataset switch; cristeigabriela) (source: wiki/sources/descriptions/cristeigabriela__bb-viewer.md); embeddable resolver library [[ntkernelwalkerlib]] (dbghelp + ntoskrnl executable-section gadget scan; same author) (source: wiki/sources/descriptions/jsacco__NTKernelWalkerLib.md); kernel-level modding/research utilities such as [[r0ak]] (C/C++; Some Tricks / Windows Ring3; gmh5225) complement symbol-walking and debugger tooling for low-level Windows, Linux, and mobile kernel RE. (source: wiki/sources/descriptions/gmh5225__r0ak.md); cross-format general-purpose ROP gadget finder via [[ropgadget-rs]] (Rust; parallel PE/ELF/Mach-O scan; ret-terminated insn chains for exploit-chain RE) (source: wiki/sources/descriptions/hugsy__ropgadget-rs.md); x86 ROP gadget finder + ROP chainer via [[agafi]] (HelpSystems Advanced Gadget Finder; programs/modules/running processes; Cheat / ROP Finder lane) (source: wiki/sources/descriptions/helpsystems__Agafi.md); Python automatic ROP chain generator via [[exrop]] (constraint-driven gadget chain synthesis from a binary; Cheat / ROP Generation) (source: wiki/sources/descriptions/d4em0n__exrop.md); angr-based automatic ROP gadget finder + chain builder via [[angrop]] (symbolic execution, constraint solving, graph search; CLI + API; architecture-agnostic; Cheat / ROP Generation) (source: wiki/sources/descriptions/angr__angrop.md); Windows NT syscall reference tables via [[syscall-tables]] (hfiref0x; pre-generated ntoskrnl/win32k/IUM SSN maps Vista→Win11 x64/ARM64; Zydis `ntdll`/`win32u` extraction + HTML/Markdown compose) alongside per-build extraction via [[ntsleuth]] (PDB + disasm → JSON/C headers) (source: wiki/sources/descriptions/hfiref0x__SyscallTables.md) (source: wiki/sources/descriptions/xaitax__NTSleuth.md); quick x86/x64 assemble-and-run via [[quickasm]] (Keystone) (source: wiki/sources/descriptions/zodiacon__QuickAsm.md); open-source shellcode compiler [[scc]] (Vector35; C/C++ CMake; compact shellcode-oriented output; internal CTF origin, integrated into Binary Ninja; exploit dev + controlled low-level codegen; cheat / shellcode compiler) (source: wiki/sources/descriptions/Vector35__scc.md); low-latency runtime x86-64 dynamic codegen via [[chasm]] (C library; instruction IR, relative reference linking, AVX-256; JIT/emulator/runtime optimization workloads) (source: wiki/sources/descriptions/aqilc__chasm.md); early-stage Java bytecode assemble/disassemble via [[raung]] (cheat / RE tools; syntax still unstable) (source: wiki/sources/descriptions/skylot__raung.md); lightweight Java/JVM attach debugger [[jdbg]] (JDWP; method hooks / breakpoints / class enum for Java game clients) (source: wiki/sources/descriptions/roger1337__JDBG.md); IDA xref-extension plugin [[xrefsext]] (source: wiki/sources/descriptions/zengfr__XrefsExt.md); missing xref materialization via [[find-xrefs]] (full-database RIP-relative/absolute pointer scan; materializes undefined bytes so IDA creates string/data xrefs; large game/AC binaries; TheCruZ; cheat / IDA Plugins) (source: wiki/sources/descriptions/TheCruZ__FindXrefs.md); indirect/complex control-flow xref generation via [[xrefgen]] (seifreed; Python; data-flow taint, call-graph, CFF/opaque-predicate detection; XRefer-compatible export; x86/x64/ARM/ARM64/MIPS/WASM; cheat / IDA Plugins) (source: wiki/sources/descriptions/seifreed__xrefgen.md); advanced xref navigation via [[xrefxpert]] (0xGotcha; Python/PyQt dockable viewer; real-time function xref list, click-to-jump, hotkeys; immediates/parameter-count/signature filters; game binary / vuln RE; cheat / IDA Plugins) (source: wiki/sources/descriptions/0xGotcha__XrefXpert.md); cursor RVA clipboard copy via [[copy-rva]] (RomanRybachek; Python IDAPython; context menu; WinDbg breakpoints on unsymbolized drivers; cheat / IDA Plugins) (source: wiki/sources/descriptions/RomanRybachek__Copy_RVA.md); mnemonic-pattern breakpoint automation via [[cbs]] (Reodus; Python IDAPython + PyQt; regex scan disasm lines; set/enable/disable/remove breakpoints across functions; cheat / IDA Plugins) (source: wiki/sources/descriptions/Reodus__CBS.md); register cross-references via [[ida-plugins]] (vs Oregami value-use filtering; cheat / IDA Plugins) (source: wiki/sources/descriptions/repnz__ida-plugins.md); live IDA ↔ x64dbg annotation/type sync via [[symbridge]] (module+RVA keyed; Python broker) (source: wiki/sources/descriptions/xp987__symbridge.md); automated structure/type recovery on stripped binaries via [[symless]] (data-flow + memory-access patterns; improves Hex-Rays output) (source: wiki/sources/descriptions/thalium__symless.md); remote browser review of a live IDB via [[idarem]] (Flask REST/SSE + React; live follow / optional rename-comment write-back) (source: wiki/sources/descriptions/xsslize__idarem.md); real-time multi-user IDA database sync via [[idarling]] (connect IDA Pro instances; collaborative RE; cheat / IDA Plugins) (source: wiki/sources/descriptions/matteyeux__IDArling.md); IDA database migration via [[ida-migrator]] (Python plugin; migrate IDB between IDA versions or environments; cheat / IDA Plugins) (source: wiki/sources/descriptions/giladreich__ida_migrator.md); cross-disassembler collaborative analysis sync via [[binsync]] (IDA Pro, Ghidra, Binary Ninja, angr; Git-backed push/pull of names, comments, types, structs; cheat / Sync) (source: wiki/sources/descriptions/gmh5225__binsync.md); offline CPU instruction docs at the cursor via [[idaref]] (Python; SQLite refs for x86-64/ARM/MIPS/Xtensa; cheat / IDA Plugins) (source: wiki/sources/descriptions/nologic__idaref.md); live register/stack debugger views via [[dereferencing]] (danigargu; Python IDAPython plugin; dereferenced pointer chains, color-coded memory annotations, PEDA/GEF/pwndbg-like UX; x86/ARM/MIPS; cheat / IDA Plugins) (source: wiki/sources/descriptions/danigargu__deREferencing.md); richer register/instruction documentation in disasm + decompiler via [[friend]] (C++; Capstone processor extensions; contextual hints, external doc links, function summaries; optional Hex-Rays; Windows/Linux/macOS; cheat / IDA Plugins) (source: wiki/sources/descriptions/alexhude__FRIEND.md); IDA Pro CLI/client for agents via [[idac]] (Unix socket to live GUI or headless idalib; structured JSON; batch/preview/dry-run; not MCP; early alpha) (source: wiki/sources/descriptions/trailofbits__idac.md); IDA ↔ VS Code IDAPython edit/run/debug bridge via [[idacode]] (early alpha; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__idacode.md); Cling/Clang 20 C++ REPL in IDA scripting via [[idacpp]] (allthingsida; native IDA SDK + Hex-Rays types; snippet editor + output REPL tab; Windows/macOS; cheat / IDA Plugins) (source: wiki/sources/descriptions/allthingsida__idacpp.md); IDA Pro + VMware GDB stub Windows kernel debugging via [[ida-vmware-windows-gdb]] (configuration/guide; IDA GDB debugger → VMware built-in stub; breakpoints, memory inspect, kernel stepping; cheat / guide) (source: wiki/sources/descriptions/gmh5225__ida_vmware_windows_gdb.md); VirtualKD-Redux VM kernel debug acceleration via [[virtualkd-redux]] (4d61726b; C/C++ driver + host-side components; VMware/VirtualBox; legacy Windows through Win11; current WinDbg; faster VM kernel debug for systems security research) (source: wiki/sources/descriptions/4d61726b__VirtualKD-Redux.md); IDA Pro + Bochs emulation debugging on Windows via [[ida-bochs-windows]] (configuration/guide; Bochs software CPU backend; full-system + kernel-mode stepping without live KD; cheat / guide) (source: wiki/sources/descriptions/gmh5225__ida_bochs_windows.md); IDA MCP server plugin [[ida-mcp-server-plugin]] (Python; exposes disasm/decompile/xrefs/functions/types to MCP clients) (source: wiki/sources/descriptions/taida957789__ida-mcp-server-plugin.md); full IDAPython MCP automation via [[ida-pro-mcp]] (installable plugin + docs + MCP test framework; rename/types/xrefs/decompile/structs for agents) (source: wiki/sources/descriptions/mrexodia__ida-pro-mcp.md); faster IDA MCP with multi-instance routing + optional live kernel memory via [[iida-mcp]] (77 tools; `iida-mcp-ioctl` driver) (source: wiki/sources/descriptions/saileaxh__iida-mcp.md); curated IDA MCP peer [[pcm]] (rand-tech; README MCP-for-IDA tag; description also claims Process Context Monitor) (source: wiki/sources/descriptions/rand-tech__pcm.md); in-IDA Claude-3 chat assistant via [[ida-assistant]] (interactive guidance for RE workflows; cheat / IDA Plugins) (source: wiki/sources/descriptions/stuxnet147__IDA-Assistant.md); AI-powered IDA 9.0+ assistant for C++ game RE via [[aida]] (cheat / IDA Plugins) (source: wiki/sources/descriptions/sigwl__AiDA.md); local llama.cpp IDA LLM Explainer via [[ida-llm-explainer]] (function explain/rename/struct inference; human-in-the-loop accept; CFG recovery; cheat / IDA Plugins) (source: wiki/sources/descriptions/pgarba__ida-llm-explainer.md); LLM pseudocode assistant via [[gepetto]] (JusticeRage; Python IDAPython; explain decompiled functions + variable rename + code comments; menu actions + hotkeys; cloud/local multi-provider config; malware/software/game-security RE; cheat / IDA Plugins / `[ChatGPT]`) (source: wiki/sources/descriptions/JusticeRage__Gepetto.md); local LLM fork via [[ida-gepetto]] (apkunpacker; explain/rename; offline backends + localization; cheat / IDA Plugins) (source: wiki/sources/descriptions/apkunpacker__IDA-Gepetto.md); AI-powered RE copilot via [[aether]] (CSIT-SG; Python IDAPython; AI-assisted decompilation, interactive chatbot with tool-calling, function annotation, vulnerability analysis, RAG context from binary databases; multi-provider LLM backends, prompt templates, syntax highlighting, custom viewer UI; malware/RE workflows; cheat / IDA Plugins) (source: wiki/sources/descriptions/CSIT-SG__AETHER.md); official radare2 GUI [[iaito]] (Qt5/6; RE workflow / editor tooling / plugins; Cheat → Radare) (source: wiki/sources/descriptions/radareorg__iaito.md); LLM-based reversing assistant for radare2 via [[r2ai]] (interactive LLM↔r2 sessions; Cheat → Radare Plugins) (source: wiki/sources/descriptions/radareorg__r2ai.md); retired local-LLM radare2 pointer [[r2a]] (repo gone; use [[r2ai]]) (source: wiki/sources/descriptions/radareorg__r2a.md); Lua IDA SDK scripting via [[luda]] (direct SDK access from Lua; rapid RE automation; cheat / IDA Plugins) (source: wiki/sources/descriptions/stolevchristian__LUDA.md); third-party Lumina server connectivity via [[openlumina]] (IDA plugin + Hex-Rays `.crt`; cheat / IDA Plugins) (source: wiki/sources/descriptions/tomrus88__OpenLumina.md); IDAPython convenience layer via [[sark]] (“IDAPython Made Easy”; IDA-6.x branch for older IDA) (source: wiki/sources/descriptions/tmr232__Sark.md); IDAPython namespace replacement via [[ida-minsc]] (arizvisa; DWIM interface; tagging/filtering; database/function automation; cheat / IDA Plugins) (source: wiki/sources/descriptions/arizvisa__ida-minsc.md); IDA productivity shortcuts via [[lazyida]] (auto-relocation jump during debug, memory dump to file, ASCII/HEX/BASE64 paste-to-memory, RVA copy, jump-to-address without rebasing IDB; gmh5225; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__LazyIDA.md); Windows x64 call-stack reconstruction in IDA via [[better-call-stack]] (AntonKukoba1; C++ IDA debugger plugin; DbgHelp + StackWalk64 for more reliable frames than default debugger view; auto-loads during debug sessions; protected/complex binary RE; cheat / Improve call stack) (source: wiki/sources/descriptions/AntonKukoba1__BetterCallStack.md); centralized IDAPython plugin settings via [[ida-settings]] (williballenthin; Python + Qt; typed plugin config via Hex-Rays HCLI/ida-config.json; dockable Plugin Settings Manager GUI; legacy scoped IDASettings module; IDA Pro 9.0+; game binary / anti-cheat RE workflows; cheat / RE Tools) (source: wiki/sources/descriptions/williballenthin__ida-settings.md); WakaTime time tracking in IDA via [[ida-wakatime-py]] (Python; background heartbeats to WakaTime API; tracks analyzed binaries and session duration; es3n1n) (source: wiki/sources/descriptions/es3n1n__ida-wakatime-py.md); parallel IDA worker offload via [[ida-taskr]] (Python; Qt + multiprocessing; keeps UI responsive during heavy IDAPython; cheat / IDA Plugins) (source: wiki/sources/descriptions/mahmoudimus__ida-taskr.md); Rust symbol demangle/normalize in IDA via [[ida-rust-demangler]] (depends on `rs-dml`; cheat / IDA Plugins) (source: wiki/sources/descriptions/timetravelthree__IDARustDemangler.md); Rust Cargo dependency display in IDA via [[ida-rust-cargo]] (Python plugin; cheat / IDA Plugins) (source: wiki/sources/descriptions/kkent030315__IDARustCargo.md); cross-platform Itanium/MSVC (+ D/Rust/Swift) symbol demangling via [[demumble]] (`c++filt` / `undname.exe` replacement; cheat / RE tools) (source: wiki/sources/descriptions/nico__demumble.md); MSVC/C++ RTTI parse in IDA 9.2 via [[rtti-parser]] (IDA script; cheat / IDA Plugins) (source: wiki/sources/descriptions/rem0obb__rtti-parser.md); C++ RTTI class hierarchy + auto-rename via [[pyclassinformer]] (IDA Pro plugin; hierarchy viz, library/method classification, member coloring; cheat / IDA Plugins) (source: wiki/sources/descriptions/herosi__PyClassInformer.md); GCC RTTI class hierarchy + vtable reconstruction via [[ida-medigate]] (Python; Hex-Rays union disambiguation; xref tracker; stripped polymorphic C++/firmware; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__ida_medigate.md); IDA 9.X vtable ops via [[ida-vtable-tools]] (dump `.hpp` interface skeleton / class-prefix rename / `this` type / slot index·offset; Python; cheat / IDA Plugins) (source: wiki/sources/descriptions/oxiKKK__ida-vtable-tools.md); automated GCC/MSVC vtable detection, RTTI inheritance analysis, override comparison, and hierarchy visualization via [[ida-vtable-explorer]] (K4ryuu; C++ IDA Pro 9.x plugin; virtual-function index/offset annotation; cheat / IDA Plugins) (source: wiki/sources/descriptions/K4ryuu__IDA-VTableExplorer.md); C++ class/vtable/signature management via [[classy]] (gmh5225; PyQt5 GUI; vtable generation from ranges, function-to-class assignment, Itanium name mangling, IDA struct mapping, C header export; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__Classy.md); constructor-pseudocode C++ class reconstruction via [[classmaker]] (Pycatchown; Python IDAPython; traces vtable assignments from ctor pseudocode, creates/updates IDA structs, naming heuristics; 32/64-bit practical reversing; cheat / IDA Plugins) (source: wiki/sources/descriptions/Pycatchown__ClassMaker.md); missing indirect CALL/JMP target recovery via [[ida-missinglink]] (C++ OOP-heavy binaries; cheat / IDA Plugins) (source: wiki/sources/descriptions/kweatherman__ida_missinglink.md); Rust-accelerated angr fork / Rust decompiler [[oxidizer]] (symbolic exec / CFG / data-flow; high-fidelity pseudocode from stripped binaries; enum/match/`?` recovery; Rust 1.39–1.93) (source: wiki/sources/descriptions/sefcom__oxidizer.md); automated binary-analysis + ML platform [[re-architect]] (understand binaries / extract meaningful info; cheat / RE tools) (source: wiki/sources/descriptions/pandaadir05__re-architect.md); Python binary-patch script generation via [[genpatch]] (dialog on success; cheat / IDA Plugins) (source: wiki/sources/descriptions/sterrasec__genpatch.md); IDA PatchGen patched-byte export via [[ida-genpatch]] (Alt-F8; grouped bytes, disassembly, C# `SinglePatchHunk`; cheat / IDA Plugins) (source: wiki/sources/descriptions/frasten__ida-genpatch.md); IDA database → linkable COFF/ELF object export via [[ida2obj]] (relocations, symbols, section content; binary patching / recompilation; gmh5225; cheat / COFF Relink) (source: wiki/sources/descriptions/gmh5225__IDA2Obj.md); COFF object deep parse in Ghidra via [[ghidra-coffparser]] (MEhrn00; Python Ghidra analysis script; headers/symbols/string tables/relocations with type info; applies relocations and xrefs beyond default loader; COFF object RE; cheat / COFF) (source: wiki/sources/descriptions/MEhrn00__Ghidra_COFFParser.md); targeted C struct import via [[ghidra-struct-importer]] (Katharsas; Java GhidraScript; per-struct import with dependency resolution beyond Parse C Source; SDK-leak/decompiled-header layout reconstruction; cheat / Struct Importer) (source: wiki/sources/descriptions/Katharsas__ghidra-struct-importer.md); Hex-Rays microcode IR display via [[genmc]] (IDAPython; debug microcode plugin / decompiler-extension work) (source: wiki/sources/descriptions/patois__genmc.md); Hex-Rays P-Code display for the current function via [[idapcode]] (Python IDA plugin; cheat / IDA Plugins) (source: wiki/sources/descriptions/binarly-io__idapcode.md); Intel AVX→Hex-Rays microcode lifting via [[microavx]] (IDA Pro plugin; `m_ext` visitor replaces opaque ext nodes; AVX coverage-gap scraper; cheat / IDA Plugins) (source: wiki/sources/descriptions/gaasedelen__microavx.md); Hex-Rays decompiler convenience utilities via [[happyida]] (IDAPython; Swift-style parameter labels, clipboard name/type helpers, SEH try/catch reconstruction, vtable navigation, Rust string prettification; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__HappyIDA.md); PE SEH chain inspection via [[seh-helper]] (Binary Ninja; Python; list entries, inspect cursor handler, follow cursor context; EliseZeroTwo; Windows PE exception metadata during static analysis) (source: wiki/sources/descriptions/EliseZeroTwo__SEH-Helper.md); multi-architecture shellcode assemble/disassemble and hex/Python/C array format conversion via [[shellcoder]] (Binary Ninja; Python; rapid payload iteration; 0xricksanchez; exploit prototyping / shellcode RE) (source: wiki/sources/descriptions/0xricksanchez__Shellcoder.md); Hex-Rays WPP trace-call cleanup via [[ida-wpp-remover]] (L4ys; Python; microcode pass strips `WPP_SF*` noise from Windows PE pseudocode; toggle from decompiled view; malware/game binary RE; cheat / IDA Plugins) (source: wiki/sources/descriptions/L4ys__IDA-WPP-Remover.md); curated essential IDA plugin pack [[idaplugins]] (deobfuscation / binary diffing / custom crypto; cheat / IDA Plugins) (source: wiki/sources/descriptions/ssmugabi__IDAPlugins.md); Willi Ballenthin IDA Pro script/plugin/util collection via [[idawilli]] (Python IDAPython; function analysis, string decryption, struct annotation, xref navigation, workflow automation; malware/firmware; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__idawilli.md); multi-version IDA Pro SDK archive via [[idasdk-collection]] (headers, libs, examples; backward-compatible plugin dev; cheat / IDA SDK) (source: wiki/sources/descriptions/gmh5225__idasdk-collection.md); mirrored IDA Pro SDK headers/libs/docs via [[ida-sdk]] (C++ plugin + processor-module dev across IDA releases; cheat / IDA SDK) (source: wiki/sources/descriptions/gmh5225__ida-sdk.md); community-maintained IDA plugin catalog via [[idaplugins-list]] (version-aware discovery; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__idaplugins-list.md); categorized IDA plugin index via [[list-of-ida-plugins]] (language / last-updated metadata / category tags; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__ida-plugins.md); Hex-Rays/pseudocode function-definition colorizing via [[ida-functioncolor]] (Python; cheat / IDA Plugins) (source: wiki/sources/descriptions/sneakyevil__ida_functioncolor.md); function outline / call-hierarchy trees via [[ida-func-outline]] (callers/callees + depth; iOS ARM64 decomp readability; cheat / IDA Plugins) (source: wiki/sources/descriptions/richor1042__IDAFuncOutline.md); compiler function-outlining reversal via [[function-inliner]] (Cellebrite Labs IDA Pro plugin; clone outlined helpers per caller, redirect BL/RET, restore Hex-Rays on clang `--moutline` ARM binaries; manual + batch; cheat / IDA Plugins) (source: wiki/sources/descriptions/cellebrite-labs__FunctionInliner.md); function clustering and organization for large binaries via [[idaclu]] (Qt GUI; i18n; group similar functions by criteria; visual navigation; cheat / IDA Plugins) (source: wiki/sources/descriptions/harlamism__IdaClu.md); workflow-centric function triage and prioritization via [[ida-spotlight]] (prioritize analysis targets in large binaries; malware and protected-game RE; cheat / IDA Plugins) (source: wiki/sources/descriptions/dyussekeyev__ida-spotlight.md); in-IDA Yara file scanning via [[yarascan-ida]] (Python; cheat / IDA Plugins) (source: wiki/sources/descriptions/senko37__yarascan-ida.md); decompiled-pseudocode SAST vulnerability scanning via [[ida-security-scanner]] (Python; opengrep/semgrep-style YAML rules; interactive findings UI; optional AI triage; SymbioticSec; cheat / IDA Plugins) (source: wiki/sources/descriptions/SymbioticSec__ida-security-scanner.md); insecure-API call-site triage via [[rhabdomancer]] (0xdea; Rust idalib headless IDA plugin; locates strcpy/sprintf/system/ioctl and similar dangerous calls; tiered badness, bookmarks, backtrace audit paths; candidate vulnerability points for manual review; cheat / IDA Plugins) (source: wiki/sources/descriptions/0xdea__rhabdomancer.md); string→pseudocode static triage via [[augur]] (0xdea; Rust idalib headless IDA plugin; extracts strings and related Hex-Rays pseudocode; per-string directories map to decompiled referencing functions; fast static analysis pipelines; cheat / IDA Plugins) (source: wiki/sources/descriptions/0xdea__augur.md); zero-dependency JavaScript bundle SAST via [[omega-sast]] (Black0ffR; Node.js OMEGA-5.0; hand-rolled AST + inter-procedural taint; obfuscator fingerprinting + string-array/CFF/JSFuck deobfuscation; XSS/injection/credential-leak findings; HTML/JSON/Markdown/SARIF + LLM taint contracts; game-client + AC web-asset RE) (source: wiki/sources/descriptions/Black0ffR__omega-sast.md); independent Motorola M·CORE decompiler via [[mcore-decompiler]] (Siesta; C++17 IDA Pro 9.4 plugin; custom IR from MCORE disasm through optimization, control-flow structuring, stack-frame recovery, and call-arg analysis to F5-bound C pseudocode without Hex-Rays M·CORE backend; embedded firmware and feature-phone binaries such as Motorola E1000; cheat / IDA Plugins) (source: wiki/sources/descriptions/Siesta__MCORE-Decompiler.md); LLVM IR–based static analysis via [[static-analyzer-factory]] (Rust; C/C++ pointer/value-flow/taint/IFDS; abstract interpretation, points-to, call graphs; Python SDK, CLI, SARIF/HTML export; compiled-binary vulnerability detection) (source: wiki/sources/descriptions/Static-Analyzer-Factory__static-analyzer-factory.md); unofficial YARA IDA Pro plugin via [[yara4ida]] (default **Alt-Y**; rebind in `plugins.cfg`; cheat / IDA Plugins) (source: wiki/sources/descriptions/kweatherman__yara4ida.md); in-IDA YARA rule scanning with match highlighting via [[findyara-ida]] (gmh5225; custom rules against loaded binary; disasm navigation to hits; malware/crypto/packer sigs; cheat / Yara) (source: wiki/sources/descriptions/gmh5225__findyara-ida.md); FindCrypt crypto-constant identification via [[findcrypt-yara]] (Python IDA plugin; YARA rules for AES S-boxes, DES/SHA/CRC tables; annotate algorithm names at matched sites; cheat / Yara) (source: wiki/sources/descriptions/gmh5225__findcrypt-yara.md); Ghidra-native FindCrypt analyzer via [[ghidra-findcrypt]] (Java Gradle Ghidra extension; JSON signature DB for AES S-boxes, DES, MD5, SHA-1, TEA, Salsa, CRC32; labels crypto routines during analysis; TorgoTorgo; cheat / Ghidra Plugins) (source: wiki/sources/descriptions/TorgoTorgo__ghidra-findcrypt.md); dockable in-Ghidra hex editor via [[ghidra-hexeditor]] (sengi12; Java Ghidra script plugin; Swing UI; in-place byte edit, binary search, BinaryExporter save; cheat / Ghidra Plugins) (source: wiki/sources/descriptions/sengi12__ghidra-hexEditor.md) and [[scalpel]] (ntdlll; Java 21 Ghidra extension; dark-mode hex/ASCII grid synced to Listing; wildcard hex/UTF-8 search; inline transaction patching; cheat / Ghidra Plugins) (source: wiki/sources/descriptions/ntdlll__Scalpel.md) (source: wiki/sources/descriptions/ntdlll__Scalpel.md); function pattern search via [[findfunc]] (gmh5225; filter functions by byte patterns, instruction sequences, operand types, and xrefs; Recognizing Function By Pattern; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__FindFunc.md); common Anti-Cheat artifact detection in IDA via [[kiroshi]] (RE/academic; cheat / IDA Plugins) (source: wiki/sources/descriptions/not1cyyy__Kiroshi.md); Tencent ACE Free Fire native-library RE automation via [[ff-ace-anticheat-analysis]] (Lixense; Python/JS parallel IDA workflows, string decryption, detection catalog + SQLite index for `libanogs`/`libanort`; Explore AntiCheat System:ACE) (source: wiki/sources/descriptions/Lixense__ff-ace-anticheat-analysis.md); OTCv8 Windows client AC telemetry audit via [[pokealliance-anti-cheat-analysis]] (LordeTyrael; PE static RE of `PokeAlliance_dx.exe` + Frida/Python dynamic tracer logging fingerprint collection and server-triggered enumeration; MMORPG server-side bot-detection design study) (source: wiki/sources/descriptions/LordeTyrael__PokeAllianceAntiCheatAnalysis.md); in-memory patch/hook discovery via [[patch-finder]] (executable segments vs on-disk PE byte-compare; custom PE parser VA↔file-offset alignment; highlight diffs in disasm; cheat / IDA Plugins) (source: wiki/sources/descriptions/momo5502__patch-finder.md); header-only memory-integrity experiment headers such as [[integrity-experiments]] (gmh5225; AC `Detection:Memory Integrity`) for defensive check prototyping (source: wiki/sources/descriptions/gmh5225__integrity_experiments.md); header-only PE section checksum library [[integrity]] (afulsamet; non-writable section baseline hashes + periodic re-check; SSE4.2 CRC32; compile-time algorithm config; tamper / AC hardening) for runtime self-protection study (source: wiki/sources/descriptions/afulsamet__integrity.md); fast IDA signature scan/create via [[ida-fusion]] (unique sigs vs duplicated binary parts; cheat / IDA Plugins) (source: wiki/sources/descriptions/senator715__IDA-Fusion.md); zero-dependency IDA Pro 9+ cross-platform signature maker via [[ida-sigmaker]] (shortest unique sigs; wildcard address operands; XREF fallback; batch search; optional SIMD; cheat / IDA Plugins) (source: wiki/sources/descriptions/mahmoudimus__ida-sigmaker.md); alternate gmh5225 [[ida-sigmaker]] fork auto-generates IDA/code-style patterns with wildcard bytes and binary-unique verification (source: wiki/sources/descriptions/gmh5225__ida-sigmaker.md); enhanced IDA Pro signature maker via [[sigmakerex]] (code/IDA/x64dbg pattern formats; automatic uniqueness verification; batch generation; clipboard integration; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__sigmakerex.md); gmh5225 [[ida-pro-sigmaker]] (Signature Maker; wildcard-masked byte patterns from selected code for runtime scan; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__IDA-Pro-SigMaker.md); Binary Ninja → IDA FLIRT `.pat` export via [[bndb2pat]] (Python; LLIL byte masks with wildcard operands, CRC16, named symbols; sigmake → `.sig` libraries; inspired by idb2pat/hrtng; cheat / Binary Ninja Plugins) (source: wiki/sources/descriptions/joren485__bndb2pat.md); Binary Ninja byte-pattern signature maker via [[binja-sigmaker]] (Python; IDA-style wildcard sigs from disassembled functions; function-start fallback; plugin-manager compatible; cheat / Binary Ninja Plugins) (source: wiki/sources/descriptions/apekros__binja_sigmaker.md); Ghidra in-binary SPF-style signature generate/search via [[spf-ghidra-pattern-helper]] (Java GhidraScript; Pattern Generator/Finder GUI; wildcards/ranges/alternation/displacement masking; SPF-Framework PatternFinder output; optional uniqueness verify; ATS/ETS2 plugin RE; TrackAndTruckDevs; cheat / Ghidra Plugins) (source: wiki/sources/descriptions/TrackAndTruckDevs__SPF_GhidraPatternHelper.md); standalone x86 wildcard signature workshop via [[signature-forge]] (Elinam03; Python FastAPI + React/Electron; x64dbg/Cheat Engine/raw hex input; smart anchor scoring; multi-format export; cheat / RE Tools) (source: wiki/sources/descriptions/Elinam03__Signature-Forge.md); high-performance Aho-Corasick multi-pattern string matching via [[aho-corasick]] (ISM state-transition matrix; mmap-serializable automata; C API build/query/dump; signature/YARA-style scan backends) (source: wiki/sources/descriptions/mischasan__aho-corasick.md); AV signature recovery for anti-signature-scanning research via [[avdebugger]] (Cheat → Anti Signature Scanning) (source: wiki/sources/descriptions/scrt__avdebugger.md); Big5 byte decode in IDA via [[big5-decode-ida]] (Python; cheat / IDA Plugins) (source: wiki/sources/descriptions/sean2077__big5-decode-ida.md); CyberChef-style encode/decode pipelines in IDA via [[ida-cyberchef]] (HexRaysSA; Python + Qt; malware analysis / binary triage; cheat / IDA Plugins) (source: wiki/sources/descriptions/HexRaysSA__ida-cyberchef.md); Hex-Rays enum rename/add workflow via [[ida-enums-helper]] (hotkey **N**/**A**/**Shift-A**; `tinfo_t` ordinal match + chooser dialogs; cheat / IDA Plugins) (source: wiki/sources/descriptions/milankovo__ida_enums_helper.md); automatic standard-function enum identification via [[auto-enum]] (Python/C; identifies and applies enums for common API/stdlib calls; cheat / IDA Plugins) (source: wiki/sources/descriptions/junron__auto-enum.md); type-aware binary search via [[ida-search]] (IDA Pro 9.x; 010 Editor–style typed search; `ida-plugin.json` auto-load; cheat / IDA Plugins) (source: wiki/sources/descriptions/milankovo__ida-search.md); compiled YARA rule bytecode disassembly via [[yaravm]] (IDA processor + loader for `.yar.bin`; arena format / regex bytecode / `libyara.til`; cheat / IDA Plugins) (source: wiki/sources/descriptions/milankovo__YaraVM.md); multi-platform YARA rule generation via [[hyara]] (Python; IDA Pro, Ghidra, Binary Ninja, Cutter; create/check/detect signatures from binary patterns; cheat / Yara) (source: wiki/sources/descriptions/hyuunnn__Hyara.md); linker `.MAP` symbol import via [[ida-pro-loadmap]] (VC/Borland/Dede/GCC/IDA MAP formats; section:offset → named functions/labels; kernwin/segment APIs; cheat / IDA Plugins) (source: wiki/sources/descriptions/mefistotelis__ida-pro-loadmap.md); gmh5225 [[ida-map-symbol-parser]] (IDA Map File Symbol Renamer; parse linker MAP files; apply function/global/segment names to stripped IDB; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__IDA-MapSymbolParser.md); runtime `.MAP` symbol import in [[x64dbg]] via [[x64dbg-mapldr]] (C++ plugin; MSVC/Borland/linker or IDA-exported MAP → function/global/segment names in the debugger symbol DB; Cheat x64dbg Plugins) (source: wiki/sources/descriptions/gmh5225__X64DBG-MapLdr.md), DWARF debug symbol import via [[dwarfhelper]] (CynicRus; libdwarf; ELF/PE function names, variable types, file:line comments; x86/x64; Cheat x64dbg Plugins) (source: wiki/sources/descriptions/CynicRus__DWARFHelper.md); high-resolution graph/disassembly screenshot capture via [[ida-screenshot]] (Python plugin; `make install` on macOS/Linux or manual `screenshot.py`; cheat / IDA Plugins) (source: wiki/sources/descriptions/jonpalmisc__ida_screenshot.md); dark syntax-highlight color theme via [[long-night]] (IDA Pro; cheat / IDA themes) (source: wiki/sources/descriptions/gmh5225__long_night.md); Nord-palette dark theme via [[ida-nord-theme]] (disassembly/hex/graph/editor; cheat / Skins) (source: wiki/sources/descriptions/gmh5225__ida-nord-theme.md); modern Dark+ theme via [[ida-dark-plus]] (disassembly/hex/structures/all IDA windows; syntax-highlighted dark palette; cheat / IDA themes) (source: wiki/sources/descriptions/gmh5225__ida-dark-plus.md); dark theme [[dp701]] (custom syntax/UI palette for disassembly readability; cheat / IDA themes) (source: wiki/sources/descriptions/gmh5225__dp701.md); VS Code→IDA theme converter [[ida-themer]] (Long Night/Celestial base; remaps VS Code theme JSON; cheat / IDA themes) (source: wiki/sources/descriptions/gmh5225__IdaThemer.md); custom Qt skin/theme plugin [[idaskins]] (CSS-like styling for disassembly/hex/output windows; cheat / Skins) (source: wiki/sources/descriptions/gmh5225__IDASkins.md); Cheat Engine value tracing in IDA via [[ce-tracer-ida]] (Python plugin; memory analysis; cheat / IDA Plugins) (source: wiki/sources/descriptions/goseungduk__CE_Tracer-IDA.md); IDA Pro + Cheat Engine current-module offset sync via [[doffset]] (dNop90; module RVAs for multi-tool static+dynamic RE with IDA, Cheat Engine, x64dbg; cheat / IDA Plugins) (source: wiki/sources/descriptions/dNop90__dOffset.md); Cheat Engine disassembler page remapping via [[ce-remap-plugin]] (Delphi CE plugin; hooks CE plugin SDK to remap disassembler memory pages for hidden/obfuscated code visibility; tested on CE 7.4; cheat / Remap; gmh5225) (source: wiki/sources/descriptions/gmh5225__CE-remap-plugin.md); Delphi x86/x86_64 binary analysis via [[delphi-helper]] (eset; cheat / IDA Plugins; setup requires py7zr) (source: wiki/sources/descriptions/eset__DelphiHelper.md); IDA-side Delphi function-name recovery via [[ida-for-delphi]] (Coldzer0; IDAPython; event constructor patterns; live-debug session; 64-bit; malware/legacy Delphi RE) (source: wiki/sources/descriptions/Coldzer0__IDA-For-Delphi.md); Delphi symbol recovery for Ghidra via [[delphiresym]] (WenzWenzWenz; pyghidra Python script; qualified function signatures, parameter metadata, vtable context from embedded compiler metadata → Ghidra data types; modern Delphi; malware/legacy RE) (source: wiki/sources/descriptions/WenzWenzWenz__DelphiReSym.md); Frida↔IDA static+dynamic bridge via [[frinet]] (IDA Pro plugin; run Frida scripts on live target while syncing memory values, function args, and return values into IDA navigation; cheat / Frida-based tracer) (source: wiki/sources/descriptions/gmh5225__frinet.md); lightweight in-IDA whiteboard sketching via [[draw-ida]] (MIT; brainstorm/annotate directly in IDA UI; cheat / IDA Plugins) (source: wiki/sources/descriptions/idkhidden__DrawIDA.md); live Marp/Slidev RE presentation decks docked in IDA via [[ida-slides]] (IDA 9.2+ Python; `@name`/`@0xADDR` bidirectional jump to disasm/pseudocode; embed live decompiled lines; unresolved-ref lint; WKWebView/WebView2; cheat / IDA Plugins) (source: wiki/sources/descriptions/hyuunnn__ida-slides.md); instruction-signature library function renaming via [[renamaida]] (Python IDA plugin; Jaro-Winkler match on arch-specific insn tokens; JSON sig DB from debug builds; ≥0.83 / ≥10 insns; sample strongSwan ARMv5TE; firmware/static-link RE) (source: wiki/sources/descriptions/kirovgrad__Renamaida.md); cloud function symbol recognition via [[finger]] (aliyunav; Python SDK + IDA 7+ plugin; extract function features → cloud recognition backend → rename/highlight matches; Python 2.7/3; malware/game binary triage; Recognizing Function By Cloud) (source: wiki/sources/descriptions/aliyunav__Finger.md); batch function/symbol name management via [[ida-names]] (Python; batch rename, pattern match, prefix/suffix, import/export; renames pseudocode window titles; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__ida_names.md); IDA function-list Markdown export via [[ida-export-functions]] (Python; dump DB function index to a specified path for notes/reporting; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__ida_export_functions.md); structured data/disassembly export via [[ida-data-export-plus]] (Krietz7; Python; extends/replaces default data export window; integer/float formats + assembly text; hotkey-driven; modern IDA; repetitive extraction; cheat / IDA Plugins) (source: wiki/sources/descriptions/Krietz7__IDA-DataExportPlus.md); function–string association and auto-comments from literals via [[ida-function-string-associate]] (IDA 9.X; scan function bodies for string refs; navigable summary; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__ida-function-string-associate.md); user comment capture and organization via [[idacomments]] (NoneShell; Python IDA 7.x/8.x plugin; hooks comment actions; dedicated review view; keyboard/menu access; note management for game clients and AC modules; cheat / IDA Plugins) (source: wiki/sources/descriptions/NoneShell__IDAComments.md); `.data`-section pointer lookup via [[ida-find-.data-ptr]] (Python; locate/xref global `.data` pointers; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__ida-find-.data-ptr.md); Hex-Rays pseudocode Ctrl+F search via [[idafind]] (IDA Pro plugin; find-in-text for Pseudocode windows; cheat / IDA Plugins) (source: wiki/sources/descriptions/cristeigabriela__IDAFind.md); automatic symbol renaming via [[autorename]] (Python IDA plugin; auto rename symbol; asset pipelines / plugin development; cheat / IDA Plugins) (source: wiki/sources/descriptions/crifan__AutoRename.md); static-library function ID in stripped PEs via [[idenlib]] (IDA plugin; VC++/STL signature DB; FLIRT-adjacent) (source: wiki/sources/descriptions/secrary__idenLib.md); Linux FLIRT signature packs such as [[sig-database]] (OpenSSL/system libs across Ubuntu amd64/i386; IDA library ID) (source: wiki/sources/descriptions/push0ebp__sig-database.md); KMDF/WDF driver annotation in IDA via [[ida-kmdf]] (structures, callbacks, I/O queues, device init; Python) (source: wiki/sources/descriptions/thalium__ida_kmdf.md); Windows kernel driver RE via [[driver-buddy-reloaded]] (IOCTL dispatch, IRP handlers, vulnerable-driver patterns, WDM structure annotations; gmh5225; Windows Kernel Analysis) (source: wiki/sources/descriptions/gmh5225__DriverBuddyReloaded.md); driver vulnerability triage via [[driver-vuln-analyzer-ida-plugin]] (CyberSecurityUP; Python IDAPython; IOCTL extract/`CTL_CODE` decode, `METHOD_NEITHER` + sensitive-kernel-API flags; JSON export; driver attack-surface assessment) (source: wiki/sources/descriptions/CyberSecurityUP__DriverVuln-Analyzer-IDA-Plugin.md); automated pipeline-scale driver vuln research via [[deepzero]] (416rehman; parse/decompile kernel drivers at scale; AI-agent exploitable IOCTL analysis) (source: wiki/sources/descriptions/416rehman__DeepZero.md); standalone driver static analysis and exploitation triage via [[drveye]] (0xDbgMan; IOCTL recovery, taint analysis, emulation-based handler tracing, certificate checks, YARA, PoC generation) (source: wiki/sources/descriptions/0xDbgMan__DrvEye.md); bitfield structure visualization via [[ida-bitfields]] (annotate/display individual bit flags in registers and structure fields; driver IOCTL / flag-heavy RE; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__ida_bitfields.md); Hex-Rays NT kernel decompiler enrichment via [[ntrays]] (NTSTATUS/IOCTL/object-type/EPROCESS·ETHREAD field names; Windows Kernel Enhance; cheat / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__NtRays.md); PHNT Native API headers → IDA TIL/IDC via [[ida-phnt-types]] (Dump-GUY; idaclang/tilib; 32/64-bit; Windows SDK + PHNT type libraries for driver/AC binary RE) (source: wiki/sources/descriptions/Dump-GUY__IDA_PHNT_TYPES.md); indirect-call prototype application via [[apply-callee-type-ex]] (Dump-GUY; ApplyCalleeType reborn; Python; apply function prototype to indirect CALL for correct decompiler/disasm; IDA 8.x–9.3+; cheat / IDA Plugins) (source: wiki/sources/descriptions/Dump-GUY__ApplyCalleeTypeEx.md); UEFI firmware annotation in IDA via [[ida-efiutils]] (protocol GUIDs, Boot/Runtime Services, PEI/DXE entry points; Python; `[EFI binaries]`) (source: wiki/sources/descriptions/snare__ida-efiutils.md); automated UEFI firmware analysis via [[efixplorer]] (EFI protocol GUID matching; Boot/Runtime Services call annotation; protocol interface resolution; PEI/DXE driver dependency reconstruction; bootkit/EFI malware RE; gmh5225; `[UEFI firmware]`) (source: wiki/sources/descriptions/gmh5225__efiXplorer.md); Go UEFI flash-image parse/edit toolkit via [[fiano]] (Firmware Volumes, FFS, PE32, LZMA/Tiano compression, GUIDed sections; extract/replace/remove modules; `[EFI binaries]`) (source: wiki/sources/descriptions/linuxboot__fiano.md); AMD Secure Processor / PSP firmware loader for Binary Ninja via [[amd-sp-loader]] (AGESA Bootloader + PSP bootloader load-address setup; optional PSP syscall dictionary annotation; PSPTool-extracted blobs; AMD-SP/PSP firmware RE; dayzerosec; `[AMD-SP or PSP firmware]`) (source: wiki/sources/descriptions/dayzerosec__AMD-SP-Loader.md); Binary Ninja ↔ x64dbg plugin lane via [[x64dbgbinja]] (Python BN plugin) (source: wiki/sources/descriptions/x64dbg__x64dbgbinja.md); MachO kernelcache + KDK dSYM symbol/type load via [[binja-kc]] (Binary Ninja plugin) (source: wiki/sources/descriptions/skr0x1c0__binja_kc.md); MLIL division/modulo deoptimization via [[binja-division-deoptimization]] (Binary Ninja plugin; architecture-agnostic strength-reduction recovery) (source: wiki/sources/descriptions/jmprdi__binja-division-deoptimization.md); PTX / CUDA GPU virtual ISA RE via [[ptxninja]] (Binary Ninja plugin; plugin manager) (source: wiki/sources/descriptions/seekbytes__ptxNinja.md); call-graph / coverage-assisted graph analysis via [[ariadne]] (Binary Ninja plugin) (source: wiki/sources/descriptions/seeinglogic__ariadne.md); Ghidra Sleigh/p-code bridge into BN via [[binaryninja-pcode]] (C++; experimental LLIL from p-code) (source: wiki/sources/descriptions/pd0wm__binaryninja-pcode.md); Binary Ninja ↔ Ghidra Server bidirectional analysis sync via [[ghidra-svr-bridge]] (C++/Qt6 sidebar + Java 17 bridge; local TCP JSON; symbols/comments/types/signatures/parameters/bookmarks; Ghidra program-model API writes) (source: wiki/sources/descriptions/mutinylaboratories__ghidra_svr_bridge.md); Solana eBPF (SBF) ISA disasm/decompile via [[bn-ebpf-solana]] (Binary Ninja plugin; custom BPF encoding / memory model / calling conventions) (source: wiki/sources/descriptions/otter-sec__bn-ebpf-solana.md); Solana sBPF rlib signature packs for IDA/Ghidra/Binary Ninja via [[solana-sbpf-rlib]] (Python; plugin development / modding / SDK generation; IDA signature database lane) (source: wiki/sources/descriptions/cpkt9762__solana-sbpf-rlib.md); Ethereum EVM bytecode disasm/CFG/xrefs via [[ethersplay]] (Binary Ninja plugin; compiled Solidity smart-contract analysis; blockchain security auditors) (source: wiki/sources/descriptions/gmh5225__ethersplay.md); IDA Pro EVM bytecode processor module via [[ida-evm]] (Crytic; PUSH/POP/SLOAD/SSTORE/CALL/JUMPI decode; operand formatting + xrefs; Python plugin; smart-contract bytecode RE) (source: wiki/sources/descriptions/crytic__ida-evm.md); process auto-attach via [[auto-attach]] (x64dbg plugin; target process name + optional attach delay; enable/disable commands) (source: wiki/sources/descriptions/legendabrn__AutoAttach.md); collaborative x64dbg breakpoint management via [[slothbp]] (source: wiki/sources/descriptions/x64dbg__SlothBP.md); .NET 6 / C# x64dbg plugins via [[dotx64dbg]] (live edit + custom commands/expressions) (source: wiki/sources/descriptions/x64dbg__DotX64Dbg.md); OOP class documentation while debugging via [[classroom]] (member funcs/vars; persisted docs) (source: wiki/sources/descriptions/x64dbg__Classroom.md); live DLL export-table monitoring via [[expomon]] (Qt GUI; names/ordinals/addresses; Exports monitoring) (source: wiki/sources/descriptions/milcert__ExpoMon.md); DLL load-notification callback inspection via [[x64dbg-view-dll-notification]] (C++/C++ x64dbg plugin; Cheat x64dbg Plugins) (source: wiki/sources/descriptions/gmh5225__X64DBG-ViewDllNotification.md); memory write/access tracing via [[xfindout]] (what writes/accesses an address; Cheat Engine–style watch in [[x64dbg]]) (source: wiki/sources/descriptions/morsisko__xFindOut.md); memory value scanning via [[clawsearch]] (Cheat Engine–style first/next scan in [[x64dbg]]; int/float types; exact/changed/increased filters) (source: wiki/sources/descriptions/codecat__ClawSearch.md); offline `.trace64` execution-trace parse/disasm/filter via [[x64dbg-trace-reader]] (Capstone disasm; per-instruction register/memory state; regex filter) (source: wiki/sources/descriptions/mibho__x64dbgTraceReader.md); sequential DLL load-order debugging via [[disable-parallel-loader]] (patches `LdrpMapAndSnapWork` / Win10+ parallel loader; phnt; x64dbg plugin) (source: wiki/sources/descriptions/mrexodia__DisableParallelLoader.md); live static-library function ID via [[idenlibx]] (idenLib x64dbg plugin; signature scan → name apply) (source: wiki/sources/descriptions/secrary__idenLibX.md); Windows type parsing via [[manytypes]] (x64dbg typeparsing plugin; structure/type discovery for memory RE) (source: wiki/sources/descriptions/notpidgey__ManyTypes.md); XFG call-signature marking via [[x64dbg-xfg-marker]] (8-byte signatures as data before target functions; Cheat x64dbg Plugins) (source: wiki/sources/descriptions/m417z__x64dbg-xfg-marker.md); WinDbg CFG coverage inspection via [[cfgdump]] (JKornev; C++ extension; print CFG maps, query ranges, list protected regions; exploit research + hardening validation) (source: wiki/sources/descriptions/JKornev__cfgdump.md); multiline assemble/disassemble via [[multiline-ultimate-assembler]] (x64dbg/OllyDbg plugin; plugin SDK / modding) (source: wiki/sources/descriptions/m417z__Multiline-Ultimate-Assembler.md); ChaiScript scripting via [[chaiscript-plugin]] (x64dbg plugin; three commands; thorough API vs rapid prototyping; Cheat x64dbg Plugins) (source: wiki/sources/descriptions/jdavidberger__chaiScriptPlugin.md); Lua scripting via [[x64dbg-playtime]] (embedded Lua runtime; memory/registers/breakpoints/labels/modules/assembler; autorun scripts; ZehMatt; Cheat x64dbg Plugins / Lua script lane) (source: wiki/sources/descriptions/ZehMatt__x64dbgPlaytime.md); Python 3 scripting via [[x64dbgpython]] (C++ in-debugger plugin; Python wrappers mirroring plugin SDK APIs; memory/assembly/module/GUI example scripts; debugger automation for x86/x64; ElvisBlue; Running python3 script) (source: wiki/sources/descriptions/ElvisBlue__x64dbgpython.md); native x64dbg script samples and IDA label/comment export helpers via [[x64dbg-script]] (Ahmadmansoor; multi-step execution control, globals, instruction-sequence search; game/binary RE automation) (source: wiki/sources/descriptions/Ahmadmansoor__x64dbgScript.md); x64dbg plugin install/management via [[x64dbg-plugin-manager]] (C++/C; plugin development / modding; Cheat x64dbg Plugins) (source: wiki/sources/descriptions/horsicq__x64dbg-Plugin-Manager.md); dedicated in-process string search/browse via [[stringsx64dbg]] (C++/Qt; SearchStringsWidget tab; 32/64-bit; Cheat x64dbg Plugins) (source: wiki/sources/descriptions/horsicq__stringsx64dbg.md); standalone binary/process string extraction via [[strings2]] (C/C++; modding / memory analysis; disk images + live process memory; cheat / RE tools) (source: wiki/sources/descriptions/glmcdona__strings2.md); in-debugger static compiler/packer/protector ID via [[nfdx64dbg]] (Nauz File Detector / NFD tab; C++/Qt; 32/64-bit; Cheat x64dbg Plugins) (source: wiki/sources/descriptions/horsicq__nfdx64dbg.md); standalone signature-based linker/compiler/packer/protector triage via [[nauz-file-detector]] (NFD; PE/ELF/Mach-O+; C++/Qt GUI+CLI; horsicq) (source: wiki/sources/descriptions/horsicq__Nauz-File-Detector.md); IDA JM Xorstr decrypt attempts via [[ida-jm-xorstr-decrypt-plugin]] (x64) (source: wiki/sources/descriptions/yubie-re__ida-jm-xorstr-decrypt-plugin.md); nProtect GameGuard string decrypt via [[ida-gameguard-str-dec]] (Python; modding; cheat / IDA Plugins) (source: wiki/sources/descriptions/crtdll__ida-gameguard-str-dec.md); anti-Xorstr recovery via [[anti-xorstr]] (Python; cheat / IDA Plugins) (source: wiki/sources/descriptions/lstaroth__AntiXorstr.md); stack-string deobfuscation via [[unxorer]] (IDA Pro/Home C++ plugin; Unicorn emulation explores branching paths, preserves state, scans stack for decoded text; configurable start points + output navigation; malware/game-security RE; cheat / IDA Plugins) (source: wiki/sources/descriptions/SamuelTulach__unxorer.md); iOS IDA helper [[ida-ios-helper]] (vtable symbols required) (source: wiki/sources/descriptions/yoavst__ida-ios-helper.md); Android DEX→Java via [[jadx]] (CLI+GUI; APK/DEX/AAR) (source: wiki/sources/descriptions/skylot__jadx.md); HarmonyOS NEXT ArkCompiler `.abc`→JS/TS via [[arkdecompiler]] (ArkTS/ArkJS bytecode; CFG recovery; mobile RE lane) (source: wiki/sources/descriptions/jd-opensource__arkdecompiler.md); Open/HarmonyOS `.abc` parser/decompiler via [[dayu]] (maintenance not guaranteed; cheat/RE lane) (source: wiki/sources/descriptions/hx1997__dayu.md); DEX↔JAR conversion via [[dex2jar]] (d2j-baksmali / APK sign / DEX manip; JD-GUI/CFR lane) (source: wiki/sources/descriptions/pxb1988__dex2jar.md); smali/Dalvik bytecode editor via [[dalvikus]] (Android RE; cheat / RE tools) (source: wiki/sources/descriptions/loerting__dalvikus.md); Python Dalvik bytecode emulator via [[dalivm]] (DEX execution, Android API mocking, static analysis, dependency tracing; malware RE; no Android runtime) (source: wiki/sources/descriptions/fatalSec__DaliVM.md); automated static Android DEX/resource unpacker via [[kavanoz]] (Python; commercial packer schemes—Bangcle/Ijiami/Qihoo 360+; banker malware; static APK analysis) (source: wiki/sources/descriptions/eybisi__kavanoz.md); Zygisk runtime DEX dump via [[zygisk-dump-dex]] (`libdexfile.so` hook; Android 14/15; Cheat Magisk) (source: wiki/sources/descriptions/ri-char__zygisk-dump-dex.md); Android loaded `.so` ELF reconstruction from live process memory via [[memdumper]] (no `ptrace`; `/proc//mem`; 32/64-bit; Cheat / Dump) (source: wiki/sources/descriptions/kp7742__MemDumper.md); Zygisk runtime `.so` memory dump via [[zygisk-memdump]] (Magisk module; process memory extraction for native RE; Cheat Magisk) (source: wiki/sources/descriptions/hackcatml__zygisk-memdump.md); Linux/Android HWBP process watching via [[pwatch]] (debug without attaching a conventional debugger; cheat / debugging) (source: wiki/sources/descriptions/ri-char__pwatch.md); C/C++ variant [[pwatch-c]] (enenH; same HWBP lane) (source: wiki/sources/descriptions/enenH__pwatch-c.md); ARM64 Linux kernel HWBP module [[hardware-breakpoint]] (Ylarod; exported APIs + proc; exec/watch breakpoints; trigger stats; Android/embedded kernel debugging; HWBP on linux/android) (source: wiki/sources/descriptions/Ylarod__hardware-breakpoint.md); Android app dynamic behavior tracking via eBPF such as [[btrace]] (C/C++/Go; cheat / RE tools) (source: wiki/sources/descriptions/null-luo__btrace.md); Android eBPF load/trace examples such as [[android-ebpf]] (syscall/network/process/perf tracing; cheat / EBPF) (source: wiki/sources/descriptions/gmh5225__android_ebpf.md); eBPF stack trace / hook analysis [[stackplz]] (SeeFlowerX; Go controller + eBPF C; syscall/uprobe/hardware-breakpoint tracing on ARM64; args/registers/stacks; filtering, structured output, optional Frida RPC; rooted mobile security / game protection RE; cheat / eBPF-based debugger for Android) (source: wiki/sources/descriptions/SeeFlowerX__stackplz.md); Frida ART smali instruction tracer [[frida-smali-trace]] (SeeFlowerX; JS/TS agents hook interpreter paths; execution logs; IDA offset/register prep; Android RE / runtime behavior; cheat / Smali trace) (source: wiki/sources/descriptions/SeeFlowerX__frida-smali-trace.md); eBPF Android debugger [[edbg]] (Sh11no; CLI ARM64 debugger without ptrace; GDB-like breakpoints/memory/registers/threads; file+offset breakpoints; anti-debug resistance; rooted mobile RE / game security) (source: wiki/sources/descriptions/Sh11no__eDBG.md); [[edbgserver]] (Satar07; Rust multi-crate eBPF debugger server for Android/Linux; Arm64/x86_64; breakpoints/stepping/memory/registers/signals/library info; ptrace-free low-intrusion model; monitored-environment RE) (source: wiki/sources/descriptions/Satar07__edbgserver.md); cross-platform remote debugger/scanner [[dynadbg]] (DoranekoSystems; TypeScript/React Tauri GUI + Rust/C/C++ backend; memory scan modes, watchpoints, code tracing, debugger views, host-remote workflows; Android/iOS; GUI-driven low-level RE / game security) (source: wiki/sources/descriptions/DoranekoSystems__DynaDbg.md); ARM64 uprobe hook framework [[ehook]] (Go + C eBPF; on-enter/on-leave handlers; memory R/W wrappers; rooted mobile game RE / runtime tracing; ShinoLeah; cheat / eBPF hook) (source: wiki/sources/descriptions/ShinoLeah__eHook.md); KPM uprobe mass-hook [[kernel-trace]] (AndroidReverser-Test; C/C++ Linux/Android kernel module; bulk user-space function hooks via uprobes; tracefs output; userspace probe config APIs; Android dynamic analysis / behavior tracing) (source: wiki/sources/descriptions/AndroidReverser-Test__Kernel-Trace.md); Linux ptrace TEB readers such as [[ptrace-read-teb]] (C++; inspect Windows TEB under Linux for Wine/cheat RE) (source: wiki/sources/descriptions/pgarba__ptrace_read_teb.md); Android apktool via [[apktool-mcp-server]] (MCP suite) (source: wiki/sources/descriptions/zinja-coder__apktool-mcp-server.md); headless JADX MCP via [[delamain]] (Java/Javalin + FastMCP; APK/DEX/AAB decompile, xrefs, Frida hooks for agents) (source: wiki/sources/descriptions/xjoker__delamain.md); ProGuard/R8 APK name recovery + HTML class-hierarchy reports via [[obfu-de-scate]] (source: wiki/sources/descriptions/user1342__Obfu-DE-Scate.md); APK signature-crack study via [[asctool]] (Kotlin; Some Tricks / Android) (source: wiki/sources/descriptions/stars-one__ASCTool.md); APK v1/v2/v3 signature copy/extract/patch via [[apksigcopier]] (Python; Signing Block transplant / compare APKs) (source: wiki/sources/descriptions/obfusk__apksigcopier.md); standalone Android APK signing via [[apksigner]] (Apk Sign Tool; cheat / RE tools) (source: wiki/sources/descriptions/jixiaoyong__ApkSigner.md); Android OTA `payload.bin` dumps via [[payload-dumper]] (Python; ROM/RE tools) (source: wiki/sources/descriptions/vm03__payload_dumper.md) and Go [[payload-dumper-go]] (parallel decompress / checksum) (source: wiki/sources/descriptions/ssut__payload-dumper-go.md); Android HTTP/HTTPS capture + NL query via [[android-proxy-mcp]] (mitmdump/SQLite) (source: wiki/sources/descriptions/zhizhuodemao__android_proxy_mcp.md) - **Cheat Engine UX:** official Lua gamepad add-on [[controller-mode]] (cheat-engine/ControllerMode; full CE desktop UI via Xbox-style controller; D-pad list/tree/hex navigation, on-screen hints, `.CT` file picker, experimental Steam Deck keyboard; cheat / CE plugin) supports handheld RE workflows on [[cheat-engine]]. (source: wiki/sources/descriptions/cheat-engine__ControllerMode.md) Community Lua extension packs such as [[ce-lua-extensions]] (Skyrimfus; autorun loader + breakpoint cleanup, function-caller lookup, template insertion, interface workflow scripts; cheat / Lua Extensions) speed up live memory-analysis RE on [[cheat-engine]]. (source: wiki/sources/descriptions/Skyrimfus__CE-lua-extensions.md) Modular Lua utility packs such as [[ce-extensions]] (FreeER; autosave, disassembler highlighting, structure/offset helpers, process attachment conveniences; independently loadable scripts; cheat / Lua Extensions) extend CE interface and scripting for advanced users. (source: wiki/sources/descriptions/FreeER__CE-Extensions.md) CE Mono introspection helpers such as [[cheatengine-mono-helper]] (JasonGoemaat; Lua + CE tables; searchable Mono class/field/method views, hook templates, disassembly jump, runtime monitoring scripts; cheat / CE Mono Helper) extend that UX lane for Unity Mono managed-runtime RE beside [[mono]] and [[dnspy]]. (source: wiki/sources/descriptions/JasonGoemaat__CheatEngineMonoHelper.md) Multi-game prebuilt CE table collections such as [[mydev-cheat-engine-tables]] (`.CT` pointer chains, script cheats, hotkey bindings; direct Cheat Engine load for single-player value editing) complement that UX lane for researchers studying table structure and pointer-chain workflows. (source: wiki/sources/descriptions/bbfox0703__Mydev-Cheat-Engine-Tables.md) Large forum-curated archives such as [[cheat-engine-tables]] (Hexorg; thousands of game-specific `.CT` files under a tables directory; pointer chains, AOB scans, Lua scripts, trainers; offline-focused; cheat / [Cheat Engine]) extend that lane for cross-title CE technique reference. (source: wiki/sources/descriptions/Hexorg__CheatEngineTables.md) Broad example and practice-table collections such as [[ce-examples]] (FreeER; Lua/`.CT` assets for memory scanning, Auto Assembler, pointer utilities, UI helpers, Mono workflows, trainer experiments; snippets and templates for RE and game memory manipulation; teaching CE workflows; cheat / Some Examples) complement that lane for hands-on CE technique study. (source: wiki/sources/descriptions/FreeER__CE-Examples.md) Title-specific MapleStory v179 CE `.CT`/CEA script collections such as [[maplestory-v179-cheat-engine]] (Noosh404; pattern-scan byte patches for full-map attack, skill injection, no-delay, pet loot teleport, knockback tweaks; legacy MapleStory RE practice; cheat / game:maplestory [V179 CT]) extend that lane for version-specific Auto Assembler workflow study. (source: wiki/sources/descriptions/Noosh404__Maplestory-V179-Cheat-Engine.md) Native Windows x64 memory research tool [[pointer-lab]] (HeathHowren; ImGui dockspace; scan, pointer chains, disasm/patch, Lua automation; offline RE / CTF practice—not online AC evasion) complements [[cheat-engine]] for authorized live-memory RE workflows. (source: wiki/sources/descriptions/HeathHowren__Pointer-Lab.md) Portable Windows memory scanner [[simple-memory-editor]] (daveymcq; C + custom NCRT + Win32 GUI; external attach/scan/edit/freeze; int/float/double equal/increased/decreased filters; static 32/64-bit portable builds; in-game variable RE and external memory-editing study) complements [[cheat-engine]] and [[pointer-lab]] for lightweight portable workflows. (source: wiki/sources/descriptions/daveymcq__SimpleMemoryEditor.md) - **DBI:** Frida, DynamoRIO, Pin; trap-and-emulate CFT; WHP user-mode hypervisor tracing; WHP-hosted x64 PE emulation such as [[winvisor]] (`Windows Emulator`); RING3 kernel-driver sandboxing such as [[kace]] (self context mapping or Unicorn; PE mapping, memory tracking, anti-debug/anti-emulation checks; AC/driver RE without loading on the host; Qfrost911 fork) (source: wiki/sources/descriptions/x86matthew__WinVisor.md) (source: wiki/sources/descriptions/waryas__KACE.md) (source: wiki/sources/descriptions/Qfrost911__KACE.md); hybrid semi-emulated/semi-native kernel-driver emulator [[kdemu]] (PE load, exception handling, kernel dump integration, anti-detection, execution monitoring; rootkit/AC drivers resisting conventional debug; ShallowFeather) (source: wiki/sources/descriptions/ShallowFeather__KDemu.md); platform-independent x86 user+kernel environment emulator [[kubera]] (research-focused; cheat / DBI; binsnake) (source: wiki/sources/descriptions/binsnake__KUBERA.md); WIP x86-64 user-mode emulator [[zyemu]] (JIT handler codegen + code cache; Zydis decode/encode; CPU/memory core; C++; low-level emulation / binary analysis; ZehMatt) (source: wiki/sources/descriptions/ZehMatt__zyemu.md); Hex-Rays self-checking multi-arch CPU emulator [[rax]] (Rust; x86/x64/ARM32/AArch64/Hexagon/RISC-V; SMIR JIT; instruction-level diff vs KVM/QEMU oracles; Linux boot, SDE trace, GDB stub for IDA; binary analysis / fuzzing; HexRaysSA) (source: wiki/sources/descriptions/HexRaysSA__rax.md); Linux userspace x86/x64-on-RISC-V emulator [[felix86]] (JIT recompiler + vectorized SSE translation + RISC-V extensions; modern C++; cross-arch execution research; `Linux Emulator`; OFFTKP) (source: wiki/sources/descriptions/OFFTKP__felix86.md); title-specific Tencent ACE (Anti-Cheat Expert) reverse-engineering such as [[starrail-ace-b]] (Honkai: Star Rail; kernel driver behavior, integrity checks, detection/bypass surfaces; gmh5225) documents miHoYo/HoYoverse PC protection beside sandboxed driver emulation (source: wiki/sources/descriptions/gmh5225__StarRail-ACE-B.md); Honkai Impact 3rd ACE bypass research such as [[hi3-ace-b]] (integrity-check / detection circumvention; gmh5225) complements Star Rail ACE documentation for HoYoverse titles (source: wiki/sources/descriptions/gmh5225__HI3-ACE-B.md); Microsoft Hyper-V memory introspection / RE such as [[hyper-rev]] (structures, hypercalls, partitions, VP / memory virtualization) (source: wiki/sources/descriptions/noahware__hyper-reV.md); multi-emulator binary harnessing such as [[smallworld]] (unified angr / Ghidra / PANDA / Unicorn interface; coverage, crash triage, firmware testing) (source: wiki/sources/descriptions/smallworld-re__smallworld.md); architecture-neutral whole-system dynamic analysis via [[panda]] (QEMU-based PANDA; full-machine software emulation without hardware VT; cheat / QEMU/KVM/PVE/VBOX research) (source: wiki/sources/descriptions/panda-re__panda.md); QEMU **Malware Behavior Analyzer** [[glacierw-mba]] (GlacierW/MBA; full QEMU tree + instrumentation; memory forensics, API tracing, behavioral monitoring; Windows/Linux guests; malware whole-system introspection) (source: wiki/sources/descriptions/GlacierW__MBA.md); Intel-PT–backed hypervisor fuzzing via [[qemu-nyx]] (fast VM reset, PT decode / swapped-out disasm, breakpoint hooks + fuzzing frontend; cheat / QEMU/KVM) (source: wiki/sources/descriptions/nyx-fuzz__QEMU-Nyx.md); ISP RAS analysis/instrumentation QEMU fork [[ispras-qemu]] (coverage / taint / symbolic-exec; README windbg tree) (source: wiki/sources/descriptions/ispras__qemu.md); Frida script collections such as [[frida-scripts]] (smartdone; JS/Python; editor tooling and hooking in the cheat / Frida lane) (source: wiki/sources/descriptions/smartdone__Frida-Scripts.md) and [[0xdea-frida-scripts]] (0xdea; iOS/Android/Linux tracing, class discovery, bypass-oriented snippets) (source: wiki/sources/descriptions/0xdea__frida-scripts.md); cross-platform game/app hook scripts such as [[fridascript]] (gmh5225; JavaScript call intercept, API trace, runtime modify; Android/iOS/desktop; iOS low-level scripting) (source: wiki/sources/descriptions/gmh5225__FridaScript.md); Frida stack/backtrace helpers such as [[frida-stack]] (reuse unwind helpers for clearer traces) (source: wiki/sources/descriptions/rednaga__frida-stack.md); Frida hardware watchpoint tutorial [[frida-watchpoint-tutorial]] (`setHardwareWatchpoint`; what-writes/accesses tracing; cheat / Frida) (source: wiki/sources/descriptions/hackcatml__frida-watchpoint-tutorial.md); beginner Frida DBI workshop [[frida-boot]] (gmh5225; streamed YouTube course; cheat / Frida) (source: wiki/sources/descriptions/gmh5225__frida-boot.md); VEH-based lightweight DBI such as [[cpp-veh-dbi]] (C++ / PowerShell; exception-driven instrumentation vs full Pin/DynamoRIO) (source: wiki/sources/descriptions/revsic__cpp-veh-dbi.md); C++/C DBI / analysis / patching frameworks such as [[w1tn3ss]] (modding / hooking / memory analysis) (source: wiki/sources/descriptions/redthing1__w1tn3ss.md); Python QEMU user-mode dynamic binary analysis via [[pyda]] (Linux binary instrument / hook / mem / syscall / insn callbacks without native exec) (source: wiki/sources/descriptions/ndrewh__pyda.md); radare2-backed fast binary emulation + symbolic execution via [[radius2]] (Rust/C; Cheat → Radare Plugins) (source: wiki/sources/descriptions/radareorg__radius2.md); core DBA library [[triton]] (JonathanSalwan; C++/Python; symbolic exec, taint analysis, expression synthesis, SMT simplification; x86/x64/ARM/AArch64/RISC-V; LLVM/Z3 lift; Z3/Bitwuzla; RE automation) (source: wiki/sources/descriptions/JonathanSalwan__Triton.md); function-level rip → Python/Unicorn harnesses via [[ripr]] (IDA plugin + r2pipe; BN/Unicorn packaging) (source: wiki/sources/descriptions/pbiernat__ripr.md); educational Rust Android ELF user-mode emulator [[rudroid]] (ELF loader, memory management, syscall handling, filesystem abstractions, ARM64 Unicorn scaffolding; walkthrough docs; cheat / Android native RE / emulation) (source: wiki/sources/descriptions/ant4g0nist__rudroid.md); alternative Linux ELF dynamic loader [[sloader]] (modern C++; aims to replace glibc `ld-linux.so`; readable library load + symbol resolution; loader design docs + glibc test workflows; linker-internals / program-loading research) (source: wiki/sources/descriptions/akawashiro__sloader.md); Linux x64 ELF→self-loading shell script toolchain [[stelf-loader]] (Python + NASM shellcode; map segments, restore protections, jump to entry; compressed/base64/one-liner modes; exploit/payload/ELF loader RE) (source: wiki/sources/descriptions/DavidBuchanan314__stelf-loader.md); in-IDA Unicorn emulation via [[sk3wldbg]] (IDA plugin; x86/ARM/MIPS; register/memory setup; step without live target; Cheat → Unicorn) (source: wiki/sources/descriptions/gmh5225__sk3wldbg.md); in-IDA Unicorn emulation with trace/asm integration via [[ews]] (Emulator Wrapper Solution; ARM/x86/x64; Keystone+Capstone; click-ready traces; embedded/Android/automotive firmware; Cheat → Emulation) (source: wiki/sources/descriptions/deadeert__EWS.md); in-IDA symbolic + taint execution via [[ponce]] (Triton; path constraints, tainted data flow, input generation; Cheat → Symbolic Execution / IDA Plugins) (source: wiki/sources/descriptions/gmh5225__Ponce.md); Binary Ninja Triton integration scaffold via [[triton-bn]] (plugin base for DBA / symbolic exec inside BN; Cheat → Binary Ninja Plugins) (source: wiki/sources/descriptions/ergrelet__triton-bn.md); Binary Ninja symbolic execution via [[seninja]] (Python plugin; BN IL integration; path constraints, unreachable-code detection, reachability conditions; interactive symbolic exploration UI; Cheat → Symbolic Execution) (source: wiki/sources/descriptions/borzacchiello__seninja.md); debugger-emulator hybrids such as [[emulator]] (Unicorn + Capstone; PE section mapping; dbghelp import resolve; Windows API hooking + instruction-level logging for DRM/obfuscated EXE study; Windows User Space Emulator) (source: wiki/sources/descriptions/mojtabafalleh__emulator.md); Unicorn PE instrumentation such as [[unicorn-pe]] (emulated Windows PE execution for packed binaries; per-instruction disasm trace; cheat / DBI lane) (source: wiki/sources/descriptions/hzqst__unicorn_pe.md); .NET Unicorn analysis framework [[brovan]] (AdvDebug; x86/x64/ARM PE/ELF + memory dumps; syscall emulation, API hooking, interactive debugger shell; Windows User Space Emulator) (source: wiki/sources/descriptions/AdvDebug__Brovan.md); standalone C multi-format binary analysis / Fast APK/DEX/JAR Java decompiler via [[garlic]] (PE/ELF/Mach-O/DEX/APK + ARM disasm; CLI) (source: wiki/sources/descriptions/neocanable__garlic.md); Garlic DEX/Dalvik decompiler + multi-format parse (DEX/APK/ELF/PE/Mach-O) via [[r2garlic]] (in-memory streams; Cheat → Radare Plugins) (source: wiki/sources/descriptions/radareorg__r2garlic.md) - **IoT / firmware:** IoT firmware vulnerability hunting via [[firmeye]] (Python IDA plugin; trace arguments into sensitive functions; static checks + debugger-assisted dynamic analysis; buffer overflow / command execution / format-string rules; CLI batch workflows; firmware security auditing + embedded RE; Vu1nT0tal; cheat / IoT / IDA Plugins) sits beside [[efixplorer]], [[renamaida]], [[embedded-hacking]], and [[smallworld]] (source: wiki/sources/descriptions/Vu1nT0tal__firmeye.md). Ghidra-side UEFI firmware analysis via [[efiseek]] (DSecurity; Java analyzer plugin; known EFI GUID identification, protocol usage patterns, LOCATE_PROTOCOL/NOTIFY/INSTALL_PROTOCOL_INTERFACE callback flows; helper scripts + GUID data for headless structured firmware RE; complements [[efixplorer]] and [[ida-efiutils]]) (source: wiki/sources/descriptions/DSecurity__efiSeek.md). Motorola M·CORE embedded firmware decompilation via [[mcore-decompiler]] (IDA Pro 9.4; independent IR pipeline fills the Hex-Rays gap for MCORE processor targets such as feature-phone firmware) complements static audit tooling when lifting obscure embedded binaries to readable pseudocode. (source: wiki/sources/descriptions/Siesta__MCORE-Decompiler.md) Consumer-camera exploitation research via [[xiaomi-c400-pwn]] (Xiaomi Smart Camera C400; Python RNG-prediction exploit; Tamarin handshake models; persistent jailbreak; TaszkSecLabs) complements that lane. (source: wiki/sources/descriptions/TaszkSecLabs__xiaomi-c400-pwn.md) UEFI source-level debugging dev setups such as [[visualuefi-2-0]] (VisualUEFI-style; Clang/DWARF; EDK2 samples + Visual Studio; VMware + GDB/CLion remote frontend; complements static UEFI annotators [[efixplorer]] and [[ida-efiutils]]) sit beside that firmware RE lane. (source: wiki/sources/descriptions/Shtan7__VisualUEFI-2.0.md) - Custom Binary Ninja architecture plugins via [[binaryninjaplugins]] (Pusty; Python; Java class files, Renesas H8/300, Xtensa ELF; disassembly, decode, partial lifting; Java NOP/branch patch workflows; firmware/bytecode RE extension lane) sit beside [[binaryninja-pcode]] and [[ptxninja]]. (source: wiki/sources/descriptions/Pusty__BinaryNinjaPlugins.md) - Binary Ninja visual themes via [[binaryninja-themes]] (FuzzySecurity; `.bntheme` collection; standard/light/green Gruvbox-inspired palettes; disassembly and graph view readability; cheat / Theme) improve analyst comfort during long static-analysis sessions—parallel to IDA theme packs such as [[ida-nord-theme]] and [[long-night]]. (source: wiki/sources/descriptions/FuzzySecurity__BinaryNinja-Themes.md) - GUI API breakpoint setup via [[api-breakpoint]] (x64dbg plugin; C++; visual configure/manage workflow for Windows API tracing; x86/x64; Kwansy98; Cheat x64dbg Plugins / Api Breakpoint) sits in the [[x64dbg]] dynamic RE plugin lane beside [[slothbp]] and [[x64dbg-call-finder]]. (source: wiki/sources/descriptions/Kwansy98__ApiBreakpoint.md) - Runtime call-frequency profiling via [[x64dbg-call-finder]] (x64dbg plugin; C++; scans user functions with conditional breakpoints + counters; filter by call count after in-app actions; UI/gameplay handler discovery; Kwansy98; Cheat x64dbg Plugins / Call Finder) sits in the [[x64dbg]] dynamic RE plugin lane beside [[xfindout]] and [[clawsearch]]. (source: wiki/sources/descriptions/Kwansy98__x64dbgCallFinder.md) - Formatted byte pasting into memory/dump views via [[yummy-paste]] (x64dbg plugin; C++; C-style arrays, escaped shellcode, comma/space-separated decimals; disassembler and dump workflows; quick patching and byte injection; 0ffffffffh; Cheat x64dbg Plugins / paste string formatted byte data block into x64dbg easy) sits in the [[x64dbg]] dynamic RE plugin lane beside [[multiline-ultimate-assembler]] and [[x64dbgpython]]. (source: wiki/sources/descriptions/0ffffffffh__yummyPaste.md) - Two-stage Themida + Nuitka onefile unpack via [[nuitka-themida-unpacker]] (DimaReverse; Python; chains [[unlicense]] dynamic strip with nuthem KAX/KAY static extraction; zstd/uncompressed archives; path-traversal-safe extraction; SHA-256 manifests; optional Python artifact recovery; doubly protected malware or hardened game-tool samples; Fix Themida) sits in the Cheat Fix Themida lane. (source: wiki/sources/descriptions/DimaReverse__nuitka-themida-unpacker.md) - **Obfuscation:** MBA, OLLVM CFF, opaque predicates, VMProtect/Themida virtualization; MBA sample generation via [[mutaben]] (Python MBA generator) (source: wiki/sources/descriptions/z1ko__mutaben.md); non-linear MBA obfuscation / samples via [[mba-obfuscator]] (`mba_obfuscator/` + `samples/`) (source: wiki/sources/descriptions/nhpcc502__MBA-Obfuscator.md); source-to-source C++ MBA constant/arithmetic transform via [[mixed-boolean-transform]] (Z3-verified polynomial identities; Eigen3 + GMP) (source: wiki/sources/descriptions/mizt0__mixed-boolean-transform.md); compile-time MBA control-flow obfuscation hiding jump targets via [[limba]] (C++20; Clang/clang-cl; per-build randomized rewrite rules; ThatLing) (source: wiki/sources/descriptions/ThatLing__limba.md); MBA expression simplification via [[cobra]] (Trail of Bits CoBRA; C++ coefficient-based reconstruction) (source: wiki/sources/descriptions/trailofbits__CoBRA.md); practical MBA simplification via [[mbased]] (bliutech; Cheat Mixed boolean-arithmetic) (source: wiki/sources/descriptions/bliutech__mbased.md); MBA deobfuscation via program synthesis and term rewriting via [[promba]] (linear/polynomial MBA; VM-protector contexts; astean1001; Cheat Mixed boolean-arithmetic) (source: wiki/sources/descriptions/astean1001__ProMBA.md); oracle-backed MBA simplification via [[msynth]] (Python; pre-computed lookup tables + Smir stochastic synthesis; Miasm symbolic execution + optional SMT verify; Cheat Mixed boolean-arithmetic) (source: wiki/sources/descriptions/mrphrazer__msynth.md); GPU-accelerated CUDA MBA evaluation and simplification via [[mba]] (SynthesisLab; multiple CUDA kernels; JSON I/O; cooperative groups; Cheat Mixed boolean-arithmetic) (source: wiki/sources/descriptions/SynthesisLab__MBA.md); browser-based Rust/WASM MBA obfuscation, linear congruence solving, permutation polynomial generation, and expression simplification via [[mba-wasm]] (MathJax UI; MBA-research; Cheat Mixed boolean-arithmetic) (source: wiki/sources/descriptions/MBA-research__mba-wasm.md); GNN-based MBA deobfuscation via [[gnn-deobfuscation]] (Python; Loki/MBABlast/MBAObfuscator datasets by variable count and operation depth; LostOxygen; Cheat Mixed boolean-arithmetic) (source: wiki/sources/descriptions/LostOxygen__gnn_deobfuscation.md); IDA Pro oracle-guided MBA synthesis via [[qsynthesis]] (Python; program synthesis + SMT; Hex-Rays decompiler integration; Cheat → IDA Plugins) (source: wiki/sources/descriptions/gmh5225__qsynthesis.md); exact Drill & Join Boolean/bit-vector synthesis for 64-bit opaque predicates and MBA-style expressions via [[drill-and-join]] (C++17 header-only; ANF synthesis + Bitwuzla equivalence; SMT-guided bit dependency reduction; truth-table synthesis CLI) (source: wiki/sources/descriptions/fvrmatteo__DrillAndJoin.md); bitvector/array SMT solving via [[stp]] (Simple Theorem Prover; MiniSat/CryptoMiniSat backends; SMT-LIB 2) for symbolic-exec / verification backends (source: wiki/sources/descriptions/stp__stp.md); circuit-based AIG SAT via [[cirsat]] (DAG logic networks / AIGER; hardware verification & combinational equivalence) (source: wiki/sources/descriptions/nbulsi__cirsat.md); [[shredder-rs]] for x86_64 instruction-level polymorphic shredding vs static analysis (source: wiki/sources/descriptions/zx0CF1__shredder-rs.md); Python x64 opcode-equivalent substitution via [[beatrice-py]] (semantically identical encodings; AV/AC signature-evasion / binary-diversity research) (source: wiki/sources/descriptions/raskolnikov90__Beatrice.py.md); radare2 metamorphic binary transform via [[r2morph]] (r2pipe; Cheat → Radare Plugins) (source: wiki/sources/descriptions/seifreed__r2morph.md); polymorphic mimikatz PE rewriter via [[morphkatz]] (disassembly, CFG analysis, instruction-level morphing, data-flow obfuscation; semantically identical Windows x64 variants) (source: wiki/sources/descriptions/0xMohammedHassan__morphkatz.md); OLLVM fix / plugin-hook work on `libtprt.so` via [[deobf]] (source: wiki/sources/descriptions/zhuzhu-Top__deobf.md); Java bytecode shrink/optimize/obfuscate via [[proguard]] (Guardsquare; shrinker/optimizer/obfuscator/preverifier; configurable keep/rename rules; Java/Android client hardening; `[Java]`) (source: wiki/sources/descriptions/Guardsquare__proguard.md); Java bytecode deobfuscation via [[deobfuscator]] (gmh5225 fork + narumii; ProGuard/Allatori/ZKM string decrypt, CFF restore, opaque-predicate simplify, identifier rename, dead-code cleanup; Java/Android RE) (source: wiki/sources/descriptions/gmh5225__deobfuscator.md) (source: wiki/sources/descriptions/narumii__Deobfuscator.md); Ricochet AC deobfuscation via [[ricochet-deobfuscator]] (C/C++; driver / memory analysis; explore anticheat:ricochet) (source: wiki/sources/descriptions/weak1337__ricochet_deobfuscator.md); Ricochet AC reverse-engineering via [[aurum-re]] (Aurum RE; anti-cheat research + driver development; explore anticheat:ricochet) (source: wiki/sources/descriptions/gmh5225__AurumRE.md); IDA CFF deflattening via [[idadeflat]] (angr symbolic exec → recover CFG / patch) (source: wiki/sources/descriptions/za233__IDADeflat.md); IDA deobfuscation plugin work via [[ida-easy-life]] (Python; cheat / IDA Plugins) (source: wiki/sources/descriptions/wINfOG__IDA_Easy_Life.md); Pikabot RC4/AES string decrypt via [[pikabot-deobfuscator]] (Hex-Rays context; current/all functions; cheat / IDA Plugins) (source: wiki/sources/descriptions/threatlabz__pikabot-deobfuscator.md); decompilation-time deobfuscation via [[d810-ng]] (d810 next-gen; Fix OLLVM lane) (source: wiki/sources/descriptions/w00tzenheimer__d810-ng.md); IDA client + Go backend for OBPO deobfuscation via [[obpo-plugin]] (closed core; open plugin; Fix OLLVM) (source: wiki/sources/descriptions/obpo-project__obpo-plugin.md); opaque-predicate detection via [[opaque-predicates-detective]] (invariant-expression / BB-local damage model; Binary Ninja plugin lane) (source: wiki/sources/descriptions/yellowbyte__opaque-predicates-detective.md); obfuscated-region pinpointing via [[obfuscation-detection]] (Binary Ninja plugin; CFF via loop/dominator analysis, insn complexity, n-gram BB reference DB, statistical outliers; batch scripts) (source: wiki/sources/descriptions/mrphrazer__obfuscation_detection.md); Ghidra obfuscated/complex-function triage via [[ghidra-obfuscation-detection]] (Java Ghidra script; heuristic function-body feature extraction; lightweight RE workflow integration; Deatty; source: wiki/sources/descriptions/Deatty__Ghidra-Obfuscation-Detection.md); automated malware-scan platform via [[malicious-code-detection-bugu]] (Go gRPC microservices; Bugu; file upload, hash verification, Protobuf gRPC+HTTP API; gmh5225; Malicious code detection and obfuscation) (source: wiki/sources/descriptions/gmh5225__Malicious-code-detection-bugu.md); obfuscated-code analysis and simplification via [[obfuscation-analysis]] (Binary Ninja plugin; MBA backward-slice + msynth oracle lookup, opaque-predicate dataflow detection, Z3-verified BNIL simplification workflows) (source: wiki/sources/descriptions/mrphrazer__obfuscation_analysis.md); PE32 password packing via [[pe32-password]] (Binary Packer) (source: wiki/sources/descriptions/ytk2128__pe32-password.md); PE X86 compress+encrypt packing via [[packer]] (decompression stub; import/relocation/TLS restore; `[X86]`) (source: wiki/sources/descriptions/longqun__Packer.md); C/C++ PE X86 packing via [[pe-packer]] (Binary Packer / `[X86]`; czs108) (source: wiki/sources/descriptions/czs108__PE-Packer.md); C++/C# modding/hooking/debugging framework [[ares-framework]] (Binary Packer; craids) (source: wiki/sources/descriptions/craids__AresFramework.md); PE X64 packing via [[x64-exe-packer]] (source: wiki/sources/descriptions/xsj3n__x64-EXE-Packer.md); C++ PE X64 packing via [[pepacker]] (asset pipeline; Binary Packer / `[PE X64]`) (source: wiki/sources/descriptions/hid3rx__PEPacker.md); Windows PE X64 compress+encrypt packing via [[atom-pe-packer]] (runtime decompression stub; import/relocation/TLS restore; `[PE X64]`; gmh5225) (source: wiki/sources/descriptions/gmh5225__AtomPePacker.md); tutorial-oriented x64 PE packer/protector via [[hm-pe-packer]] (C++ Visual Studio; wrap/protect Windows binaries at load time; PE structures, packing stubs, protection mechanics study; `[PE X64]`; TheAenema) (source: wiki/sources/descriptions/TheAenema__hm-pe-packer.md); Windows x86 PE protection framework via [[pe-protector]] (ATsahikian; C++; instruction mutation, built-in x86 assembler pipeline, configurable stub logic, binary compression; CMake build + tests; software protection / anti-tamper / packer-style defense research; `[X86]`) (source: wiki/sources/descriptions/ATsahikian__pe-protector.md); polymorphic PE packer/crypter via [[polyengine]] (junk code insertion, instruction substitution, XTEA encryption, RunPE process hollowing, stack spoofing, module stomping, Hell's Gate syscall invocation; CTF and Windows low-level security education; in-memory execution; Anti Cheat → Binary Packer) (source: wiki/sources/descriptions/LongWayHomie__PolyEngine.md); packed/protected module loader framework via [[win32-nebula]] (Lima-X; C++ PoC; loader library + builder utility; SDK-style APIs, dynamic service manager; patch/encrypt/pack pipeline; software protection / loader architecture / anti-analysis techniques in malware and anti-cheat ecosystems; `[PE X64]`) (source: wiki/sources/descriptions/Lima-X__Win32.Nebula.md); C/C++ x86/x64 PE rebuild packer via [[exe-packer]] (Huffman-compressed payload section; custom stub resolves NTDLL/KERNEL32 APIs, decrypts import names, maps sections/relocs/imports, OEP jump; Visual Studio; andrew9382) (source: wiki/sources/descriptions/andrew9382__exe_packer.md); basic Win32 x86 PE packer via [[eronana-packer]] (Eronana; C++ + companion compression; Visual Studio solution + CLI; self-validation extension branch; PE packing / unpacking RE education; `[PE X86]`) (source: wiki/sources/descriptions/Eronana__packer.md) step-by-step from-scratch PE packer tutorial via [[packer-tutorial]] (sections, imports, relocs, compression stub, OEP redirect; educational; `[Packer]`) (source: wiki/sources/descriptions/gmh5225__packer-tutorial.md); encrypted PE loader generator via [[huan]] (per-run keys; payload in new loader section; PE loading study; Anti Cheat → Binary Packer) (source: wiki/sources/descriptions/frkngksl__Huan.md); Rust PE & shellcode packing via [[2pack]] (EXE/DLL + raw shellcode) (source: wiki/sources/descriptions/xM0kht4r__2Pack.md); Rust PE packing via [[oxide]] (`exe-rs` PE parse/rewrite; compressed payload + TLS-callback trampoline stub x86/x64 NASM; extensible obfuscation passes; `[Written by Rust]`) (source: wiki/sources/descriptions/frank2__oxide.md); cross-platform Rust app bundler via [[wrappe]] (executable + resource directory → single self-contained binary; Zstandard; parallel pack/unpack; streaming decompression; metadata/resource transfer; portable one-file deployment; `[Rust]`; Systemcluster) (source: wiki/sources/descriptions/Systemcluster__wrappe.md); shellcode/payload entropy reduction via [[shellcode-entropyfix]] (English-word substitution / padding; AV/EDR entropy-heuristic evasion) (source: wiki/sources/descriptions/gmh5225__shellcode-EntropyFix.md); Caesar-cipher encoding shellcode obfuscation lab via [[shellcode-obfuscation]] (Python obfuscator + C VirtualAlloc loader; baseline comparison loader; AV signature/heuristic/ML detection notes; academic bypass-rate measurements; n1h-nb) (source: wiki/sources/descriptions/n1h-nb__Shellcode-Obfuscation.md); cross-platform multi-cipher shellcode packing and source emit via [[shellcrypt]] (Lavender-exe; Python; AES/ChaCha20/RC4/Salsa20/XOR; chained encode/compress; C/C#/Go/Rust/Nim/Python/PowerShell output; payload packing / loader prototyping) (source: wiki/sources/descriptions/Lavender-exe__Shellcrypt.md); polymorphic shellcode encryption via [[shoggoth]] (asmjit-generated unique position-independent payloads; reflective COFF/PE loaders) (source: wiki/sources/descriptions/frkngksl__Shoggoth.md); PE binary entropy reduction via [[entropy-reducer]] (section padding / data-distribution manipulation; AV/AC packed-exe heuristic evasion) (source: wiki/sources/descriptions/gmh5225__EntropyReducer.md); ELF packing via [[woody-woodpacker]] (outputs “woody”) (source: wiki/sources/descriptions/vsteffen__woody_woodpacker.md); ELF pack/protect via [[elfuck]] (NRV2E / password / anti-debug / SMC) (source: wiki/sources/descriptions/timhsutw__elfuck.md); C/C++ ELF packing via [[m0dern-p4cker]] (`[ELF]`) (source: wiki/sources/descriptions/n4sm__m0dern_p4cker.md); ELF32 `.text` XOR packing via [[elfpacker]] (decrypt stub prepended; ELF header/PHDR/SHDR inject; `[ELF]`) (source: wiki/sources/descriptions/mix64__ELFpacker.md); Linux x86-64 ELF packer/protector via [[kiteshield]] (GunshipPenguin; layered RC4 encryption + custom user-space loader; ptrace keeps only active call-stack functions decrypted; anti-debug checks; C + asm; binary obfuscation / anti-analysis education; `[ELF X64]`) (source: wiki/sources/descriptions/GunshipPenguin__kiteshield.md); educational Go ELF/script packer via [[pakkero]] (89luca89; compression + AES-256-GCM encryption + payload padding + obfuscation; in-memory execution; optional UPX with metadata mutation; anti-reversing / software protection tradeoff study; `[ELF]`) (source: wiki/sources/descriptions/89luca89__pakkero.md); ELF `.text` RC4 packing via [[elfcrypt]] (embedded decrypt stub; `mprotect` + decrypt at runtime; mmap/section headers; `[ELF]` RC4) (source: wiki/sources/descriptions/droberson__ELFcrypt.md); Linux ELF packing via [[papaw]] (LZMA/zstd/miniz compression; statically-linked ELF; self-replacement on disk; optional anti-debug; papawify/unpapawify; `[ELF]` LZMA) (source: wiki/sources/descriptions/dimkr__papaw.md); cross-arch ELF protection via [[midgetpack]] (password + Curve25519 challenge-response; AES-128/HMAC-SHA256; Linux/FreeBSD x86/x86-64/ARM; controlled-assessment hardening; `[ELF]`) (source: wiki/sources/descriptions/arisada__midgetpack.md); simple ELF runtime dropper packer via [[ward]] (Go/C; runtime unpack; `[ELF]`) (source: wiki/sources/descriptions/ex0dus-0x__ward.md); ARM64/AArch64 ELF pack + in-memory loader via [[harmless]] (encrypt; custom stub; fileless `memfd_create`; Linux `[ELF]`) (source: wiki/sources/descriptions/litemars__hARMless.md); ELF anti-reversing techniques via [[embuche]] (collection to hinder reversers; Binary Packer / `[ELF]`) (source: wiki/sources/descriptions/magnussen7__Embuche.md); PE-focused packing via [[petoy]] (C/C++ + JS; Binary Packer / `[PE]`) (source: wiki/sources/descriptions/r0ngwe1__petoy.md); PE debugging/packing via [[greym]] (C/C++; Binary Packer / `[PE]`) (source: wiki/sources/descriptions/greyb1t__GreyM.md); PE/PE+ multi-file linking via [[shibari]] (C++/C modding; merge into one image) (source: wiki/sources/descriptions/jnastarot__shibari.md); C++/C PE packing via [[pezor]] (hooking-oriented Binary Packer surface) (source: wiki/sources/descriptions/phra__PEzor.md); C# PE XOR cipher packing via [[xorpacker]] (all PE; debugging-oriented Binary Packer) (source: wiki/sources/descriptions/nqntmqmqmb__xorPacker.md); C++ Huffman+XOR PE pack/unpack via [[hxor-packer]] (self-unpacking stub executes payload from memory; compression/encryption/both CLI; PE internals / runtime loading study; `[PE XOR]`) (source: wiki/sources/descriptions/akuafif__hXOR-Packer.md); pure C ELF/PE packer via [[silent-packer]] (section insertion, code caves, text-section infection; XOR/AES; loader + asm runtime unpack stub; RE practice / obfuscation / defensive packed-binary research; Anti Cheat → Binary Packer) (source: wiki/sources/descriptions/SilentVoid13__Silent_Packer.md); simple C++ PE packer via [[pepacker-samlarenn]] (`.text` XOR encrypt + appended decrypt stub; custom PE section parse/rewrite; packer development / basic obfuscation RE; Anti Cheat → Binary Packer) (source: wiki/sources/descriptions/SamLarenN__PePacker.md); Windows PE packer/crypter via [[evader]] (KooroshRZ; C++ packer + unpack stub; configurable key size/keyspace; runtime key recovery + in-memory payload execution; payload obfuscation, resource embedding, staged decryption; packer development / evasion-focused RE; Anti Cheat → Binary Packer `[PE]`) (source: wiki/sources/descriptions/KooroshRZ__Evader.md); Windows x64 PE packer via [[fatpack]] (Fatmike-GH; C++ LZMA compression + custom loader stub; resource/section packing; icon/manifest; relocation/import/TLS; helper tooling for stub embed + post-build integration; executable protection research / manual-map loader experimentation; Anti Cheat → Binary Packer) (source: wiki/sources/descriptions/Fatmike-GH__Fatpack.md); Windows GUI PE crypter/packer via [[encryptix-crypter]] (Ezmatehw; C# .NET Framework 4.8 WinForms; AES/XOR encrypt + configurable stub template; RegAsm/RegSvcs/MSBuild LOLBin injection; optional persistence, anti-VM, sleep delays, metadata cloning; dnlib obfuscator + build-time stub compile; KeyAuth license gating; crypter construction / payload packing / evasion technique study; Anti Cheat → Binary Packer) (source: wiki/sources/descriptions/Ezmatehw__Encryptix-Crypter.md); C# .NET PE packing via [[netcrypt]] (encrypted/compressed managed assembly in loader stub; CLR-only decrypt/decompress/invoke; near-zero delay; SimplePacker GUI; Anti Cheat → Binary Packer / `.NET`) (source: wiki/sources/descriptions/friedkiwi__netcrypt.md); .NET assembly packing via [[origami]] (compressed managed payload in PE debug directory or `.origami` section; RelocLoader runtime decompress/execute; PE format abuse; Anti Cheat → Binary Packer / `.NET`) (source: wiki/sources/descriptions/dr4k0nia__Origami.md); minimal PE manual-map packer/crypter via [[tinyload]] (custom VM stub; no standard loader APIs; Binary Packer) (source: wiki/sources/descriptions/iamsopotatoe-coder__TinyLoad.md); LLVM pass-plugin obfuscation/anti-tamper via [[kagura]] (CFF/bogus CFG, string/data encryption, anti-debug runtime; mobile/desktop/Wasm) (source: wiki/sources/descriptions/ykus4__kagura.md); lightweight LLVM IR pass obfuscator via [[the-poor-mans-obfuscator]] (insn sub / CFF / string encrypt; ELF/Mach-O) (source: wiki/sources/descriptions/romainthomas__the-poor-mans-obfuscator.md); security-oriented C23 compiler toolchain via [[neverc]] (NeverSight; custom LLVM backend; compile-time string encryption + DynCode PIC runtime codegen; plugin API across 130+ phases; PE/ELF/Mach-O; user-mode, Windows kernel driver, and Android kernel module examples; offensive toolchain / obfuscation-engine research) (source: wiki/sources/descriptions/NeverSight__NeverC.md); LLVM 18 New Pass Manager plugin for manually mapped Windows DLLs via [[dll-ollvm]] (LLVMObfuscationx; insn sub / bogus CFG / CFF / global-ctor trim; tess-obf preset; per-function skip/protect/force markers; manual-map injection hardening vs AC allocation/table pattern scans; R7flex) (source: wiki/sources/descriptions/R7flex__dll-ollvm.md); Rust LLVM pass plugin [[amice]] (fuqiuluo; `clang -fpass-plugin`; string encrypt / CFF / bogus CFG / MBA / indirect calls+branches / BB split-shuffle / instruction-level VMP; llvm-plugin-rs + inkwell; LLVM 11–22; Android NDK; C/C++/Rust IR) (source: wiki/sources/descriptions/fuqiuluo__amice.md); out-of-tree LLVM pass-plugin obfuscator via [[obscura]] (ObjC metadata / anti-debug·hook / string encrypt / CFF / indirect branch; Clang/Swift; Darwin) (source: wiki/sources/descriptions/nkhmelni__Obscura.md); Swift iOS identifier rename via [[swiftshield]] (SourceKit; irreversible encrypted names; crash-log conversion map) (source: wiki/sources/descriptions/rockbruno__swiftshield.md); Obfuscation Engine research via [[wprotect]] (C/C++ WProtect; xiaoweime) (source: wiki/sources/descriptions/xiaoweime__WProtect.md); Windows PE code virtualizer via [[dedf-wprotect]] (DeDf; disassemble→VM bytecode, jump stubs, new PE section; AsmJit + udis86; software protection / VM anti-tamper study) (source: wiki/sources/descriptions/DeDf__WProtect.md); WProtect SDK generation via [[wprotectsdk]] (C/C++ SDK integration tooling) (source: wiki/sources/descriptions/jokerNi__WProtectSDK.md); C/C++ obfuscation engine via [[furikuri]] (jnastarot PE protect/obfuscate research; Anti Cheat → Obfuscation Engine) (source: wiki/sources/descriptions/jnastarot__furikuri.md); PE relocation attack research via [[relocbonus]] (Attack Reloc; DEF CON 26; AC / obfuscation-engine study) (source: wiki/sources/descriptions/nickcano__RelocBonus.md); ELF JMPREL/GOT relocation obfuscation via [[rel-fuscate]] (Python toolchain; manipulates jmprel `r_offset` so static disassemblers/decompilers show wrong import names while runtime resolves correctly; partial RELRO lazy binding; caprinux) (source: wiki/sources/descriptions/caprinux__rel-fuscate.md); minimalistic .NET assembly obfuscation via [[obfuscar]] (rename overload / string hide / BAML; NuGet/global tool) (source: wiki/sources/descriptions/obfuscar__obfuscar.md); open-source .NET protector via [[confuserex]] (Confuser successor; managed Binary Packer / CLR protection lane) (source: wiki/sources/descriptions/mkaring__ConfuserEx.md); ConfuserEx deobfuscation via [[confuserex-idapython]] (govcert-ch; Python IDAPython script; cheat / IDA Plugins) (source: wiki/sources/descriptions/govcert-ch__ConfuserEx_IDAPython.md); .NET obfuscation technique demos via [[obfuscation-methods]] (C#/dnlib; CFF / anti-dump / anti-de4dot·dnSpy / rename / encrypt / junk / invalid metadata) (source: wiki/sources/descriptions/nak0823__ObfuscationMethods.md); .NET await-based control-flow obfuscation via [[awaitfuscator]] (bin2bin; long await expression chains + custom awaiters; decompiler CFG recovery PoC; Washi1337) (source: wiki/sources/descriptions/Washi1337__AwaitFuscator.md); post-compile x64 PE obfuscation via [[alcatraz]] (mutation / CFF / anti-disasm / IAT; Zydis + AsmJit) (source: wiki/sources/descriptions/weak1337__Alcatraz.md) (source: wiki/sources/descriptions/gmh5225__Alcatraz.md); PE import-table call-target obfuscation via [[call-obfuscator]] (INI-mapped decoy IAT + load-time shellcode resolver via PEB→Ldr export walk; Call Obfuscation; d35ha) (source: wiki/sources/descriptions/d35ha__CallObfuscator.md); PE same-DLL IAT entry swap + TLS pre-main restore via [[iat-obfuscation]] (MahmoudZohdy; C++; static API-sequence obfuscation; import-hiding educational research; README IAT Obfuscation) (source: wiki/sources/descriptions/MahmoudZohdy__IAT-Obfuscation.md); hash-based API/string constant resolution via [[hashdb-ida]] (OALabs; Python IDA plugin; HashDB lookup service; single/bulk module import; XOR-aware matching; hash-algorithm hunt + enum annotation; cheat / IDA Plugins) (source: wiki/sources/descriptions/OALabs__hashdb-ida.md); Win32/x64 PE obfuscation framework via [[nb-obfuscator]] (Capstone + udis86 insn analysis; polymorphic stub / dead-code injection; PSC-Engine; Obfuscation Engine; cxxrev0to1dev) (source: wiki/sources/descriptions/cxxrev0to1dev__nb_obfuscator.md); post-compile x64 PE multi-pass obfuscation via [[obfuscator]] (CFF / junk / insn mutation / import obfuscation / anti-disasm; disassemble→reassemble; es3n1n; AC Obfuscation Engine) (source: wiki/sources/descriptions/es3n1n__obfuscator.md); x86 PE instruction-expansion obfuscator [[perses]] (selected-instruction → larger semantic-equivalent sequences) (source: wiki/sources/descriptions/mike1k__perses.md); x32 PE full-rebuild mutator [[milfuscator]] (Zydis + AsmJit; CS:GO P2C-inspired) (source: wiki/sources/descriptions/nelfo__Milfuscator.md); dual-mode Windows protector [[vxlang-page]] (virtualization / flatten / anti-tamper; PE/DLL/SYS + .NET) (source: wiki/sources/descriptions/vxlang__vxlang-page.md); bin2bin x86-64 PE code virtualizer [[nocturne]] (SDK markers / 30+ polymorphic VM handlers / junk / PDB-guided rewrite) (source: wiki/sources/descriptions/nodiuus__nocturne.md); x86 code virtualizer [[phantasm-x86-virtualizer]] (static-link or manual VM-runtime embed; AC Obfuscation Engine / `[VM]`) (source: wiki/sources/descriptions/layerfsd__phantasm-x86-virtualizer.md); RISC-V payload-obfuscation workshop [[riscy-workshop]] (custom **riscvm** VM interpreter + llvm-mingw C→RISC-V toolchain + liveness/instruction-mutation obfuscator; shellcode / transpilation / anti-analysis exercises) (source: wiki/sources/descriptions/mrexodia__RiscyWorkshop.md); bin2bin x64 PE obfuscator (no new section) [[binprotect]] (custom asm/disasm; BB-level rewrite; exception dirs / RTTI / relocs / jump tables) (source: wiki/sources/descriptions/noahware__binprotect.md); x86 binary rewriting / obfuscation via [[stitch]] (function relocation, global ref patching, branch handling; CMake examples) (source: wiki/sources/descriptions/badhive__stitch.md); Linux x86-64 ELF static rewrite via [[e9patch]] (GJDuck; instruction punning + eviction; jumps/trampolines/instrumentation at any instruction without reassembly; static instrumentation / RE) (source: wiki/sources/descriptions/GJDuck__e9patch.md); x86 PE bin2bin protector/obfuscator [[ryujin]] (Bin2Bin transformation research; AC Obfuscation Engine / `[X86 PE BIN2BIN]`) (source: wiki/sources/descriptions/keowu__Ryujin.md); C++17 compile-time+runtime obfuscation library [[obfusk8]] (logic/data protection) (source: wiki/sources/descriptions/x86byte__Obfusk8.md); compile-time AES-128 / S-box string encryption via [[sbox]] (constexpr macros; Obfusk8 spin-off) (source: wiki/sources/descriptions/x86byte__sbox.md); canonical C++17 compile-time string encryption via [[xorstr]] (JustasMasiulis; SSE/AVX vectorized inline decrypt; compile-time keys; keeps string data out of normal read-only sections; AC String Crypter) (source: wiki/sources/descriptions/JustasMasiulis__xorstr.md); header-only runtime lazy import via [[lazy-importer]] (JustasMasiulis; avoids static IAT + plaintext export strings; safe/cached/forwarded resolve modes; per-build hash randomization; RE-resistant tooling) (source: wiki/sources/descriptions/JustasMasiulis__lazy_importer.md); SIMD compile-time string/integer xorstr via [[mystic-xorstr]] (C++17 header-only; AVX/SSE/NEON decrypt + junk/opaque-predicate decompiler clutter) (source: wiki/sources/descriptions/wufhex__Mystic-xorstr.md); C++20 header-only compile-time variable obfuscation via [[obfuscxx]] (AVX2/SSE2/NEON decrypt; MSVC+WDM/LLVM/GCC; x86-64/ARM; AC Encrypt Variable) (source: wiki/sources/descriptions/nevergiveup-c__obfuscxx.md); runtime polymorphic in-memory variable obfuscation via [[polymorphic-engine]] (Nou4r; C++; stack/heap transforms; optional SIMD; LLVM/Clang-primary; software protection / anti-analysis research) (source: wiki/sources/descriptions/Nou4r__Polymorphic-Engine.md); compile-time XOR string crypter via [[skcrypter]] (header-only constexpr/template; String Crypter) (source: wiki/sources/descriptions/skadro-official__skCrypter.md); header-only C++14 compile-time string literal obfuscation via [[obfuscate]] (constexpr encrypt + randomized keys; macro API; String Crypter) (source: wiki/sources/descriptions/adamyaxley__Obfuscate.md); header-only portable C++14 compile-time obfuscation via [[obfusheader-h]] (string/constant encryption, import/call hiding, control-flow mutation, anti-decompiler passes; Windows/Unix; AC Obfuscation Engine) (source: wiki/sources/descriptions/ac3ss0r__obfusheader.h.md); macro-only C compile-time obfuscation via [[obfus-h]] (DosX-dev; TCC-oriented Windows x86/x64; function-call obfuscation, control-flow mutation, string hiding, anti-debug, anti-decompilation, fake signatures, optional virtualized math; preprocessor-flag toggles; AC Obfuscation Engine / Compile Time) (source: wiki/sources/descriptions/DosX-dev__obfus.h.md); string crypter via [[xorlit]] (single-argument default key `xorlit::seed`; AC Compile Time / String Crypter) (source: wiki/sources/descriptions/igozdev__xorlit.md); C++17 XOR data obfuscation framework via [[xordata]] (constants, variables, and strings; compile-time and runtime-style XOR transforms; helper structures; software hardening / anti-analysis experiments; AC Compile Time / Obfuscation Engine) (source: wiki/sources/descriptions/Sherman0236__XorData.md); Zig compile-time static string obfuscation via [[static-string-obfuscation]] (build-time randomized XOR keys; stripped x86_64 Windows targets; lightweight runtime decrypt; RE resistance / anti-analysis hardening; AC String Crypter) (source: wiki/sources/descriptions/Reijaff__static_string_obfuscation.md); C++23 header-only compile-time PIC string/array obfuscation via [[malstring]] (ManulMap; template metaprogramming XOR stack/call strings and callable arrays; per-string keys; decrypt-on-use; concise source API; static analysis resistance; AC String Crypter / Compile Time) (source: wiki/sources/descriptions/ManulMap__malstring.md); Rust compile-time string obfuscation via [[obfstr]] (CasualX; `obfstr!`/`obfcstr!`/`obfbytes!`/`wide!`/`random!` macros; embed obfuscated constants with local runtime decode; lightweight integration and reproducible build-time randomness; reduces obvious plaintext artifacts; AC String Crypter) (source: wiki/sources/descriptions/CasualX__obfstr.md); C++20 compile-time string/number obfuscation via [[crystr]] (XOR keys from compile-time math, timestamps, and counters; inline or virtual decrypt; per-char/per-value key variation; AC String Crypter) (source: wiki/sources/descriptions/android1337__crystr.md); C++20 header-only compile-time string obfuscation via [[vm-str-hpp]] (Mowokuma; compile-time obfuscation bytecode schema + stack-based VM runtime reconstruct; narrow/wide string macros; keeps plaintext out of static program data; software hardening / RE resistance; AC String Crypter) (source: wiki/sources/descriptions/Mowokuma__vm_str.hpp.md); C++14+ compile-time call obfuscation via [[crycall]] (lambda/virtual-dispatch wrappers hide real callees and argument flow; AC Compile Time) (source: wiki/sources/descriptions/android1337__crycall.md); header-only MSVC x64 Hex-Rays decompiler breakage via [[brkida]] (compile-time stubs + crafted stack-access patterns force decompiler failure on protected functions; anti-tamper / software protection research) (source: wiki/sources/descriptions/android1337__brkida.md); platform-agnostic compile-time any-constant encryption via [[oxorany]] (obfuscated literals at build; C/C++; AC Compile Time) (source: wiki/sources/descriptions/llxiaoyuan__oxorany.md); constexpr SHA-2/SHA-3 hashing via [[cthash]] (`cthash::literals` hash_value suffixes; AC Compile Time) (source: wiki/sources/descriptions/hanickadot__cthash.md); compile-time regular expressions via [[compile-time-regular-expressions]] (CTRE; cmake `ctre` target; AC Compile Time) (source: wiki/sources/descriptions/hanickadot__compile-time-regular-expressions.md); compile-time random constants via [[compile-time-random]] (Deniskore; C++11 constexpr FNV/Murmur3-style hashing; 32/64-bit macros; no runtime RNG; AC Compile Time) (source: wiki/sources/descriptions/Deniskore__CompileTimeRandom.md); Go string crypter via [[obfuscatxor]] (generates encrypted string variables for Go code; AC Compile Time / String Crypter) (source: wiki/sources/descriptions/redskal__obfuscatxor.md); Go build-time obfuscator via [[garble]] (wraps `cmd/go`; identifier/package/path hash rename, metadata strip, optional literal obfuscation, tiny mode, experimental CFF; deterministic; `garble reverse` stack-trace mapping; AC Obfuscation Engine) (source: wiki/sources/descriptions/burrowers__garble.md); C++20 fold-based API hammering (loop-free call bloat) via [[bloatedhammer]] (AC Compile Time) (source: wiki/sources/descriptions/rad9800__BloatedHammer.md); Encrypt Variable scalar header-only via [[encrypted-value]] (C++ in-app scalar encrypt) (source: wiki/sources/descriptions/serge-14__encrypted_value.md); XOR float encrypt sample via [[xor-float]] (C++ XOR-based float/value hiding; AC Encrypt Variable) (source: wiki/sources/descriptions/obama-gaming__xor-float.md); single-header pointer/value encryption via [[xv]] (C++ `xval`; per-variable algorithm randomization; AC Encrypt Variable) (source: wiki/sources/descriptions/emlinhax__xv.md); homomorphic encrypted computation via [[e3]] (Encrypt-Everything-Everywhere; C++ FHE wrappers + encrypted variable types/operators; MoMA Lab; protected game-state research) (source: wiki/sources/descriptions/momalab__e3.md); source+binary C++ obfuscation experiments via [[obfcoder]] (CMake/OpenSSL; before/after demos) (source: wiki/sources/descriptions/ssyuqixe__obfCoder.md); JavaScript/Node.js source obfuscation via [[javascript-obfuscator]] (TypeScript; CLI + Node API; CFF / string arrays / self-defending / domain lock; browser games + client logic) (source: wiki/sources/descriptions/javascript-obfuscator__javascript-obfuscator.md); Node.js runtime API tracing for obfuscated malware/scripts via [[nodejs-tracer]] (CheckPointSW; preload instrumentation; log core module calls, spoof anti-analysis checks, preserve dropped files; lightweight dynamic JS behavior analysis; Simple Node.jstracer) (source: wiki/sources/descriptions/CheckPointSW__Nodejs-Tracer.md); Rust source-level obfuscation via [[rust-obfuscator]] (automatic proc-macro inserter; `cryptify` compile-time string encryption + `labyrinth_macros` CFF + symbol rename; static-analysis hardening research) (source: wiki/sources/descriptions/dronavallipranav__rust-obfuscator.md); Python script obfuscation via [[pyarmor]] (CLI; irreversible rename / selected-function C conversion; machine binding + expiry; optional Themida on Windows; Python 2/3; cross-platform) (source: wiki/sources/descriptions/dashingsoft__pyarmor.md); AST-based Python obfuscation via [[pyobfus]] (zhurong2020; cross-file rename, literal encoding, import rewrite, CFF; YAML + FastAPI/Django/Flask presets; reverse stack-trace mapping, JSON CLI, MCP server, VS Code extension; CPython 3.9–3.14; game tooling / commercial IP hardening) (source: wiki/sources/descriptions/zhurong2020__pyobfus.md); Python deobfuscation and analysis via [[de4py]] (Fadi002; open-source GUI + CLI framework; multi-obfuscator support; packed-artifact analyzers, hash/string inspection, behavior monitoring, process-integrated execution; PySide6 + native Windows injection/hook helpers; malware/RE workflows) (source: wiki/sources/descriptions/Fadi002__de4py.md); modular multi-format unpack/deobfuscate/decompile via [[disrobe]] (1-3-7; Rust; PE packers, PyArmor/PyInstaller, APK, WASM, JVM/.NET/Go/JS, archives; Ghidra workflow + Python/TypeScript bindings; benchmark corpora; source: wiki/sources/descriptions/1-3-7__disrobe.md); Luau/Lua VM script obfuscation via [[lua-obfuscator-clyde-protection]] (TypeScript AST + stack/register VM; Roblox-oriented) (source: wiki/sources/descriptions/sfr-development__Lua-Obfuscator-Clyde-Protection.md); Fix VMP / VTIL demos such as [[vmdevirt-vtil]] (broken VTIL compile path; jmp-around-`vmenter` IDA display idea) (source: wiki/sources/descriptions/xtremegamer1__vmdevirt-vtil.md); Python VMProtect symbolic-exec deobf via [[novmpy]] (handler-chain semantics → original insn reconstruct; Triton) (source: wiki/sources/descriptions/wallds__NoVmpy.md); multi-engine VM detection/analysis via [[vmdragonslayer]] (DTT / SE / pattern classification / ML; Cheat RE Tools) (source: wiki/sources/descriptions/poppopjmp__VMDragonSlayer.md); Python VMProtect trace/symbolic-exec handler recovery via [[rumba]] (virtual opcode handlers → original CFG/semantics; MBA-tagged README) (source: wiki/sources/descriptions/thalium__rumba.md); general-purpose execution-trace view/edit/analyze via [[execution-trace-viewer]] (originally for obfuscated-code RE; cheat / debugging lane) (source: wiki/sources/descriptions/teemu-l__execution-trace-viewer.md); .NET Harmony instrumentation of VMProtect-virtualized methods via [[vmunprotect]] (trace invokes / params; anti-debug bypass; VMP 3.6.0) (source: wiki/sources/descriptions/void-stack__VMUnprotect.md); dynamic .NET VMProtect unpack/dump via [[vmunprotect-dumper]] (force static ctor restore → AsmResolver PE dump; VMP 3.7.0) (source: wiki/sources/descriptions/void-stack__VMUnprotect.Dumper.md); native PE VMProtect unpack via [[vmpunpacker]] (C++/Python; LZMA decompress → original sections/IAT; Unpacker) (source: wiki/sources/descriptions/oureveryday__VMPUnpacker.md); emulation-based VMProtect/packer unpack via [[vmpunpack]] (Python 3.8+ stdlib; patched sogen emulator to OEP; PE rebuild + IOC extract; no devirt; Unpacker) (source: wiki/sources/descriptions/milk-analyzer__vmpunpack.md); static Go VMProtect PE unpack/rebuild via [[vmpstatic]] (VMP 1.x–3.x; Fix VMP / Unpacker) (source: wiki/sources/descriptions/notsnakesilent__VMPStatic.md); emulation-based generic PE unpack via [[xvolkolak]] (XEmulUnpacker / XEmulator single-step to OEP; Qt GUI + CLI; 21 packer-specific unpackers incl. UPX/ASPack/MPRESS; Unpacker) (source: wiki/sources/descriptions/horsicq__XVolkolak.md); modular Python PE/ELF packer detection + unpack pipeline via [[unpacker]] (anpa1200; section/entropy/heuristic/signature ID; UPX native + Unicorn/Unipacker for 32-bit ASPack/Themida/VMProtect + Qiling for 64-bit VMProtect; multi-layer re-detect + PE rebuild; CLI detect→unpack→validate; Unpacker) (source: wiki/sources/descriptions/anpa1200__Unpacker.md); kernel-mode malware sample unpack via [[mal-unpack-drv]] (experimental test-signed driver; VM-only; hasherezade Sample Unpacker) (source: wiki/sources/descriptions/hasherezade__mal_unpack_drv.md); live-process VMP 3.x import-protection fix via [[vmpimportfixer]] (Unicorn emulation of near-call stubs → real import addresses; Zydis + pepp; x86/x64 including WoW64 fix from x64; Fix VMP) (source: wiki/sources/descriptions/mike1k__VMPImportFixer.md); title-specific WoW client IAT repair via [[wow-iat-fix]] (C/C++; plugin/modding/SDK generation; cheat / game:wow) (source: wiki/sources/descriptions/helloobaby__wow-IAT-fix.md); title-specific WoW client module unpacker via [[dumpwow]] (gmh5225 fork; C++/Python; namreeb/dumpwow lineage; cheat / game:wow) (source: wiki/sources/descriptions/gmh5225__dumpwow.md); Blizzard WoW anti-dump [[x64dbg]] plugin via [[wowdumpfix]] (adde88; C/C++; removes anti-dumping obstacles from protected game processes; Scylla import/dump repair; debugger attach breakpoint restore; cheat / game:wow / Dump Fix) (source: wiki/sources/descriptions/adde88__WoWDumpFix.md); WoW auto-fishing automation via [[wow-wowautofishing]] (C/C++; rendering / audio / memory analysis; cheat / game:wow; gmh5225) (source: wiki/sources/descriptions/gmh5225__WOW-WowAutoFishing.md); open-source WoW hack via [[ohack]] (fail46; C++; memory analysis; cheat / game:wow) (source: wiki/sources/descriptions/fail46__OHack.md); curated Rust WoW private-server ecosystem resources via [[awesome-wow-rust]] (arlyon; server implementations / protocol + file-format libraries / renderers + asset viewers; auth / networking / data formats; cheat / game:wow) (source: wiki/sources/descriptions/arlyon__awesome-wow-rust.md); title-specific Overwatch IAT repair via [[overwatch-iat-fixer]] (gmh5225; obfuscated/encrypted import reconstruction for disassembler analysis; cheat / game:overwatch) (source: wiki/sources/descriptions/gmh5225__overwatch-iat-fixer.md); title-specific Overwatch protected-binary unpack/decrypt tooling via [[ow-unpack]] (Midi12; reuploaded C++; decryption/helper modules + assembly-assisted unpacking; binary analysis / protected-game unpack study; cheat / game:overwatch) (source: wiki/sources/descriptions/Midi12__ow_unpack.md); Themida / WinLicense 3.x VM research via [[themida-research]] (`VM_CONTEXT` / handlers / bytecode dispatch; Triton lifting sketches) (source: wiki/sources/descriptions/stuxnet147__Themida-Research.md); Themida IDA plugin / Fix Themida via [[tde]] (devirtualization engine) (source: wiki/sources/descriptions/sodareverse__TDE.md); original Pascal Themida auto-unpacker via [[magicmida]] (Hendi48; custom user-mode debugger; 32/64-bit PE + .NET dump; import rebuild + section restore; BeaEngine; GUI + `/unpack` CLI; ScyllaHide settings; Fix Themida) (source: wiki/sources/descriptions/Hendi48__Magicmida.md); automatic Themida v1/v2/v3 unpack via [[magicmida-rs]] (Rust Win32 Debug API; OEP + IAT rebuild; optional ScyllaHide; verify mode; Fix Themida) (source: wiki/sources/descriptions/guoxing2024__magicmida-rs.md); in-debugger mutation-assembly cleanup via [[codecleaner]] (x64dbg plugin; Capstone + AsmJit; strips redundant NOPs and no-op register moves from disassembly; Themida mutation assembly; Steesha) (source: wiki/sources/descriptions/Steesha__CodeCleaner.md) - **Game engines:** [[il2cpp]] dumps (canonical [[il2cppdumper]]; Perfare; C#; ELF/Mach-O/PE/NSO/WASM metadata + dummy DLLs + IDA/Ghidra/BN scripts; [Il2Cpp Dump]) (source: wiki/sources/descriptions/Perfare__Il2CppDumper.md), cross-platform [[il2cpp-inspector]] (C# metadata extract + IDA/Ghidra/BN scripts; [Il2Cpp Dump]) (source: wiki/sources/descriptions/djkaty__Il2CppInspector.md), automated Facepunch Rust offset pipelines such as [[oxide-dumper]] (LabGuy94; Python; SteamCMD + [[il2cppdumper]] + GitHub Actions; reusable C++ header export; `[Auto Dump]`; repeatable extraction for tooling maintainers tracking frequent game updates) (source: wiki/sources/descriptions/LabGuy94__OxideDumper.md) and [[rust-auto-dumper]] (Akandesh; C++; Steam build-ID watch + dump scripts; regex parse of `dump.cs`/script data → JSON, C++ headers, C# constants incl. encrypted fields; `[Auto Dump]`; multi-format synchronized offset exports) (source: wiki/sources/descriptions/Akandesh__rust-auto-dumper.md), CS:GO build-watch auto-dump pipelines such as [[csgo-auto-dumper]] (Akandesh; C++; steamcmd + build-ID polling; triggers local dumper + scripts on new CS:GO builds; `[Auto Dump]`; keeps Source 1 offset artifacts current) (source: wiki/sources/descriptions/Akandesh__csgo_auto_dumper.md), Unreal SDK generators such as [[ue4genny]] (cursey; runtime UE4 reflection scan → C++ SDK headers with class hierarchies, property offsets, and function signatures; [SDK Generator]) (source: wiki/sources/descriptions/cursey__ue4genny.md), multi-format runtime reflection toolkit [[zircon-ue-dumper]] (TheHolyOneZ; C++20; UE 4.22–5.7 auto-detect; internal inject, external read-only attach, minidump, or static PE; C++ SDK, USMAP, IDA/Ghidra/BN types, Frida bindings, Python stubs; [SDK Dump]) (source: wiki/sources/descriptions/TheHolyOneZ__Zircon-UE-Dumper.md), live UE4/UE5 scripting/modding framework [[re-ue4ss]] (Lua + C++ mod APIs, blueprint loading, live property inspection/editing, SDK/header dumpers; runtime hooks; [Re-Host of Unreal Engine 4/5 Scripting System]; UE4SS-RE) (source: wiki/sources/descriptions/UE4SS-RE__RE-UE4SS.md), title-specific Arena Breakout Infinite UE4.26 SDK dumps such as [[ue426-abinfinite-win64-shipping]] (cra0; C/C++; pre-generated UE4.26 headers for ABInfinite-Win64-Shipping; [SDK]) (source: wiki/sources/descriptions/cra0__UE426_ABInfinite-Win64-Shipping.md), general-purpose C++ SDK codegen libraries such as [[sdkgenny]] (cursey; third-party app SDK generation; PEGTL parser optional; cheat / sdk codegen) (source: wiki/sources/descriptions/cursey__sdkgenny.md), interactive live-memory struct reconstruction via [[regenny]] (cursey; C++; real-time memory viewer mapping raw bytes to user-defined layouts—nested structs, arrays, pointers, enums, bitfields—for iterative SDK-oriented RE; [Reconstruct structures and generate header files]) (source: wiki/sources/descriptions/cursey__regenny.md), profiler-driven UE4 source architecture notes such as [[unreal-source-explained]] (donaldwuid; init/game loop/task graph/render pipeline via profiler call stacks; Game Engine / Unreal guide) (source: wiki/sources/descriptions/donaldwuid__unreal_source_explained.md), public UE4 game source drops such as [[warriorb]] (NotYetGames; shipped action-platformer C++ + engine config without full asset rebuild; production Unreal implementation patterns; Game Engine / source) (source: wiki/sources/descriptions/NotYetGames__WarriOrb.md), native PE/pattern workflows; classic SNES title reimplementations such as [[zelda3]] (Zelda 3; playable end-to-end) give reverse engineers a readable remake surface in the Game Develop / source lane. (source: wiki/sources/descriptions/snesrev__zelda3.md); reverse-engineered Diablo 1 retail Windows binaries such as [[devilution]] (MSVC 4.20-era C/C++; drlg_l1–l4, rendering, spell/item/monster tables, multiplayer, save/load, Storm MPQ/DiabloUI/Storm DLL; Game Develop / source) extend that lane for late-1990s Windows RPG decompilation study. (source: wiki/sources/descriptions/galaxyhaxz__devilution.md); clean-room classic ARPG engine stacks such as [[abyss-engine]] (C; SDL2/FFmpeg; MPQ assets, scene/render/audio decoders; no original proprietary code reuse; transparent modding/legacy-behavior foundation; `[ARPG]`) (source: wiki/sources/descriptions/AbyssEngine__AbyssEngine.md); classic DOOM idTech 1 source ports such as [[doomretro]] (C/SDL2; widescreen/uncapped FPS/lighting/filtering; WAD/DeHackEd/BOOM compatibility; Game Develop / source) extend that lane for idTech 1 engine modernization study. (source: wiki/sources/descriptions/bradharding__doomretro.md); header-only stdlib-free [[pure-doom]] (Daivuk; pure C; 32/64-bit; minimal embed model; compact retro core for constrained hosts; Game Develop / source) (source: wiki/sources/descriptions/Daivuk__PureDOOM.md); Retro Engine v5/v5U decompilations such as [[rsdkv5-decompilation]] (RSDKModding; Sonic Mania and other Retro Engine titles; cross-platform; modding API; multiple audio/rendering backends; legacy engine compatibility; Game Engine / source) extend that lane for proprietary 2D engine decompilation study. (source: wiki/sources/descriptions/RSDKModding__RSDKv5-Decompilation.md); WIP Barnyard + TOSHI 2.0 decompilations such as [[openbarnyard]] (InfiniteC0re; C++ reimplementation on reconstructed Toshi engine; DirectX 8/OpenGL via Premake; RE progress tracking vs original binary addresses; Detours SDK hooks, mod loading, ImGui debug, sample graphics/speedrun mods; Ghidra RE workflow; Game Engine / source) extend that lane for legacy Toshi-based title decompilation study. (source: wiki/sources/descriptions/InfiniteC0re__OpenBarnyard.md); modder-friendly **GZDoom** idTech 1 forks such as [[gzdoom]] (C/C++; OpenGL/Vulkan rendering; ZScript/mod scripting; gameplay extensions and cross-platform engine development; GPLv3; Game Develop / source) extend that lane for modern Doom modding and runtime-architecture study. (source: wiki/sources/descriptions/ZDoom__gzdoom.md); [[uzdoom]] (GZDoom continuation; high-resolution rendering, dynamic lighting, 3D floors, mod ecosystem; OpenGL/Vulkan; CMake cross-platform C/C++; Game Develop / source) continues that lineage. (source: wiki/sources/descriptions/UZDoom__UZDoom.md); open-source Croteam Serious Engine trees such as [[serious-engine-base]] (classic Serious Sam generation; C/C++; render/world/entity/network/audio/scripting subsystems; Visual Studio + Ogg/Vorbis; engine programmers / modders / legacy FPS RE; Game Engine / source) extend that classic FPS engine-source lane. (source: wiki/sources/descriptions/Serious-Engine__Base.md); fiber-based C++ job schedulers such as [[task-scheduler]] (work-stealing, task grouping, Windows/POSIX; parallel game-logic/render pipelines; Game Engine / Task Scheduler) (source: wiki/sources/descriptions/SergeyMakeev__TaskScheduler.md); GTA: San Andreas 1.0 US binary-compatible C++ reimplementations such as [[gta-reversed-modern]] (decompiled/rewritten functions compiled beside the original EXE; rendering/physics/vehicles/scripting/audio) extend that lane for RenderWare-era AAA decompilation study. (source: wiki/sources/descriptions/gta-reversed__gta-reversed-modern.md); reverse-engineered GTA III and Vice City reimplementations such as [[regta]] (Switch / PS Vita / Wii U ports; Game Develop / source) extend that classic trilogy lane beside SA decompilation work. (source: wiki/sources/descriptions/gmh5225__reGTA.md); curated GTA modding source collections such as [[grand-theft-auto-modding-source]] (re3/reVC reimplementations; reverse-engineered GTA III/Vice City with platform ports, DirectX/OpenGL rendering, mod infrastructure; Game Develop / source) extend that classic trilogy lane with bundled modding snippets. (source: wiki/sources/descriptions/gmh5225__Grand-Theft-Auto-Modding-Source.md); standalone re3/reVC engine reimplementations such as [[game-gta-re3]] (gmh5225; fully decompiled portable C++; cross-platform including PS Vita via CMake; Game Develop / source) extend that classic trilogy lane with another readable engine tree. (source: wiki/sources/descriptions/gmh5225__Game-GTA-re3.md); GTA V source-tree build tutorials such as [[gtav-sourcecode-build-guide]] (gmh5225; VM recommended; Game Develop / guide) give reverse engineers a reproducible RAGE-engine compile environment beside classic-trilogy reimplementations. (source: wiki/sources/descriptions/gmh5225__gtav-sourcecode-build-guide.md); GTA V proprietary save/snapmatic format tooling such as [[gta5view]] (gmh5225; Viewer/Editor; parse in-game photos, saves, profile data; export/manage UGC offline) gives reverse engineers a file-format study surface beside source-tree build guides. (source: wiki/sources/descriptions/gmh5225__gta5view.md); GTA V v1.59 byte-pattern signature sets such as [[gta-5-sigs-1.59]] (World, ReplayInterface, Viewport, Ammo, Clip; cheat / game:gta5 `[Offset]`; gmh5225) give reverse engineers runtime scan patterns beside save-format tooling. (source: wiki/sources/descriptions/gmh5225__GTA-5-SIGS-1.59.md); Unreal Dead By Daylight clone samples such as [[dead-by-daylight]] (physics / animation / asset pipelines; readable C++ source) extend that remake surface for asymmetric-horror mechanic study. (source: wiki/sources/descriptions/kantam5__DeadByDaylight.md); UE5 Roll a Ball tutorial samples such as [[ue5-roll-a-ball-game]] (asset pipelines / editor tooling / modding; beginner Unreal project) give reverse engineers a compact UE5 starter surface in the Game Develop / source lane. (source: wiki/sources/descriptions/gmh5225__ue5-roll-a-ball-game.md); BTS modular Unreal feature samples such as [[bt-modular-game-features]] (gmh5225; C/C++; audio / physics / animation; Plugins:Unreal) give reverse engineers a compact modular plugin surface beside those starter projects. (source: wiki/sources/descriptions/gmh5225__BT_ModularGameFeatures.md); UE5 FPS game samples such as [[ue5-fps-crypt-raider]] (gmh5225; C++/C; editor tooling / modding; first-person loop) extend that lane for UE5 FPS starter study. (source: wiki/sources/descriptions/gmh5225__UE5-FPS-CryptRaider.md); UE5 Street Fighter–style title sources such as [[unrealengine5-ultimate-streetfighters]] (gmh5225; C#/C++; audio / physics / animation; compact fighting-game project) extend that UE5 starter surface. (source: wiki/sources/descriptions/gmh5225__UnrealEngine5-UltimateStreetFighters.md); classic PC platformer reimplementations such as [[openclaw]] (Captain Claw 1997; C++/Box2D; CMake + Android) extend that remake surface for custom 2D engine / physics study. (source: wiki/sources/descriptions/pjasicek__OpenClaw.md); Electronic Arts' official [[cnc-red-alert]] release (Command & Conquer: Red Alert; Steam Workshop; publisher-maintained Westwood RTS source) extends that remake surface beside community reimplementations such as [[redalert2]] (Red Alert 2 / Yuri's Revenge game logic; unit AI, buildings, resources, multiplayer, map rendering; README Red Alert 2 on Web) for classic RTS engine-architecture study. (source: wiki/sources/descriptions/electronicarts__CnC_Red_Alert.md) (source: wiki/sources/descriptions/huangkaoya__redalert2.md); community RA2/YR engine extension [[phobos]] (Phobos-developers; C++; YRpp + Syringe injection; engine-level behavior customization for mod projects; README Red Alert 2: Yuri's Revenge engine extension) extends that classic RTS modding surface. (source: wiki/sources/descriptions/Phobos-developers__Phobos.md); Python Plants vs. Zombies remakes such as [[python-plants-vs-zombies]] (graphics-focused; Game Develop / source) give reverse engineers a readable Python 2D title surface beside compiled remakes. (source: wiki/sources/descriptions/marblexu__PythonPlantsVsZombies.md); reversed CS1.6 server game DLLs such as [[regamedll-cs]] (`mp.dll` reimplementation; GoldSource-compatible; plugin API hooks) give a readable GoldSrc server-logic surface in the same remake / RE lane. (source: wiki/sources/descriptions/s1lentq__ReGameDLL_CS.md); official Valve [[halflife]] Half-Life 1 engine and SDK source (ValveSoftware; C/C++; client/server/shared interfaces; Windows + Linux builds; modding-oriented GoldSrc architecture; Game Engine / source) gives upstream ground truth for that GoldSrc lane. (source: wiki/sources/descriptions/ValveSoftware__halflife.md); consolidated community Half-Life SDK such as [[halflife-unified-sdk]] (SamVanheer; unified HL/OpFor/Blue Shift C++ mod tree; CMake builds; bug fixes + deduplicated shared code; docs/tooling; game development / classic FPS architecture study; README [Half-Life SDK]) extends that GoldSrc modding reference beside the official tree. (source: wiki/sources/descriptions/SamVanheer__halflife-unified-sdk.md); reverse-engineered GoldSource engine reimplementations such as [[regs]] (HL1 engine components; networking / rendering / physics / game-module interfaces; Game Develop / source) give a readable full-engine surface in that same GoldSrc / HL1 RE lane. (source: wiki/sources/descriptions/gmh5225__reGS.md); decompiled/reconstructed GoldSource rebuilds such as [[goldsource-rebuild]] (gmh5225; rendering / networking / game systems; modding / research) extend that GoldSrc decompilation study lane beside [[regs]]. (source: wiki/sources/descriptions/gmh5225__GoldSourceRebuild.md); reverse-engineered CS1.6 clients such as [[cs16-client]] (Velaron; C/C++; Xash3D FWGS ecosystem; cross-platform/mobile builds for preservation, portability research, and engine-level modding) extend that GoldSrc client RE lane. (source: wiki/sources/descriptions/Velaron__cs16-client.md); reverse-engineered HLDS dedicated-server reimplementations such as [[rehlds]] (dreamstalker; DWARF from Linux `engine_i486.so`; HLDS 6152/6153; protocol-compatible bugfixes) extend that GoldSrc / HL1 server RE lane beside [[hlmaster]]. (source: wiki/sources/descriptions/dreamstalker__rehlds.md); open-source X-Ray engine reimplementations such as [[xray-16]] (OpenXRay; S.T.A.L.K.E.R. X-Ray; 64-bit + bugfixes; cross-platform C++; modding/RE community engine study) extend that production-engine RE lane. (source: wiki/sources/descriptions/OpenXRay__xray-16.md); open-source RCT2 reimplementations such as [[openrct2]] (OpenRCT2; RollerCoaster Tycoon 2; park simulation + multiplayer + plugin integration; CMake C++; modding/RE community engine study) extend that classic-title reimplementation RE lane. (source: wiki/sources/descriptions/OpenRCT2__OpenRCT2.md); the [[openarena-engine]] ioquake3 fork (Quake III stack; renderer/audio/networking/runtime; make-based C/C++; classic FPS multiplayer architecture study; Game Engine / source [quake3]) extends that id Tech 3 engine RE lane beside [[q3vm]] bytecode tooling. (source: wiki/sources/descriptions/OpenArena__engine.md); open TF2-era Source Engine trees such as [[source-engine]] (nillerusr; CI / cross-platform client/server/engine) give reverse engineers a full Source 1 surface for studying Source titles outside closed Valve trees. (source: wiki/sources/descriptions/nillerusr__source-engine.md); open-source Linux CS:GO port trees such as [[kisak-strike]] (SwagSoftware; buildable full game + Source engine; CMake; SDL/OpenGL Linux paths; Source internals and cross-platform port RE; Game Engine / source) extend that open Source 1 lane beside TF2-era mirrors. (source: wiki/sources/descriptions/SwagSoftware__Kisak-Strike.md) Leaked CS:GO source mirrors such as [[csgo-src]] (PiMoNFeeD; full Source engine + game networking/rendering/logic/client-server architecture; Leaked CSGO; Game Engine / source) give reverse engineers ground-truth CS:GO client-server internals beside partial trees such as [[cstrike15-src]]. (source: wiki/sources/descriptions/PiMoNFeeD__csgo-src.md); Orange Box–era Source Engine 2007 source-tree mirrors such as [[source-engine-2007]] (gmh5225; se2007 engine/client/server; networking, demos, rendering hooks) give reverse engineers a readable Orange Box–generation Source stack. (source: wiki/sources/descriptions/gmh5225__SourceEngine2007.md); early HL2-era Source archival snapshots such as [[source-engine-2003]] (UTINKA; 2003 Source engine + HL2-era modules/tools; material/graphics, game DLL logic, legacy Windows toolchains; engine internals / legacy game security RE; Game Engine / source) extend that Source 1 RE lane with a pre-Orange-Box reference corpus. (source: wiki/sources/descriptions/UTINKA__source-engine.2003.md); free CS1.6 cheat codebases such as [[oxware]] (C++; alpha; ~73k LOC) give an offensive client-side GoldSrc surface for the same title RE lane. (source: wiki/sources/descriptions/oxiKKK__oxware.md); title-specific COD7 research tooling such as [[cod7-tools]] (VcPkg; cheat / game:cod7) gives reverse engineers an extensible Call of Duty 7 study surface. (source: wiki/sources/descriptions/nice-sprite__COD7-Tools.md) Black Ops III client modification/research such as [[cod-boiii]] (gmh5225; client patches, SDK structures, runtime BOIII engine analysis/modification; Reverse engineering and analysis) extends that Call of Duty study surface beside [[t7-linker]]. (source: wiki/sources/descriptions/gmh5225__COD-boiii.md); Rust high-performance pattern/signature scanning via [[patternsleuth]] (SIMD multi-pattern + wildcards; file or live process; Unreal address-scanner lane) (source: wiki/sources/descriptions/trumank__patternsleuth.md); UE4/UE5 `.uasset`/`.umap` dependency graphs via [[jmap]] (reflection-data format/extractor; asset loading chains) (source: wiki/sources/descriptions/trumank__jmap.md); Rust UE pak/UAsset explorers such as [[paksmith]] (FModel rewrite; pak v3–v11; offline texture/mesh/audio extract) (source: wiki/sources/descriptions/r6e__paksmith.md); C# UAsset binary GUI viewers/editors such as [[uassetgui]] (tree-view exports/imports/properties; cooked `.uasset`/`.umap`; UE4–UE5; offline modding) (source: wiki/sources/descriptions/atenfyr__UAssetGUI.md); low-level .NET UAsset read/write libraries such as [[uassetapi]] (JSON round-trip; Kismet bytecode; optional `.usmap`; binary fidelity for programmatic asset edit) (source: wiki/sources/descriptions/atenfyr__UAssetAPI.md); modular .NET UE4 asset libraries such as [[uetools]] (PAK VFS + asset/registry parse; C# reusable modules; offline inspection/modding/research) (source: wiki/sources/descriptions/UETools__UETools.md); legacy UE1–UE3 package browsers/decompilers such as [[ue-explorer]] (C# WinForms; UnrealScript decompile, class/sound export, package dependency inspection, structured hex viewer; modding/RE; Browser and decompiler for UE packages) (source: wiki/sources/descriptions/UE-Explorer__UE-Explorer.md); Rust UE4 `.pak` unpack/pack/list/check/mount tools such as [[rust-u4pak]] (limited pak versions) (source: wiki/sources/descriptions/panzi__rust-u4pak.md); C++ Unity `.assets`/AssetBundle desktop editors such as [[uabe]] (SeriousCache; Win32 + CMake; plugin import/export; multi-version; modding/asset inspection; Extracting assets) sit in the Game Assets / Unity offline lane beside UE pak explorers (source: wiki/sources/descriptions/SeriousCache__UABE.md); canonical C# Unity asset extractors such as [[assetstudio]] (Perfare; AssetBundle explore/extract/export; textures/audio/fonts/meshes/shaders/animation; bundle decompression + scene hierarchy + practical export formats; modders / RE / game-security analysts; Extracting assets) (source: wiki/sources/descriptions/Perfare__AssetStudio.md) extend bulk extraction beside editor-style [[uabe]] workflows; multi-threaded fork [[assetstudio-razviar]] (Unity 2.x–6; parallel load/export) continues that lane (source: wiki/sources/descriptions/Razviar__assetstudio.md); .NET Unity asset recovery such as [[asset-ripper]] (AssetRipper; serialized files + bundles → native Unity-style outputs; broad Unity version parsers/converters; modding / content analysis; Extracting assets) (source: wiki/sources/descriptions/AssetRipper__AssetRipper.md) complements bulk extraction for reconstruction workflows; title-specific God of War (2018) asset extractors such as [[gow-tool]] (HitmanHimself; C++ Visual Studio; DirectXTex + glTF; extract/convert proprietary assets; practical extraction pipeline for modders / asset researchers / format RE; God of War 2018) (source: wiki/sources/descriptions/HitmanHimself__GOWTool.md); Unity master-bundle and title-specific format RE such as [[unturned-godot]] (C# reimplementation of Unturned/Unity serialized formats; Steam-install map/terrain/object/audio load; U3-SDK reference validation; xUnit core) sit in the Game Assets / Unity bundle lane beside UE pak explorers. (source: wiki/sources/descriptions/jlucaso1__unturned-godot.md); the official [[godot]] engine source tree (GDScript/C#; Game Engine / source) gives reverse engineers a readable OSS surface for Godot title internals beside runtime dumpers such as [[gddumper]] and export-time GDScript obfuscators such as [[gdmaim]] (Godot 4.x export plugin; rename/inlining/strip/shuffle; GDBC strings; source-map debug; preprocessor + platform feature tags). (source: wiki/sources/descriptions/cherriesandmochi__gdmaim.md) (source: wiki/sources/descriptions/godotengine__godot.md); official Godot demo/template collections such as [[godot-demo-projects]] (GitHub Pages exports; feature-scoped sample projects) extend that Godot RE surface beside the full engine tree. (source: wiki/sources/descriptions/godotengine__godot-demo-projects.md); official Houdini Engine Unreal plugins such as [[houdini-engine-for-unreal]] (HDA / procedural content pipeline) sit in the adjacent Game Engine Plugins:Unreal / asset-authoring lane (source: wiki/sources/descriptions/sideeffects__HoudiniEngineForUnreal.md); UE4 Lua scripting plugins such as [[luamachine]] (Blueprint Lua assets / reflection metatables / actor-component proxies) sit in the same Plugins:Unreal gameplay-scripting lane for engine/mod RE (source: wiki/sources/descriptions/rdeioris__LuaMachine.md); Lua bytecode decompiler [[luadecompiler]] (Coldzer0; Pascal; Lua 5.1–5.5; SSA CFG reconstruction, boolean recovery, custom opcode tables for game-modified VMs; script RE / Decompiler) helps recover gameplay logic from compiled Lua chunks beside live-script bridges (source: wiki/sources/descriptions/Coldzer0__LuaDecompiler.md); Unity-side Lua↔C# bridge [[xlua]] (Tencent; two-way interop + runtime hotfix; Mono/.NET/Unity clients; Game Hot Patch / scripting RE lane) complements that lane on C# game stacks (source: wiki/sources/descriptions/Tencent__xLua.md); Unity C# logic hotfix [[injectfix]] (Tencent; IL inject/route patched gameplay at runtime; broad Unity version/platform; live bugfix without full rebuilds; Game Hot Patch RE lane) extends that lane for direct managed-code patching (source: wiki/sources/descriptions/Tencent__InjectFix.md); UE CoreCLR / .NET 6 gameplay plugins such as [[unrealclr]] (C# bindings for actors / components / Blueprints) sit beside them in that same Plugins:Unreal managed-scripting lane for engine/mod RE (source: wiki/sources/descriptions/nxrighthere__UnrealCLR.md); Flutter/Dart AOT snapshot static analysis via [[unflutter]] (source: wiki/sources/descriptions/zboralski__unflutter.md); Guardsquare Flutter RE experiment kit [[flutter-re-demo]] (Python IDA Pro scripts parse reFlutter/DWARF, rename Dart functions, import VM dumps, rebuild objects/xrefs, stack-pointer/microcode decompilation aids; Frida memory capture; sample game APKs; Flutter protection / obfuscation limits study) (source: wiki/sources/descriptions/Guardsquare__flutter-re-demo.md); managed .NET 2D engine trees such as [[flatredball]] for inspecting a complete editor/runtime codebase (source: wiki/sources/descriptions/vchelaru__FlatRedBall.md); MonoGame pixel-art 2D engine trees such as [[murder]] (Murder Engine; C# ECS + Aseprite + dialogue/editor; README `[pixel]`) for inspecting a complete narrative 2D managed engine codebase (source: wiki/sources/descriptions/isadorasophia__murder.md); cross-platform Java game frameworks such as [[libgdx]] (shared Java codebase → Android/LWJGL/GWT backends; OpenGL ES rendering; JNI helpers; useful when analyzing libGDX-based titles) (source: wiki/sources/descriptions/libgdx__libgdx.md); open-source C# 3D engine trees such as [[stride]] (formerly Xenko; editor + Vulkan/D3D/OpenGL backends) (source: wiki/sources/descriptions/stride3d__stride.md); lightweight cross-platform 2D/3D engine source such as [[urho3d]] (source: wiki/sources/descriptions/urho3d__Urho3D.md); Urho3D C#/WYSIWYG fork [[rbfx]] (source: wiki/sources/descriptions/rbfx__rbfx.md); Python/C++ 3D frameworks such as [[panda3d]] (liberal-license engine tree) (source: wiki/sources/descriptions/panda3d__panda3d.md); open C++ 3D engine source such as [[wickedengine]] (`WickedEngine_Windows` static lib) (source: wiki/sources/descriptions/turanszkij__WickedEngine.md); open-source Torque 3D C++ engine source such as [[torque3d]] (CMake; Assimp; render/physics/network/scripting subsystems; multi-platform; Game Engine / 3D) (source: wiki/sources/descriptions/TorqueGameEngines__Torque3D.md); open-source Torque 2D C++ engine source such as [[torque2d]] (Box2D physics; render/audio/animation; multi-platform; sample modules; Game Engine / 2D) (source: wiki/sources/descriptions/TorqueGameEngines__Torque2D.md); open-source 2D Lua+C++ engine source such as [[obengine]] (ObEngine; SFML; scene/game-object/map/animation/input/networking/plugin systems; Lua scripting; Game Engine / [2D+Lua]) (source: wiki/sources/descriptions/ObEngine__ObEngine.md); open-sourced commercial action-game engine source such as [[overgrowth]] (Wolfire Games; rendering/physics/animation/AI/level-editor/scripting; Game Engine / source) (source: wiki/sources/descriptions/WolfireGames__overgrowth.md); RPG Maker XP/VX/VX Ace encrypted-archive extraction via [[rpgmakerdecrypter]] (CLI; cheat / RE-tools lane) (source: wiki/sources/descriptions/uuksu__RPGMakerDecrypter.md); CAK compressed-archive automation such as [[auto-open-cak]] (gmh5225; batch extract/decompress CAK game-distribution archives; cheat / Bypass tool) (source: wiki/sources/descriptions/gmh5225__AutoOpenCAK.md); Warcraft III map-editor alternatives such as [[hivewe]] (large-map World Editor replacement; cheat / game:warcraft iii) for title-format / editor RE. (source: wiki/sources/descriptions/stijnherfst__HiveWE.md); title-specific Splitgate internals such as [[splitgate-internal]] (C/C++; cheat / game:splitgate) give reverse engineers an in-process offensive sample surface. (source: wiki/sources/descriptions/percpopper__Splitgate-Internal.md); PUBG desktop hooking + memory-analysis samples such as [[pubgstar]] (gmh5225; C/C++; cheat / game:pubg) extend that title-specific offensive lane beside UE4 dumpers. (source: wiki/sources/descriptions/gmh5225__PUBGSTAR.md) Title-specific Battlefield 2042 internal SDK scaffolds such as [[battlefield-2042-internal-sdk]] (Skengdo; C++; entity/player/vehicle/weapon structures, game context, rendering access, [[world-to-screen]] helpers; incomplete entity-list iteration; internal RE tooling / debugging prototypes; cheat / game:battlefield 2042 [Internal]) extend that Frostbite title-specific lane beside BF1/BF4 samples. (source: wiki/sources/descriptions/Skengdo__battlefield-2042-internal-sdk.md) RE-derived C# Harmony mod architectures with online backend integration such as [[duckov-marketmod]] (a0yark; Duckov flea market; Steam-auth API client + WebSocket + Harmony patches + auto-updating mod loader; sanitized RE internals for secondary development; modding / marketplace integration study) extend that engine/mod RE lane beside Unity BepInEx scaffolds. (source: wiki/sources/descriptions/a0yark__Duckov_marketmod.md) BepInEx Harmony runtime probe suites for Unity survival titles such as [[danis-nightmare]] (PlinKuuu; Muck; chat-command IL patches + live in-memory autocomplete; player/enemy/item/powerup/time manipulation for mod authors and engine behavior stress-testing) extend that engine/mod RE lane. (source: wiki/sources/descriptions/PlinKuuu__DanisNightmare.md) DirectX compatibility proxy DLLs such as [[dxwrapper]] (legacy DDraw/D3D8–9 hook surface; logging/overlays/resource dump for rendering RE on Win10/11) extend that lane for pre-DX10 Windows game graphics study. (source: wiki/sources/descriptions/elishacloud__dxwrapper.md) Legacy title hook frameworks such as [[winehooks]] (Daniel-Lobo; DirectX/OpenGL interception + per-game patch profiles; Windows + Wine; modding / graphics RE on classic PC games) extend that lane. (source: wiki/sources/descriptions/Daniel-Lobo__WineHooks.md) - **Anti-analysis:** kernel-mode debugger hide via [[titanhide]] (SSDT hooks on Nt kernel APIs; per-process return-value tampering; cheat / debugging) alongside usermode ScyllaHide/HyperHide plugins such as [[scyllahide-for-ida9.0rc]] (IDA 9.0 SDK build; TKazer) (source: wiki/sources/descriptions/TKazer__ScyllaHide-For-IDA9.0RC.md) vs IsDebuggerPresent/Kd* / timing checks (source: wiki/sources/descriptions/mrexodia__TitanHide.md); defensive ScyllaHide detection via [[scyllahidedetector2]] (C/C++; find hide use when debugging / restoring bytes) (source: wiki/sources/descriptions/samshine__ScyllaHideDetector2.md); debugger-use / anti-anti-debug trace detection such as [[wubbaboomark]] (hfiref0x; Ghidra/IDA/OllyDbg/x32dbg/x64dbg/WinDbg + hide-plugin environment tampering; AC / anti-debug research) (source: wiki/sources/descriptions/hfiref0x__WubbabooMark.md); WinDbg break-prevention PoC such as [[letme-gg]] (C++; gmh5225; interfere with WinDbg breakpoint/break-in; Some Tricks / Windows Ring0 anti-debug research) (source: wiki/sources/descriptions/gmh5225__LetMeGG.md); kernel-mode debugger detection driver PoC such as [[anti-kernel-debug-poc]] (C driver; gmh5225; debug port / `KdDebuggerEnabled` / `KUSER_SHARED_DATA` / interrupt-based checks; AC-style anti-kernel-debug study) (source: wiki/sources/descriptions/gmh5225__AntiKernelDebug-POC.md); title-specific Genshin Impact anti-debug bypass via [[genshin-debugger-bypass]] (gmh5225; C++ DLL; Microsoft Detours on `NtQueryInformationProcess`/`IsDebuggerPresent`; CloseMhyprot2 unloads `mhyprot2.sys`; Anti-Debug Bypass / game:genshin impact) (source: wiki/sources/descriptions/gmh5225__GenshinDebuggerBypass.md); Windows anti-debug technique catalogs such as [[makin]] (C; 30+ API/PEB/HWBP/timing/TLS checks; console pass/fail) (source: wiki/sources/descriptions/secrary__makin.md); C++ anti-debugging samples such as [[anti-debugging]] (revsic; AC / anti-debug research) (source: wiki/sources/descriptions/revsic__AntiDebugging.md); Windows C++ anti-debug protector/loader example [[anti-debugger-protector-loader]] (YouNeverKnow00; debugger executable/window-title/driver scanning; optional termination; configurable intervals; VMProtect SDK artifacts; practical anti-debug pattern study) (source: wiki/sources/descriptions/YouNeverKnow00__Anti-Debugger-Protector-Loader.md); Windows anti-tamper / anti-crack framework prototype [[anti-crack-system]] (ReFo0; C++; anti-debugging, anti-dump, anti-attach, integrity checks, process-kill, self-remapping code, string obfuscation + lightweight encryption; software protection / game security hardening experiments) (source: wiki/sources/descriptions/ReFo0__anti-crack-system.md); Windows kernel licensing path analysis via [[windows-software-policy]] (KiFilterFiberContext; `SystemPolicyInformation` `NtQuerySystemInformation` class; user-mode licensing ↔ kernel policy driver; C headers + Python binary helper; software protection / Windows internals RE) (source: wiki/sources/descriptions/KiFilterFiberContext__windows-software-policy.md); compact C++ anti-analysis toolkit [[dynamizer]] (PaulNorman01; string obfuscation, anti-step-over, SW/HW breakpoint checks, `.text` integrity, return-address manipulation, system DLL unhooking; modular drop-in modules for dynamic-analysis evasion / anti-tamper research) (source: wiki/sources/descriptions/PaulNorman01__Dynamizer.md); anti-debug + VirtualBox anti-VM example corpus [[antidebug-antivm]] (gmh5225; reference snippets for integrating checks; not a standalone build; Anti Debugging / Detection:Virtual Environments) (source: wiki/sources/descriptions/gmh5225__AntiDebug-AntiVM.md); Windows userland anti-debug library [[antidbg]] (NotRequiem; C/C++; fully syscalled API/timing/process-environment/HWBP/exception checks + direct-syscall evasion; stealth-focused anti-RE CLI; Anti Debugging) (source: wiki/sources/descriptions/NotRequiem__antidbg.md); Windows anti-debug library [[antidbg-baka]] (C/C++; Baka; PEB/NtQueryInformationProcess/HWBP/timing/exception/parent-process checks; ScyllaHide/HyperHide/TitanHide detection; integratable primitives; Anti Debugging) (source: wiki/sources/descriptions/gmh5225__antidbg-Baka.md); anti-debug plugin [[antidbg-amogus-plugin]] (C/C++; hooking / plugin development / debugging integration; Anti Debugging; gmh5225) (source: wiki/sources/descriptions/gmh5225__AntiDbg-AmogusPlugin.md); Linux anti-debugging technique catalog such as [[adbg]] (C/C++; Anti Debugging) (source: wiki/sources/descriptions/hiatus__adbg.md); early-runtime Linux debugger detector such as [[ladd]] (BarakAharoni; C; ptrace behavior, LD_PRELOAD tampering, TracerPid in /proc/self/status; simple runtime checks; anti-analysis research and Linux binary hardening; Anti Debugging) (source: wiki/sources/descriptions/BarakAharoni__LADD.md); TTD debug-testing / hooking samples such as [[ttd-anti-debugging]] (C/C++; Time Travel Debugging anti-debug stress tests; Cheat → Debug Testing) (source: wiki/sources/descriptions/liors619__TtdAntiDebugging.md); Win32 interactive anti-debug bypass practice via [[gh-anti-debug-bypass-practice-tool]] (C++/VS; ImGui/DX11 overlay; toggle checks → DETECTED; IsDebuggerPresent/PEB/heap/ThreadHideFromDebugger/timing/SEH; extensible callbacks; Anti Debugging / bypass training) (source: wiki/sources/descriptions/guidedhacking__GH_AntiDebug_Bypass_Practice_Tool.md); Black Hat 2012 anti-analysis PoCs [[blackhat2012]] (Anti-Debugging / Anti-Disassembly / Obfuscation / Anti-VM; C/C++ + FASM) (source: wiki/sources/descriptions/rrbranco__blackhat2012.md); RE disassembler/decompiler blind spots such as [[hint-break]] (`0F 1A` / `0F 1B` ghost opcodes vs modern tools) (source: wiki/sources/descriptions/sapdragon__hint-break.md); Cuckoo sandbox / virtual-environment detection demos such as [[anticuckoo]] (`Detection:Virtual Environments`; crash PoCs demonstration-only) (source: wiki/sources/descriptions/therealdreg__anticuckoo.md); open-source anti-analysis testing tool [[pafish]] (C; modular VM/sandbox/debugger/hook/environment checks for VMware, VirtualBox, QEMU, Wine; MinGW-w64; reproducible malware-style evasion testing; a0rtega) (source: wiki/sources/descriptions/a0rtega__pafish.md); compact embeddable VM-detection component [[compact-vm-detector]] (LukeGoule; C++; [[pafish]]-inspired lightweight anti-virtualization checks; Visual C++ integration; minimal footprint; anti-analysis experimentation and environment fingerprinting; Detection:Virtual Environments) (source: wiki/sources/descriptions/LukeGoule__compact_vm_detector.md); Windows C++ anti-analysis PoC test suite [[al-khaser]] (LordNoteworthy; anti-debug/anti-VM/anti-dump/anti-disassembly/timing checks via CLI; VirtualBox/VMware/QEMU/Wine + common analysis workflows; sandbox/EDR/anti-malware visibility validation; malware-style evasion testing) (source: wiki/sources/descriptions/LordNoteworthy__al-khaser.md); ML-derived VM-detection shellcode loader [[t-1]] (0xTriboulet; C++; Python/scikit-learn decision-tree training → native C++ environment checks; conditional shellcode execution vs self-removal on VM/sandbox hits; sandbox-awareness + automation-assisted malware analysis research) (source: wiki/sources/descriptions/0xTriboulet__T-1.md); static .NET client-AC architecture RE such as [[rustsecure-re]] (Leeksov; RustSecure loader/core DLL map + 13 detection modules; string decrypt/deobfuscate Python/C# tooling; bypass write-ups; static-only ILSpy/dnfile/IDA—no live execution; game:rust client-side protection study) (source: wiki/sources/descriptions/Leeksov__rustsecure-re.md); Any.Run-style sandbox detection PoC [[anti-sandbox]] (SaadAhla; C++; folder/process/user-profile/service-driver host artifact checks; layered multi-indicator scoring before flagging; malware-analysis / sandbox-evasion research; Detecting AnyRun sandbox) (source: wiki/sources/descriptions/SaadAhla__Anti-Sandbox.md); Windows Sandbox fingerprint library [[wsb-detect]] (LloydLabs; C library + sample; modular checks—sandbox processes, usernames, device paths, DNS suffixes, registry artifacts, timing; combinable by false-positive tolerance; anti-analysis / environment-awareness research; Windows Sandbox ("WSB")) (source: wiki/sources/descriptions/LloydLabs__wsb-detect.md); VMware Windows VM cloak for malware-analysis hosts via [[vmware-cloak]] (PowerShell; hide guest VMware fingerprints from VM-evasive malware; cheat / virtual environments) (source: wiki/sources/descriptions/d4rksystem__VMwareCloak.md); curated anti-virtualization resources via [[awesome-anti-virtualization]] (source: wiki/sources/descriptions/theo-abel__awesome-anti-virtualization.md); Steam-specific anti-anti-debug via [[steam-anti-anti-debug]] (patch Steam debug detection so [[x64dbg]] can attach to protected game processes) (source: wiki/sources/descriptions/wilszdev__SteamAntiAntiDebug.md); browser-based JS anti-debug bypass UserScripts such as [[js-debugger-bypass-script]] (JavaScript; Tampermonkey/Greasemonkey; neutralize `debugger` statements, DevTools detection, `console.log` timing, window-size monitoring; web/JS RE lane) (source: wiki/sources/descriptions/gmh5225__js-debugger-bypass-script.md); browser-game WebSocket/packet hooking study such as [[glotus-client]] (TypeScript/Bun Tampermonkey; Moomoo.io; document-start inject; packet/socket managers, movement simulation, spatial indexing, custom overlays; Cheat / Debugging) (source: wiki/sources/descriptions/Murka007__Glotus-Client.md); offline Steamworks API emulation via [[goldberg-emulator]] (local `steam_api` replacement; study Steam DRM/API dependencies without live Steam) (source: wiki/sources/descriptions/inflation__goldberg_emulator.md); VEH software debugger (no Debug API) via [[veh]] (breakpoint / single-step / AV handlers; CE plugin for manual-mapped VEH DLLs) (source: wiki/sources/descriptions/user23333__veh.md); VEH/VCH chain dump to IDA-ready PE64 via [[veh-dumper]] (foothold handler + `RtlDecodePointer` list walk) (source: wiki/sources/descriptions/xxFURYWOLFxx__veh-dumper.md); PAGE_NOACCESS code-page anti-tamper via [[no-access-protection]] (VEH restore + `STATUS_SINGLE_STEP` re-protect vs external scanners) (source: wiki/sources/descriptions/weak1337__NO_ACCESS_Protection.md); VEH + `PAGE_NOACCESS` hardened console sample [[bincon]] (vs memory scans / mods / debuggers) (source: wiki/sources/descriptions/saveme712__BinCon.md); VEH + `PAGE_NOACCESS` memory-analysis sample [[veh-hide-memory]] (C++; AC / page protection) (source: wiki/sources/descriptions/gmh5225__veh_hide_memory.md); x86 on-access decrypt via PAGE_NOACCESS page guards [[no-access-protection-x86]] (anti-tamper / anti-dump; static analysis & memory-dump hindrance) (source: wiki/sources/descriptions/gmh5225__no-access-protection-x86.md); VEH + `PAGE_GUARD` code-hiding via [[voidmaw]] (AV/AC page-protection research) (source: wiki/sources/descriptions/vxCrypt0r__Voidmaw.md); self-remapping code via memory aliasing [[self-remapping-code]] (changeofpace; execute from one virtual mapping while integrity-checking another; section-backed aliased views; anti-patching / anti-debug RE) (source: wiki/sources/descriptions/changeofpace__Self-Remapping-Code.md); x64dbg ForcePageProtection plugin [[force-page-protection]] (changeofpace; fpp commands; override NtProtectVirtualMemory failures via view remapping; SEC_NO_CHANGE / anti-tamper mapped-view restrictions; Bypass Remap Memory) (source: wiki/sources/descriptions/changeofpace__Force-Page-Protection.md); non-invasive VEH + `PAGE_GUARD` printf/output hook without byte patches via [[veh-printf-hook]] (VEH function-interception RE) (source: wiki/sources/descriptions/gmh5225__veh-printf-hook.md); custom VEH registration via `RtlpCallVectoredHandlers` hook via [[custom-veh]] (faster pre-vanilla dispatch; Ring3 callback-order RE) (source: wiki/sources/descriptions/gmh5225__custom-VEH.md); ROP-only / PIC Gargoyle variant [[deepsleep]] (x64; no APCs; hide memory artifacts for page-protection RE) (source: wiki/sources/descriptions/thefLink__DeepSleep.md); cyclic shellcode encrypt/decrypt + RW/NoAccess↔RX fluctuation PoC [[shellcode-fluctuation]] (mgeeky; in-memory evasion vs memory scanners) (source: wiki/sources/descriptions/mgeeky__ShellcodeFluctuation.md); ROP-based Rust sleep obfuscation crate [[shelter]] (Kudaes; AES-128 payload/whole-PE encrypt; strips execute permission while sleeping; ROP resume; stack spoofing + indirect syscalls; in-memory evasion research) (source: wiki/sources/descriptions/Kudaes__Shelter.md); educational in-memory data polymorphism demo [[in-memory-mutation-demo]] — C++23 `ProtectedData` decrypt/use/re-encrypt cycle with `VirtualProtect`/`mprotect`, position-dependent XOR + dynamic key rotation, permission restore, and buffer zeroization (alekzandren; binary mechanics / defense-in-depth) (source: wiki/sources/descriptions/alekzandren__in-memory-mutation-demo.md); PE `.reloc`-backed allocation hiding via [[memory-relocalloc]] (gmh5225; evade heap/VAS enumeration by anti-cheat memory scanners; Windows/Android) (source: wiki/sources/descriptions/gmh5225__memory-relocalloc.md); thread-terminate/restore sleep obfuscation PoC [[death-sleep]] (janoglezcampos; page protection during no-execution + hide execution thread) (source: wiki/sources/descriptions/janoglezcampos__DeathSleep.md); dynamic runtime-protection analysis framework [[dynsec]] (gmh5225; instrumentation + monitoring for anti-tamper, anti-debug, integrity checks in games/applications) (source: wiki/sources/descriptions/gmh5225__Dynsec.md) - **LSA / dump forensics:** cross-platform LSASS credential extractors such as [[kvcforensic]] recover MSV/WDigest/Kerberos/CredMan/DPAPI secrets from live memory or `lsass.dmp` via signature scan + BCrypt (Win11 24H2–26H1; Windows/Linux). (source: wiki/sources/descriptions/wesmar__KvcForensic.md) Undocumented DPAPI RPC PoCs such as [[custom-dpapi]] (EvilBytecode; C++; direct `NdrClientCall3` to lsass `protected_storage`; bypasses `CryptUnprotectData`; dpapi.dll RE; Windows credential protection / RPC attack-surface research) (source: wiki/sources/descriptions/EvilBytecode__CustomDpapi.md) In-memory dump-pipeline hook PoCs such as [[minidumpwritedumppoc]] (Adepts-Of-0xCC; hook `MiniDumpWriteDump` to capture buffers pre-write; optional encryption and remote socket exfil; tradecraft / defensive validation research) (source: wiki/sources/descriptions/Adepts-Of-0xCC__MiniDumpWriteDumpPoC.md) In-place VM memory-snapshot / virtual-disk extractors such as [[vmkatz]] pull LSASS, SAM/LSA, cached creds, and NTDS.dit without bulk disk-image exfil (AC / IS forensics). (source: wiki/sources/descriptions/nikaiw__VMkatz.md) - **Memory forensics (RAM):** frameworks such as [[volatility]] (original Python 2; profile-based; pslist/psscan, modules, rootkit/malware plugins) and [[volatility3]] (Python 3 rewrite; layer translation + automagic profiles) extract process/network/registry/kernel artifacts from offline memory images for IR and malware RE. (source: wiki/sources/descriptions/volatilityfoundation__volatility.md) (source: wiki/sources/descriptions/volatilityfoundation__volatility3.md) MemProcFS-based automated Windows dump analysis via [[memprocfs-analyzer]] (PowerShell; processes/network/registry/event logs/browser artifacts/malware indicators; HTML reports; VirusTotal TI; IS forensics). (source: wiki/sources/descriptions/evild3ad__MemProcFS-Analyzer.md) Live Windows instrumentation dashboards such as [[aetheris]] (Dray973; PyQt6; MemProcFS + PCILeech-FPGA guarded DMA R/W; process autopsy, MFT/network/registry modules; hash-chained audit log, dry-run, Omega Rollback; Cheat DMA lane / live forensics). (source: wiki/sources/descriptions/Dray973__Aetheris.md) Linux offline RAM images as a browsable filesystem via [[memnixfs]] (C++17; AVML/LiME/raw/kdump → `/proc`-like VFS; processes/files/sockets/modules/timelines; MemProcFS-style workflow on Linux dumps; Windows/Linux hosts; AC / IS forensics). (source: wiki/sources/descriptions/MemNixFS__MemNixFS.md) Linux live memory acquisition via [[dumpit-linux]] (MagnetForensics; Rust; `/proc/kcore` → ELF core; optional tar.zst packaging; gdb/crash/drgn compatible; no custom kernel module; IR / Linux memory forensics). (source: wiki/sources/descriptions/MagnetForensics__dumpit-linux.md) Live full physical-memory capture via [[dumpit-mirror]] (Comae DumpIt mirror; one-click raw or Microsoft crash-dump output for Volatility / WinDbg; portable IR acquisition). (source: wiki/sources/descriptions/h4sh5__DumpIt-mirror.md) DIY live system memory dumps via [[tool-diy-system-memory-dump]] (gmh5225; crash-dump–compatible physical RAM from running Windows; WinDbg / Volatility offline analysis; Cheat DIY Dump Type). (source: wiki/sources/descriptions/gmh5225__Tool-DIYSystemMemoryDump.md) Pre-OS firmware offline crash dumps via [[offline-crash-dump-uefi]] (Microsoft EDK2; firmware-side memory dump before OS; encryption/redaction; gmh5225). (source: wiki/sources/descriptions/gmh5225__OfflineCrashDumpUefi.md) USB-boot UEFI physical RAM dump app via [[memory-dump-uefi]] (NoInitRD; C UEFI application; live-boot USB + UEFI shell; scripts/build/docs for memory-image collection; forensic acquisition / low-level security research; README [A UEFI application for dumping the contents of RAM]). (source: wiki/sources/descriptions/NoInitRD__Memory-Dump-UEFI.md) VMware vTPM-encrypted snapshot decryptors such as [[vmem-decrypt]] (pure-Python encobj AES-256-CBC; decrypt `.vmem`/`.vmsn`/`.vmss`/`.nvram` from VM password; `vmem_flatten.py` → Volatility 3-ready image; Win11 partial VM encryption; AC / IS forensics). (source: wiki/sources/descriptions/heeeyaaaa__vmem-decrypt.md) WinDbg-flavored multiplatform `MEMORY.DMP` analysis via [[ephemera]] covers crash-dump workflows for AC / kernel dump RE when native WinDbg is too slow. (source: wiki/sources/descriptions/vmi-rs__ephemera.md) Python minidump tooling such as [[minidumpreader]] targets the same AC / Windows kernel dump-analysis lane. (source: wiki/sources/descriptions/tasox__miniDumpReader.md) Format-level parse libraries such as [[minidump]] (skelsec; full/mini dumps; threads/modules/exceptions; LSASS credential workflows without WinDbg) support the same offline dump RE / IR lane. (source: wiki/sources/descriptions/skelsec__minidump.md) C/C++ minidump libraries such as [[libmdmp]] (libyal; memory analysis / debugging; AC / Windows kernel dump analysis) extend that lane for native tooling. (source: wiki/sources/descriptions/libyal__libmdmp.md) Cross-platform C++ user-mode minidump parsing via [[udmp-parser]] (0vercl0k; threads/register contexts/virtual memory/modules; library API + parser utility; optional Python bindings; debugger tooling / dump triage) extends native parse tooling in the same lane. (source: wiki/sources/descriptions/0vercl0k__udmp-parser.md) Cross-platform C++ Windows kernel crash-dump parsing via [[kdmp-parser]] (0vercl0k; full/active dump formats; context/exception/bugcheck params + physical memory views; library API + parser CLI; optional Python bindings; crash forensics / kernel debug automation / exploitation RE) complements user-mode minidump tooling in the same lane. (source: wiki/sources/descriptions/0vercl0k__kdmp-parser.md) Windows execution-trace symbolization via [[symbolizer]] (0vercl0k; C++ CLI; dbgeng + crash-dump data resolve raw instruction pointers to function-level symbols; crash triage, exploit debugging, postmortem trace workflows) complements dump parse tooling in the same lane. (source: wiki/sources/descriptions/0vercl0k__symbolizer.md) Ghidra-native Windows minidump loading via [[ghidra-minidump-loader]] (Rantanen; Java Gradle extension; maps dump modules to runtime addresses, imports private memory/thread stacks, thread-view stack walking; crash-dump / post-mortem malware RE inside Ghidra; cheat / Ghidra Plugins) (source: wiki/sources/descriptions/Rantanen__ghidra-minidump-loader.md) Android live-session capture into Windows minidump format via [[lldbext-dump]] (LLDB Python extension; mapped regions / thread contexts / modules; companion Unicorn replay script) extends that lane to mobile native RE. (source: wiki/sources/descriptions/mrexodia__lldbext-dump.md) Unicorn-based offline execution from `.dmp` files via [[dumpulator]] (Python; rebuild memory/modules/threads/handles; NT syscall stubs / PEB·TEB / API hooks; run arbitrary functions without live attach) closes the parse → emulate loop for Windows process dumps. (source: wiki/sources/descriptions/mrexodia__dumpulator.md) Full x86/x64 PE userspace emulation via [[sogen]] (Unicorn + Capstone; syscall emulation; minidump load; Zstd state snapshots; React web UI; FlatBuffers execution-trace IPC; Emscripten/Android NDK) extends the same Windows Emulator lane with interactive session tooling. (source: wiki/sources/descriptions/momo5502__sogen.md) Debugger-emulator PE replay via [[emulator]] (dbghelp imports; API simulation; instruction logging for obfuscated/DRM binaries) offers a focused offline PE-load lane in the same Windows User Space Emulator bucket. (source: wiki/sources/descriptions/mojtabafalleh__emulator.md) Experimental AOT PE binary translation via [[levo]] (Ghidra CFG export → XED/Remill lift to LLVM IR → native recompile; PE mapper + `kernel32` API-intercept runtime) offers a lift-and-recompile alternative in the same Windows PE study lane. (source: wiki/sources/descriptions/momo5502__levo.md) Educational x86 dynamic-recompilation learning via [[dynre-x86]] (C++; Zydis decode/operand inspect; Makefile + Docker; register-name tables; instruction-decoding / binary-translation pipeline study) offers a minimal decode-first stepping stone in that lane. (source: wiki/sources/descriptions/aroxby__dynre-x86.md) IDA→LLVM IR lifting via [[ida2llvm]] spans dynamic cursor-sync disassembly lifting (loyaltypollution; liftability viewer; source: wiki/sources/descriptions/loyaltypollution__ida2llvm.md) and microcode→IR translation with llvmlite type mapping (Sandspeare; sample binaries + IR examples; source: wiki/sources/descriptions/Sandspeare__ida2llvm.md), complementing offline lift paths such as [[levo]] for in-IDA binary-lifting study. Lightweight single-process scan engine [[pe-sieve]] (malware detection + malicious-material collection; Detection:hook) underpins live in-memory scanners such as [[xmalhunter]] (injected code / inline hooks / hollowed modules across 32/64-bit processes; libpeconv) that complement offline dump analysis for runtime injection RE. (source: wiki/sources/descriptions/hasherezade__pe-sieve.md) (source: wiki/sources/descriptions/push0ebp__xMalHunter.md) Live mapped-region manual-map scanners such as [[modfinder]] (Nou4r; C++; DOS-header pattern walk over enumerated regions; x86 runtime AC/malware forensics; Mapped Dll) (source: wiki/sources/descriptions/Nou4r__ModFinder.md) Pure-stdlib Python headerless PE reconstruction such as [[pereconstruct]] (deep memory scan, contiguous dump, wiped-header rebuild, hook analysis, export resolution; no driver/debugger; manually-mapped DLL static analysis) supports the same injection RE lane when live scanners flag concealed modules. (source: wiki/sources/descriptions/diabloidyobane__PEReconstruct.md) Windows memory-hacking library [[blackbone]] (DarthTon; x86/x64 process manipulation; manual PE map, module enum, WOW64 thread control; user-mode + kernel APIs; foundational layer for RE/instrumentation tooling) (source: wiki/sources/descriptions/DarthTon__Blackbone.md) Educational Visual Studio DLL injection technique samples such as [[inject-all-the-things]] (DanielRTeixeira; seven methods in separate source files—CreateRemoteThread through reflective load; x86/x64; process-injection mechanics for RE learners; Injection Testing) (source: wiki/sources/descriptions/DanielRTeixeira__injectAllTheThings.md) Manual thread-hijack DLL injection PoCs such as [[threadject]] (D4stiny; C++; validates/maps DLL payload, loader metadata + runtime shellcode patching, existing-thread execution redirect; Visual Studio; injection-chain study + endpoint security detection test cases; Injection Testing) (source: wiki/sources/descriptions/D4stiny__ThreadJect.md) Early cascade process-injection PoCs such as [[earlycascade-injection]] (Cracked5pider; C++; creates a process and injects during early initialization for stealthier load; build-specific structure offsets; malware analysis, EDR bypass, and defensive detection testing; Injection Testing) (source: wiki/sources/descriptions/Cracked5pider__earlycascade-injection.md) Early-stage C/C++ PE instrumentation toolkit [[pevisor]] (Nitr0-G; PeVisor component; [[blackbone]] process control/hooking/mapping + Unicorn emulation workflows; sample protection/unprotection test targets; malware/game-security PE internals research; README [PE]) extends the same Windows binary instrumentation lane. (source: wiki/sources/descriptions/Nitr0-G__PeVisor.md) Live Linux/KVM guest physical-memory introspection via [[memflow-kvm]] (memflow connector; kernel module maps guest pages into userspace with page-table walking; ioctl char device + Rust bindings; bypasses standard KVM APIs for fast cross-VM reads) complements offline RAM/dump forensics on QEMU/KVM lab hosts. (source: wiki/sources/descriptions/memflow__memflow-kvm.md) KVM guest introspection framework [[introvirt]] (IntroVirt; patched KVM hypervisor + C++ userland library + symbol parsing; runtime guest memory/execution inspect/control; process/thread introspection, breakpoints, memory access, syscall visibility; Windows/Linux guest analysis; out-of-guest monitoring / malware RE; README Guest introspection library) extends that live KVM lane with higher-level analyst APIs. (source: wiki/sources/descriptions/IntroVirt__IntroVirt.md) From-scratch KVM API tutorial such as [[kvm-kernel-example]] (minimal VMM + guest kernel; custom hypercalls, memory management, syscall/ELF loading; guide lane for hypervisor virtualization internals) (source: wiki/sources/descriptions/david942j__kvm-kernel-example.md) Live kernel-space process dumpers such as [[ks-dumper]] (EquiFox; C++ custom driver + client; PE header/section rebuild; AC-restricted handle targets) and [[ksdumper-11]] (custom KM driver + C# GUI; KDU vulnerable-driver load; PE header parse; blocklist bypass) capture protected game/process memory for the same AC / dump RE lane. (source: wiki/sources/descriptions/EquiFox__KsDumper.md) (source: wiki/sources/descriptions/mastercodeon314__KsDumper-11.md) Lightweight usermode mapped-PE dumpers such as [[dumpepe]] (OpenProcess/ReadProcessMemory; DOS/NT → `SizeOfImage` full section dump; x86/x64 CLI; PID + base + output; post-unpack packed EXE static RE; d35ha) complement that lane when RPM access suffices. (source: wiki/sources/descriptions/d35ha__DumpPE.md) Anti-tamper PE dumpers such as [[vulkan]] (atrexus; C++; iteratively resolve NOACCESS pages until Hyperion/Theia-style dynamic code encryption decrypts; import resolution; Roblox/The Finals tested; Dump lane) extend that lane when encrypted pages block plain RPM reconstruction. (source: wiki/sources/descriptions/atrexus__vulkan.md) Live-process injected-cheat module dumpers such as [[csgo-p2c-dumper]] (ch4ncellor; CS:GO internal P2C targets; signature scan, hook-displacement JMP tracing, allocation diff; logs decoded assembly and handler RVAs; Dump lane for AC / injection RE) extend that lane when studying concealed manual-mapped cheat modules. (source: wiki/sources/descriptions/ch4ncellor__CSGO-P2C-Dumper.md) Live Windows page-table inspection via [[ptview]] (VollRagm; kernel driver + C# GUI; browse/dump PTEs and physical pages, VA→PA translation, large-page awareness; in-process memory-mapping RE without full RAM capture). (source: wiki/sources/descriptions/VollRagm__PTView.md) - **Disk / file forensics:** tools such as [[file-recovery-tool]] recover deleted files on NTFS/FAT32/ExFAT via MFT/USN scan, signature carving, and sector-level reassembly (pure Win32; direct disk). (source: wiki/sources/descriptions/wesmar__FileRecoveryTool.md) macOS command-line forensic disk imaging via [[ftk-imager-osx]] (MrMugiwara; package + usage guide for FTK Imager CLI; drive acquisition, split outputs, MD5/SHA1 verification, E01/SMART formats, fragmentation/compression/evidence metadata; DFIR practitioners on macOS; Forensics Tools For MAC OS X). (source: wiki/sources/descriptions/MrMugiwara__FTK-imager-OSX.md) NTFS volume inspectors such as [[ntfstool]] read MBR/partition/VBR, MFT, BitLocker/EFS, and USN journal for AC / IS forensics. (source: wiki/sources/descriptions/thewhiteninja__ntfstool.md) Pre-OS UEFI NTFS R/W such as [[ntfs-efi]] (EfiNtfs; full MFT/B+tree engine; EFI Commander dual-panel FAT32/NTFS VFS; offline recovery / forensic extraction before Windows loads) (source: wiki/sources/descriptions/wesmar__NTFS_EFI.md) User-mode Windows API ESP mount utilities such as [[mount-system-partition]] (brew02; C++; programmatic mount of hidden EFI system partition; no external tools; UEFI/firmware RE access) (source: wiki/sources/descriptions/brew02__MountSystemPartition.md) Change-journal ↔ MFT correlators such as [[ntfs-linker]] rebuild NTFS activity timelines (paths + create/modify/rename/delete) from `$MFT` / `$UsnJrnl` / `$LogFile`. (source: wiki/sources/descriptions/strozfriedberg__ntfs-linker.md) Python NTFS forensic parser suites such as [[ntfs-parse]] (NTFSparse; links MFT/$LogFile/$UsnJrnl; CLI record export, transaction parsing, timeline PoC; parsed text/CSV; digital forensics / filesystem research). (source: wiki/sources/descriptions/NTFSparse__ntfs_parse.md) Focused NTFS USN / change-journal tooling such as [[usn]] (C++; AC / IS forensics). (source: wiki/sources/descriptions/rbmm__USN.md) NTFS change-journal viewers such as [[ntfs-journal-viewer]] (C; `$UsnJrnl` inspection; AC / IS forensics). (source: wiki/sources/descriptions/mgeeky__ntfs-journal-viewer.md) NTFS anti-forensics tooling such as [[antfs]] (ch3rn0byl; user-mode MFT deleted-file recovery + WDK kernel driver overwrite of file records/content; secure deletion at filesystem-driver level; Delete File / anti-forensics research). (source: wiki/sources/descriptions/ch3rn0byl__ANTfs.md) Curated anti-forensic technique knowledge bases such as [[anti-forensics]] (ashemery; README-indexed data hiding, log tampering, registry/FS artifact manipulation, virtualization evasion; DFIR tradecraft patterns; IS forensics study). (source: wiki/sources/descriptions/ashemery__Anti-Forensics.md) Executable post-exploitation trace-reduction tooling such as [[forensia]] (PaulNorman01; C++; file shredding, event-log/prefetch suppression, USN journal handling, timestamp cleanup, shell/cache artifact removal, Defender quarantine clearing, self-removal; red-team simulation and defensive IR/forensic workflow validation) complements those catalogs with a concrete Windows anti-forensics utility lane. (source: wiki/sources/descriptions/PaulNorman01__Forensia.md) Locked-file / running-executable self-deletion PoCs such as [[delete-self-poc]] (LloydLabs; C; rename primary data stream then SetFileInformationByHandle file disposition; handle sequencing and locked-file removal edge cases; anti-forensics / secure cleanup / defensive detection engineering). (source: wiki/sources/descriptions/LloydLabs__delete-self-poc.md) Locked-file acquisition without stopping the holding process via [[idontlikefilelocks]] (EvilBytecode; C++; memory-mapped section handle theft, remote handle duplicate/close; low-noise browser-database reads; authorized file-lock evasion / info-stealer tradecraft research; README Dump locked files by stealing memory-mapped section handle) (source: wiki/sources/descriptions/EvilBytecode__IDontLikeFileLocks.md) Bootable Linux secure disk erasure via [[shredos-x86-64]] (PartialVolume; Buildroot + nwipe; DoD/Gutmann/PRNG passes and verification modes; multi-drive; BIOS/UEFI IMG/ISO for x86/x64; optional wipe certificates/logs; media sanitization before reuse/disposal; Disk Eraser / IS forensics) complements recovery and anti-forensics tooling in the same lane. (source: wiki/sources/descriptions/PartialVolume__shredos.x86_64.md) Same-author SearchEx tooling such as [[searchex]] (C++; hooking / memory analysis; AC / IS forensics). (source: wiki/sources/descriptions/rbmm__SearchEx.md) TrustedInstaller-token launchers such as [[cmdt]] (asm GUI/CLI; TI token duplication) help RE/forensics workflows reach TI-ACL–protected OS components without taking ownership. (source: wiki/sources/descriptions/wesmar__CmdT.md) Windows access-token theft/impersonation PoCs such as [[manipulating-token]] (C/C++; SeDebugPrivilege + SYSTEM integrity-level token manipulation; gmh5225) sit in the same privilege-escalation study lane. (source: wiki/sources/descriptions/gmh5225__manipulating_token.md) Educational MBR bootkit / NTFS crypto PoCs such as [[openpetya]] (Petya-inspired; MBR replacement; MFT Salsa20 encryption; bootloader key derivation; Assembly/C/C++) complement MFT forensics tooling for studying disk-level ransomware mechanics. (source: wiki/sources/descriptions/iss4cf0ng__OpenPetya.md) - **Live DFIR triage:** Python Windows triage collectors such as [[dfirtriage]] automate process/network/scheduled-task/registry/event-log/prefetch/browser-history collection into a structured output directory for rapid IR evidence preservation before offline RE. (source: wiki/sources/descriptions/travisfoley__dfirtriage.md) Structured Markdown artifact reference guides such as [[windows-forensic-artifacts]] (Psmths; execution/account/file/network/persistence/user-activity domains; artifact locations, parsing options, timeline correlation; DFIR practitioner reference; not executable tooling) complement automated collectors in the same IS forensics lane. (source: wiki/sources/descriptions/Psmths__windows-forensic-artifacts.md) Game-security–focused AC inventory scanners such as [[anticheat-scanner]] (PickAngE; Python; read-only local scan of drivers/services/registry/BAM/Prefetch/MUICache + PE/Authenticode against a signature DB; ACE/EAC/BattlEye/EA AC/HoYoProtect) apply the same artifact layers to enumerate commercial anti-cheat footprint. (source: wiki/sources/descriptions/PickAngE__AntiCheat-Scanner.md) Live ETW event and system debug-log capture via [[dbgviewex]] (emlinhax; early-stage; cheat / RE telemetry) complements scripted triage when studying offensive kernel or cheat tooling in real time. (source: wiki/sources/descriptions/emlinhax__DbgViewEx.md) Lightweight standalone C utilities such as [[volatile-data-collector]] (handles, kernel modules, user sessions, drivers, ICMP connections, registry settings; per-artifact tools) complement scripted triage for granular volatile-state collection during IR. (source: wiki/sources/descriptions/gtworek__VolatileDataCollector.md) Offline AppCompat ShimCache parsers such as [[shimcacheparser]] extract program execution history (paths, timestamps, execution flags) from SYSTEM hives (XP–Win10; CSV/timeline export) for the same IS forensics lane. (source: wiki/sources/descriptions/mandiant__ShimCacheParser.md) AD domain host enumerators such as [[netview]] (`-d` current or specified domain; mubix) map enterprise endpoints in the same IS forensics lane. (source: wiki/sources/descriptions/mubix__netview.md) Fleet-scale remote live forensics via [[grr]] (Google GRR Rapid Response; Python server + HTTP endpoint agents; artifact/file/memory/registry collection and Python analysis flows at scale; remote live forensics). (source: wiki/sources/descriptions/google__grr.md) - **Host credential harvest:** Go static-binary collectors such as [[pillager]] export/decrypt browser passwords/cookies/history, Wi-Fi profiles, and chat-app data from Windows hosts (authorized pentest / red-team credential collection). (source: wiki/sources/descriptions/qwqdanchun__Pillager.md) Focused Python browser-password forensics utilities such as [[browser-password-exportor]] (BL0odz; Chromium/Edge/Firefox profile DBs; DPAPI/AES + Firefox key-material parsing; ASN.1 and browser-specific login-storage routines; credential forensics / browser secret-storage RE) complement those broad collectors with a narrow decrypt-and-export study surface. (source: wiki/sources/descriptions/BL0odz__BrowserPasswordExportor.md) Cross-platform modular credential-recovery frameworks such as [[lazagne]] (AlessandroZ; Python; modular collectors for browsers, mail clients, databases, chat apps, and other locally stored secrets; post-exploitation, auditing, and forensic credential-exposure assessment) extend that lane with application-family breadth across platforms. (source: wiki/sources/descriptions/AlessandroZ__LaZagne.md) .NET information-stealer samples such as [[qvoid-token-grabber]] (Enum0x539; Discord token harvest, browser cookie/password extraction, screenshot/Wi-Fi/clipboard collection, webhook exfiltration, anti-debug/anti-VM/anti-sandbox/anti-emulation; malware-analysis research into account-token abuse workflows) extend that lane with Discord-centric stealer tradecraft. (source: wiki/sources/descriptions/Enum0x539__Qvoid-Token-Grabber.md) - **Messaging / OSINT:** Python Telegram channel/chat collectors such as [[teleparser]] (Telethon API; JSON/CSV export + MongoDB; NLTK lemmatizer; cross-platform setup; README warns Telegram API changes may require updates before safe run; IS forensics / cheat-community message analysis). (source: wiki/sources/descriptions/artmih24__TeleParser.md) - **Linux live memory:** OllyDbg-style ptrace debugger [[edb-debugger]] (Qt GUI; disasm/registers/memory map/stack/breakpoints; x86/x86-64; plugin extensibility; eteran) complements GDB-based [[pince]] for graphical stepping workflows. (source: wiki/sources/descriptions/eteran__edb-debugger.md) Go CLI debugger [[fastdbg]] (x64 ELF; ptrace breakpoints/memory/registers/disasm; eBPF tracing + QEMU kernel-debug modules; Yayoi-cs; x86_64 native/qemu kernel debugger) offers a lightweight command-interface alternative beside GUI debuggers. (source: wiki/sources/descriptions/Yayoi-cs__fastDbg.md) Cheat Engine–like GDB front-end [[pince]] (PINCE Is Not Cheat Engine; Qt GUI; memory scan/edit, pointer chains, code injection, breakpoints, CE table support; Python + GDB) for Linux game hacking and RE. (source: wiki/sources/descriptions/korcankaraokcu__PINCE.md) Non-GDB `/proc/pid/mem` CLI scanner [[mempeek]] (Rust; libprocmem maps; CE-style scan filters; multi-radix REPL) offers lightweight live introspection beside [[pince]]. (source: wiki/sources/descriptions/gamozolabs__mempeek.md) Kernel-module cross-process R/W via [[taxi-driver]] (ALittlePatate; C/C++ LKM + userland; device-interface RPM/WPM and base-address lookup; example clients; game memory tooling + Linux security research) complements those user-mode paths when kernel-assisted memory access is required. (source: wiki/sources/descriptions/ALittlePatate__TaxiDriver.md) C++14 `/proc/pid/maps` parsers such as [[procmap]] (`MemorySegment` objects; address ranges, permissions, file offsets, backing paths; live layout analysis for forensics and game-security tooling) complement those workflows. (source: wiki/sources/descriptions/joaomlneto__procmap.md) Ptrace ELF injectors such as [[mandibule]] (C; icrt; runtime ELF load/relocate; fake stack; position-independent payload args) illustrate attach-and-run injection tradecraft beside those introspection tools. (source: wiki/sources/descriptions/ixty__mandibule.md) Lightweight ptrace syscall tracer [[pawtrace]] (C + assembly; attach or spawn; x86-64 syscall decode with argument inspection, socket addresses, W^X memory, `/proc/maps` snapshots, JSONL output; remote tracing via TCP; cocomelonc) complements GUI debuggers for scripted syscall forensics. (source: wiki/sources/descriptions/cocomelonc__pawtrace.md) - **Linux LKM metadata / hooks:** tools such as [[vermagic]] rewrite vermagic / CRC fields so a module can load across mismatched kernel builds (cheat / RE tools lane). (source: wiki/sources/descriptions/yaxinsn__vermagic.md) Raw Linux kernel images → symbolized ELF via [[vmlinux-to-elf]] (Python; kallsyms extract + section-header rebuild; `vmlinux`/`bzImage`/`zImage` → IDA/Ghidra) support offline kernel binary RE with named functions. (source: wiki/sources/descriptions/marin-m__vmlinux-to-elf.md) Live `/proc/kallsyms` → IDA rename via [[ida-kallsyms-symbol-renamer]] (gmh5225; import kernel symbols; auto-rename functions and data labels in kernel/LKM IDBs; cheat / IDA Plugins) complements that offline path when a matching running kernel exposes kallsyms. (source: wiki/sources/descriptions/gmh5225__IDA-KallsymsSymbolRenamer.md) Saved kallsyms dump → IDA symbol import via [[import-kallsyms]] (XMCVE; Python; map symbol names/addresses into stripped or partially symbolized kernel IDBs; cheat / IDA Plugins) offers the same lane from offline dumps. (source: wiki/sources/descriptions/XMCVE__import-kallsyms.md) AArch64 **MSR/SYS** register naming via [[aarch64-sysreg-ida]] (TrungNguyen1909; Python IDA plugin; hooks instruction display; embedded ARMv8 register database + optional Apple register JSON; ARM OS/kernel RE; cheat / IDA Plugins) complements symbol import when analyzing AArch64 kernel and driver code. (source: wiki/sources/descriptions/TrungNguyen1909__aarch64-sysreg-ida.md) ELF external library call resolution in IDA via [[autoresolv]] (airbus-seclab; IDAPython; PyQt5 + pyelftools; resolve imported calls, map wrappers to real implementations, annotate call sites, import signatures from related binaries; multi-arch; cheat / IDA Plugins) complements those Linux ELF static-RE helpers. (source: wiki/sources/descriptions/airbus-seclab__AutoResolv.md) ELF64 PLT repair when IDA auto-analysis fails via [[plt-patcher]] (GAMMACASE; Python IDAPython; repair Procedure Linkage Table entries + preserve inferred argument types on extern thunks during decompilation; cheat / IDA Plugins) sits in the same PLT/thunk recovery lane beside [[plthook]]. (source: wiki/sources/descriptions/GAMMACASE__PltPatcher.md) API-driven auto-renaming and behavioral tagging via [[auto-re]] (a1ext; Python IDA Pro plugin; rename dummy functions from imports/jump targets; tag networking, injection, crypto, file activity; dedicated tag view; cheat / IDA Plugins) accelerates unfamiliar binary triage beside [[autorename]] and [[renamaida]]. (source: wiki/sources/descriptions/a1ext__auto_re.md) Windows COM static analysis in IDA via [[comida]] (airbus-cert; scan COM GUID refs + registry metadata; Hex-Rays type inference on `CoCreateInstance` / `CoGetCallContext` / `QueryInterface`; malware/game COM triage; cheat / IDA Plugins) complements live COM tracing via [[comon]]. (source: wiki/sources/descriptions/airbus-cert__comida.md) Kernel rootkit hooking samples such as [[venom]] (C/C++; LKM hook mechanisms; cheat / linux kernel explorer) sit alongside for studying offensive Linux kernel hook surfaces. (source: wiki/sources/descriptions/sad0p__venom.md) Educational Linux rootkit sample corpus [[rootkit]] (MatheuZSecurity; C kernel/user/eBPF subprojects; file/connection hiding, syscall/ftrace hooking, privilege escalation, persistence, anti-forensics; build scripts + per-mechanism write-ups; offensive/defensive + anti-rootkit detection testing) extends that lane. (source: wiki/sources/descriptions/MatheuZSecurity__Rootkit.md) Multi-arch **Linux kernel inline-hook framework** [[kernel-hook-framework]] (WeiJiLab; trampoline patching + extended kallsyms resolution; proc runtime control; x86/x86_64/ARM/ARM64/riscv64; kernel debug + anti-cheat kernel research) offers a structured LKM hook lane beside those samples. (source: wiki/sources/descriptions/WeiJiLab__kernel-hook-framework.md) LLDB-based live/offline Linux kernel debugger [[klldb]] (djolertrk; kLLDBLive + offline post-mortem plugin; LLVM-19; Python scripting; LLDB instead of GDB/KGDB workflows) complements that lane for kernel developers and security researchers. (source: wiki/sources/descriptions/djolertrk__kLLDB.md) Defensive hidden-module discovery via [[modreveal]] (C; find concealed LKMs; Detection:Hide) complements that lane for AC / rootkit RE. (source: wiki/sources/descriptions/jafarlihi__modreveal.md) Defensive **Linux kernel integrity monitors** such as [[ksentinel]] (MatheuZSecurity; LKM; function prologue hashing, syscall table validation, LSTAR checks; configurable intervals + anti-unload; rootkit hook-tampering detection research) extend that lane. (source: wiki/sources/descriptions/MatheuZSecurity__ksentinel.md) ARM64 Linux **silent syscall hook** PoC [[arm64-silent-syscall-hook]] (3intermute; C; patches kernel SVC handling path instead of `sys_call_table`; manual function splicing + trampoline-style exception-handler patching; selected syscall redirect with reduced table-tamper indicators; stealth rootkit + syscall-hook detection research; README ARM64 Patching exception handler) complements that defensive lane. (source: wiki/sources/descriptions/3intermute__arm64_silent_syscall_hook.md) Linux **io_uring-backed post-exploitation agent** [[ring-reaper]] (MatheuZSecurity; C + Python control server; minimizes EDR visibility by routing file/process/network/session ops through async io_uring instead of traditional syscalls; offensive security + EDR evasion research) (source: wiki/sources/descriptions/MatheuZSecurity__RingReaper.md) Upstream Linux kernel development documentation via [[kernel-development]] (Greg Kroah-Hartman; patch workflow, coding style, device drivers, LKM programming; cheat / guide lane) supports that tooling with canonical upstream conventions. (source: wiki/sources/descriptions/gregkh__kernel-development.md) - **Mobile / iOS:** offline mobile RE suite [[sako-restudio]] (Maxamedxasa; Capstone disasm + IR decompiler + ptrace debugger + call graph + SakoScript plugins; APK/ELF/PE/DEX on ARM64/x86-64; Jetpack Compose + SQLite projects; optional local/OpenAI-compatible AI function explain; air-gapped IDA/Ghidra-like workflow on Android; cheat / RE Tools) (source: wiki/sources/descriptions/Maxamedxasa__SakoREStudio.md); [[apktool]] (Java APK decode/rebuild; smali/DEX, resources, manifest; `[Apk]`) (source: wiki/sources/descriptions/iBotPeaches__Apktool.md); Windows GUI wrapper [[apktoolgui]] (AndnixSH; C#/.NET; apktool + signapk + zipalign + baksmali; drag-and-drop decompile/rebuild/sign/align; ADB helpers + framework management; legitimate Android app analysis; `[Apk]`) (source: wiki/sources/descriptions/AndnixSH__APKToolGUI.md); VS Code Android RE workbench [[apklab]] (APKLab; TypeScript; Apktool + JADX + signing + HTTPS patch helpers; decode/disasm/decompile/rebuild/sign/install/bootstrap; cross-platform; mobile security / malware / tampering; `[Apk]`) (source: wiki/sources/descriptions/APKLab__APKLab.md); Bash APK RE orchestration [[apk-sh]] (ax; pull/decode/rebuild/patch, Frida gadget inject, split/bundle merge, apksigner re-sign; multi-arch; no root) (source: wiki/sources/descriptions/ax__apk.sh.md); on-device ARM64 ROM/APK unpack-pack toolkit [[tool-tree]] (Zenlua; boot/super/APK/APKS/APEX firmware + apktool-style decode/build; root or non-root; Kotlin/Java + KRScript UI) (source: wiki/sources/descriptions/Zenlua__Tool-Tree.md); Termux on-device APK modding TUI [[auto-android-app-modding-tool]] (UAMT; Python; Frida Gadget + native `.so` inject; patchelf/APKEditor auto-select; zipalign + v1/v2/v3 sign; no root) (source: wiki/sources/descriptions/VarshaWanjari0__Auto-Android-App-Modding-Tool.md); on-device package manager/auditor [[app-manager]] (MuntashirAkon; component/permission/app-op control, APK analysis/sign/edit, backup, logcat, tracker scan, root/ADB; mobile RE / app auditing) (source: wiki/sources/descriptions/MuntashirAkon__AppManager.md); Android app virtualization framework [[virtual-app]] (ServenScorpion; isolated cloned-app container; Java/native hooks; Xposed + SandHook; virtual package/process/component management; mobile RE / multi-instance sandbox) (source: wiki/sources/descriptions/ServenScorpion__VirtualApp.md); Google [[android-classyshark]] standalone APK/DEX/AAR/class bytecode viewer (class hierarchies, dependencies, multidex; interactive GUI triage) (source: wiki/sources/descriptions/google__android-classyshark.md); hidden **non-SDK API** bypass library [[bypass-hidden-api-restriction]] (WindySha; Java/Kotlin + JNI/CMake; Android 9–12 startup init; restricted platform-interface access for compatibility / security research) (source: wiki/sources/descriptions/WindySha__bypassHiddenApiRestriction.md); pure-Java alternative [[android-hidden-api-bypass]] (LSPosed; HiddenApiBypass + LSPass; invoke restricted methods/constructors, read hidden fields, manage exemption prefixes; no native code; modern Android dependency packaging; advanced instrumentation / compatibility / security research) (source: wiki/sources/descriptions/LSPosed__AndroidHiddenApiBypass.md); multi-decompiler Java/Android suite [[bytecode-viewer]] (CFR, Procyon, FernFlower, JD-GUI, Krakatau; tabbed bytecode/decompiled source/Smali for JAR/class/DEX/APK; search, strings, plugins; `[Java]`) (source: wiki/sources/descriptions/gmh5225__bytecode-viewer.md); modern JVM/Android bytecode workstation [[recaf]] (Col-E; Java; multi-decompiler, bytecode assembly, recompile, deep class/constant/instruction search, deobfuscation transforms + malformed-input handling; `[Java]`) (source: wiki/sources/descriptions/Col-E__Recaf.md); DEX control-flow obfuscator [[black-obfuscator]] (CodingGay; Java; modified dex2jar pipeline; behavior-preserving bytecode transform; configurable depth/package/rules; GUI + Android Studio plugin; mobile protection / anti-RE research; `[Dex]`) (source: wiki/sources/descriptions/CodingGay__BlackObfuscator.md); modular Python black-box APK obfuscator [[obfuscapk]] (ClaudiuGeorgiu; apktool decompile → smali/resources/manifest obfuscation passes → rebuild; multiple obfuscators; early AAB support via external decompiler; mobile RE resilience / signature-evasion evaluation; `[Android]`) (source: wiki/sources/descriptions/ClaudiuGeorgiu__Obfuscapk.md); native-assisted DEX deobfuscation/search library [[dexkit-android]] (LuckyPray; C++ NDK + JNI/Kotlin; string/relation/opcode-pattern class and method discovery; Gradle/prefab/CMake; hook-point and obfuscated-code navigation; cheat / dex deobfuscator) (source: wiki/sources/descriptions/LuckyPray__DexKit-Android.md); Java Android Dalvik deobfuscation via [[simplify]] (CalebFenton; virtual execution + optimization passes — constant propagation, dead code, reflection cleanup; obfuscated app analysis; `[Java]`) (source: wiki/sources/descriptions/CalebFenton__simplify.md); native C++ programmatic DEX construction via [[dexbuilder]] (LSPosed; AOSP-derived dexmaker alternative; runtime integration; source: wiki/sources/descriptions/LSPosed__DexBuilder.md); eBPF in-memory DEX dump via [[ebpf-dex-dumper]] (LLeavesG; Go; ART activity capture + auto-repair; UID/package filter; method traces; rooted ARM64; dynamically loaded bytecode recovery; cheat / DexDumper based eBPF on Android Platform) (source: wiki/sources/descriptions/LLeavesG__eBPFDexDumper.md); historical kernel `tfp0` exploit study via [[oob-entry]] (iOS 3.0–10.3.4; C/C++; cheat / iOS jailbreak) (source: wiki/sources/descriptions/staturnzz__oob_entry.md); semi-untethered rootless jailbreak [[dopamine]] (iOS 15.0–15.4.1; kernel R/W + PAC/PPL/AMFI; `/var/jb` bootstrap) (source: wiki/sources/descriptions/opa334__Dopamine.md); iOS 15/16 RootHide Dopamine 2 fork [[dopamine2-roothide]] (C/C++/ObjC; kernel-level / plugins; cheat / iOS jailbreak) (source: wiki/sources/descriptions/roothide__Dopamine2-roothide.md); checkm8 developer jailbreak [[palera1n]] (iOS 15+ A8–A11; rootful/rootless; AMFI/codesigning off + Sileo) (source: wiki/sources/descriptions/palera1n__palera1n.md); userland exploit-chain study via [[lightsaber]] (iOS 18.4–18.6.2 JS injection into SpringBoard and other processes) (source: wiki/sources/descriptions/zeroxjf__lightsaber.md); WIP DarkSword kexploit study via [[lara]] (iOS 17.1.1–26.0.1; font overwrite / app bypass / DirtyZero2; C/C++/Swift) (source: wiki/sources/descriptions/rooootdev__lara.md); XNU kernel KRW exploit [[dirty-zero]] (CVE-2025-24203; zero-day/recent XNU bug → reliable kernel R/W; jailbreak-chain component) (source: wiki/sources/descriptions/jailbreakdotparty__dirtyZero.md); DarkSword kernel r/w playground [[darksword-kexploit-fun]] (iOS/iPadOS 17.0–26.0.1 except A19/M5; sandbox escape / SSV root FS / PAC·TaskROP) (source: wiki/sources/descriptions/wh1te4ever__darksword-kexploit-fun.md); XNU 1-day exploit practice [[xnu-1day-practice]] (Mach IPC voucher / IOSurface / IOAccelerator PoCs + KRW helpers; C/ObjC) (source: wiki/sources/descriptions/wh1te4ever__xnu_1day_practice.md); QEMU ARM64 full-system iOS/XNU emulation via [[xnu-qemu-arm64]] (Aleph Security fork; launchd/bash, unsigned binaries, SSH tunnel, optional KVM; iOS machine models for kernel/runtime lab study; cheat / xnu) (source: wiki/sources/descriptions/alephsecurity__xnu-qemu-arm64.md); Apple Silicon QEMU fork [[qemu-apple-silicon]] (ChefKissInc; full QEMU tree + platform mods; hardware-accelerated ARM virtualization on macOS; iOS device emulation; iOS security RE / app testing and analysis; IOS Emulator) (source: wiki/sources/descriptions/ChefKissInc__qemu-apple-silicon.md); Apple Silicon macOS virtualized iPhone CLI [[vphone-cli]] (Lakr233; Swift + Python iBoot/kernel/TXM patchers, ramdisk/CFW builders; Virtualization.framework PCC research VM; SIP/AMFI off; DFU/restore; iOS RE / virtualized iOS lab) (source: wiki/sources/descriptions/Lakr233__vphone-cli.md); native macOS SwiftUI VM manager [[vphone-ws]] (zqxwce; wraps [[vphone-cli]]; browse/create/boot/clone/export/delete iOS research VMs; creation wizard + host readiness checks; IOS Emulator) (source: wiki/sources/descriptions/zqxwce__vphone-ws.md); one-script pre-jailbroken vphone bundle [[vphone-aio]] (34306; shell script + archive; automates [[vphone-cli]] download/merge/extract on macOS; SIP/AMFI off; full bootstrap; ready jailbroken iOS app-analysis lab; IOS Emulator) (source: wiki/sources/descriptions/34306__vphone-aio.md); iOS 27 beta CFW jailbreak toolkit [[usbliter8-fun]] (34306; usbliter8 SecureROM → PWN DFU; RP2350/Pico 2 + Lightning; Python CFW/patch/ramdisk + userland binary patch; A12/A13 iPhone 11 Pro; destructive CFW restore; cheat / iOS jailbreak) (source: wiki/sources/descriptions/34306__usbliter8-fun.md); Swift jailed-device system UI customization app [[mdc0]] (34306; iOS 15.0–18.3.2; exploit path writes normally read-only system files for dock/blur/lockscreen tweaks + respring helper; CVE-2025-24203; cheat / iOS jailbreak) (source: wiki/sources/descriptions/34306__mdc0.md); QEMU Darwin VM [[darwin-vm]] (jprx; boot iOS/macOS to root shell without jailbreak; virtual iPhone 12–17 and M1–M5 Macs; custom qemu-sptm fork; SPTM/TXM/MIE kernel debug; GDB/LLDB; no GUI/SpringBoard; fast reproducible Apple platform sandbox; IOS Emulator) (source: wiki/sources/descriptions/jprx__darwin-vm.md); iOS 14.0–14.4.2 kernel R/W exploit app [[humptylock]] (Coruna Pendulum PE extension; lockf / Mach OOL-port / NECP kalloc / pipe corruption → stable KRW; PAC unsign; C/ObjC Xcode) (source: wiki/sources/descriptions/wh1te4ever__HumptyLock.md); checkra1n-era XNU kernel function hooking framework [[xnuspy]] (A8–A11; no 4K; kernel hook research) (source: wiki/sources/descriptions/jsherman212__xnuspy.md); XNU kernel file-descriptor exploit framework [[kfd]] (felix-pb; C; chains XNU bugs → stable kernel R/W; iOS 15/16; jailbreak/sandbox-escape research; cheat / iOS jailbreak) (source: wiki/sources/descriptions/felix-pb__kfd.md); iOS kernel memory explorer [[kfd-explorer]] (Python/Swift; kernel R/W memory browse/analysis; cheat / iOS memory explorer) (source: wiki/sources/descriptions/hackcatml__kfd-explorer.md); iOS project reversing in IDA via [[ida-ios-helper]] (vtable symbols required) (source: wiki/sources/descriptions/yoavst__ida-ios-helper.md); Ghidra-backed desktop decompiler for iOS IPA and macOS app bundles via [[malimite]] (LaurieWired; Java; Apple resource decode, Swift class reconstruction, Swift/ObjC binaries; malware analysis and Apple app security RE; cheat / iOS and macOS Decompiler) (source: wiki/sources/descriptions/LaurieWired__Malimite.md); Android native `.so` breakpoint setup in IDA via [[ida-android-breakpoint]] (Python IDA plugin; cheat / IDA Plugins) (source: wiki/sources/descriptions/lj94093__IDAAndroidBreakpoint.md); ARM64 Android shellcode framework [[armshellcode]] (IIIImmmyyy; position-independent arm64-v8a payload generation; Dobby symbol resolution; ELF/proc-maps parsing, syscall wrappers, modular loader + linker scripts; exploit / runtime injection study; cheat / Android arm arm64-v8a ShellCode Generate) (source: wiki/sources/descriptions/IIIImmmyyy__ArmShellCode.md); ARM mobile cache side-channel toolkit [[armageddon]] (IAIK; Prime+Probe, Flush+Reload, Evict+Reload, Flush+Flush, cache template workflows; mobile privacy, crypto side channels, TrustZone observation; README Cache attacks on ARM) (source: wiki/sources/descriptions/IAIK__armageddon.md); LLM ARM64→C/ObjC/Swift pseudo-code for Mach-O (apps / kernelcache / DSC) via [[aimachdec]] (source: wiki/sources/descriptions/s3rg0x__AIMachDec.md); Objective-C dynamic-dispatch cleanup via [[workflow-objc]] (Vector35; C++ Binary Ninja workflow plugin; rewrites objc_msgSend-style calls into inferred direct-call HLIL when selector targets resolve; macOS/iOS ObjC-heavy binaries; migrated into main BN API; Cheat Binary Ninja Plugins / `[Objective-C]`) (source: wiki/sources/descriptions/Vector35__workflow_objc.md); Apple runtime inspection GUI [[runtime-viewer]] (MxIris-Reverse-Engineering; Swift/ObjC; browse ObjC/Swift metadata from loaded binaries/frameworks; syntax-highlighted interface views, export, framework loading, local/network runtime access; WIP code injection; macOS/iOS dynamic analysis; Objective-C Runtime Viewer for macOS and iOS) (source: wiki/sources/descriptions/MxIris-Reverse-Engineering__RuntimeViewer.md); runtime-assisted Objective-C class-dump CLI [[dynadump]] (DerekSelander; ObjC; list dylibs, enumerate classes, dump interfaces, demangled signatures, in-place signing; dlopen + exception-handling to avoid constructor side effects; Apple binaries + shared cache; macOS/iOS RE; A runtime ObjC class-dump) (source: wiki/sources/descriptions/DerekSelander__dynadump.md); iOS kernelcache IDA analysis via [[ida-kernelcache-ng]] (pip package + `cli.py`; cheat / IDA Plugins) (source: wiki/sources/descriptions/gilboz__ida_kernelcache_ng.md); C++ virtual-call resolution for iOS kernelcaches via [[ida-kcpp]] (IDAPython; class hierarchy from ida_kernelcache; double-click vcall navigation + xref tracking; inspired by [[ida-medigate]]; cheat / IDA Plugins) (source: wiki/sources/descriptions/cellebrite-labs__ida_kcpp.md); PPL gate-call resolution for iOS/macOS kernelcaches via [[pplorer]] (IDAPython; PPL call site ↔ underlying PPL function; Ctrl-Shift-X navigation + xref annotation; ida-netnode persistence; cheat / IDA Plugins) (source: wiki/sources/descriptions/cellebrite-labs__PPLorer.md); A12/A13 Apple PPL bypass library [[momentarius]] (C; IOMobileFramebuffer GPU firmware → IOSurface physmem + ARM64 page-table/shellcode hooks → kernel R/W; A12 Vortex/Tempest + A13 Lightning/Thunder init paths; iOS kernel exploit research) (source: wiki/sources/descriptions/staturnzz__momentarius.md); ANE kernel R/W exploit chain [[weightbufs]] (0x36; Objective-C/C; multi-bug ANE-component chain on Neural-Engine Apple devices; IOKit/IOSurface helpers; iOS 15 + macOS 12; device-range and reliability notes; XNU multi-stage exploitation study; cheat / iOS jailbreak) (source: wiki/sources/descriptions/0x36__weightBufs.md); Mali GPU kernel exploit chain [[pixel-gpu-exploit]] (0x36; C/C++; integer-overflow logic flaws + info leak → arbitrary kernel R/W; SELinux disablement + root; Pixel 7/8 Pro Android 14; Android kernel/GPU attack-surface study; cheat / Root for Pixel7/8 Pro with Android 14) (source: wiki/sources/descriptions/0x36__Pixel_GPU_Exploit.md); title-specific Battle Cats mobile asset toolkit [[battle-cats-complete]] (Rust; encrypted `.pack`/APK/XAPK decrypt, format parse, animation render/export, mod authoring; mobile game data RE) (source: wiki/sources/descriptions/omochikaeri15__battle-cats-complete.md) - **Console / QEMU:** upstream Oracle VirtualBox via [[virtualbox]] (open-source x86_64 VMM; CPU/memory virtualization, device emulation, guest additions, COM/IOCTL interfaces; hypervisor-internals and VM-based security research baseline) complements QEMU/PVE lab hosts for game-security RE. (source: wiki/sources/descriptions/VirtualBox__virtualbox.md); lsxll666/AntiCheatToggle (WinForms utility; temporarily stop/disable Tencent ACE / Perfect World / Reason CyberSecurity kernel drivers blocking VirtualBox spawn with VERR_INVALID_NAME (-104); research-host troubleshooting beside anti-detection builds; cheat / QEMU/KVM/PVE/VBOX) (source: wiki/sources/README-categories.md) (source: wiki/sources/descriptions/lsxll666__AntiCheatToggle.md); VirtualBox with a KVM backend via [[virtualbox-kvm]] (cyberus-technology; manual GPU-accel setup; QEMU/KVM/PVE/VBOX research-host lane) also sits in that lane. (source: wiki/sources/descriptions/cyberus-technology__virtualbox-kvm.md); original Xbox titles via [[xqemu]] (full-machine software emulation, no hardware VT) for RE in the QEMU/KVM/PVE/VBOX research lane. (source: wiki/sources/descriptions/xqemu__xqemu.md); original Xbox LLE via [[xemu]] (QEMU fork; NV2A/MCPX/NForce/Pentium III; OpenGL + SDL2). (source: wiki/sources/descriptions/xemu-project__xemu.md); Dreamcast PlanetWeb browser exploit chain via [[defcon-dreamcast-planetweb-research]] (piffd0s; Eden RCE + unbounded `setRawDeviceID` memory write + MIME stack overflow → native SH-4 DOOM without debugger; Python DNS/HTTP/POP3 orchestration; vintage console browser attack-surface RE). (source: wiki/sources/descriptions/piffd0s__Defcon-Dreamcast-Planetweb-Research.md); Game Boy hardware study via [[kevboy]] (Rust CPU/memory/graphics/input emulator). (source: wiki/sources/descriptions/xkevio__kevboy.md); peer Rust GB emulator [[feather-gb]] for retro handheld / GB-area RE. (source: wiki/sources/descriptions/vojty__feather-gb.md); Analogue Pocket openFPGA cheat deploy via [[openfpga-gbc-cheats-ui]] (libretro DB; Game Genie/GameShark; `.cht` SD write). (source: wiki/sources/descriptions/kroy-the-rabbit__openfpga-GBC-cheats-ui.md); multi-system retro emulator [[bizhawk]] (C#/.NET + native cores; TAS/TAStudio, Lua memory+input APIs, RAM search, hex editor, CPU debuggers, savestates/rewind, Game Genie/GameShark decoders; NES/SNES/GB/GBA/Genesis/N64/DS/PS1/MAME; deterministic frame control for cheat/mechanics RE; TASEmulators). (source: wiki/sources/descriptions/TASEmulators__BizHawk.md); cycle-accurate Rust GB/GBC emulator [[gecko]] (CPU/PPU/APU; wgpu; library GUI; README `GameCube/Wii` miscategorization). (source: wiki/sources/descriptions/ioncodes__gecko.md); GBA cartridge static analysis in Ghidra via [[gba-ghidra-loader]] (region/IO map + header entry). (source: wiki/sources/descriptions/pudii__gba-ghidra-loader.md); Game Boy DMG cartridge static analysis in Ghidra via [[ghidradboy]] (Gekkio; Kotlin/Java extension; Sharp SM83 Sleigh; banked/unbanked ROM load, boot ROM variants, memory map blocks, hardware register symbols; retro game binary / firmware RE). (source: wiki/sources/descriptions/Gekkio__GhidraBoy.md); Xbox 360 HLE via [[xenia]] (PowerPC recompiler, D3D12/Vulkan GPU, XAM/kernel/XEX) for console binary-translation / hardware-abstraction study. (source: wiki/sources/descriptions/xenia-project__xenia.md); macOS port [[xenia-mac]] for the same 360 stack on Apple hosts. (source: wiki/sources/descriptions/wmarti__xenia-mac.md); Xbox360→Windows executable porting via [[recompiler]] for emulator / Xbox RE without full HLE. (source: wiki/sources/descriptions/rexdex__recompiler.md); Xbox 360 emulator [[xbox360-emu]] (C/C++; kernel, modding, memory analysis) for console emulator / Xbox RE. (source: wiki/sources/descriptions/exjam__xbox360-emu.md); Xbox 360 XEX static analysis in IDA Pro via [[idaxex]] (C++; XEX parse, PE extraction, import/export resolution, kernel function naming; IDA 9 loader). (source: wiki/sources/descriptions/emoose__idaxex.md); Xbox 360 modded-console backup install + XEX/package patching via [[x360gamehack2025]] (IcyModz420; C# WinForms/.NET; RGH/JTAG/Bad Update/devkit; XEX encrypt/decrypt/compress, ISO→GOD/STFS, FTP/USB deploy; OG Xbox ISO/XBE; without Xbox Neighborhood). (source: wiki/sources/descriptions/IcyModz420__X360GameHack2025.md); Xbox 360 live XBDM trainer/debug via [[toastylink]] (WoahToasty; from-scratch C++17; RGH/JTAG; pointer chains, CE-style scan/freeze, PPC patch assembler, JSON cheat tables, LAN discovery; Cheat Debugging) for network memory RE on modded consoles beside package patching. (source: wiki/sources/descriptions/WoahToasty__ToastyLink.md); Xbox 360 fuse/bootloader/NAND dump for LLE emulator prep via [[xenondumper]] (Byrom90; C/C++; modified retail/devkit privileged access; fuses, bootloader, NAND artifacts; console RE, preservation, emulator preparation) for hardware artifact extraction before PC emulation. (source: wiki/sources/descriptions/Byrom90__XenonDumper.md); Xbox One/Series SystemOS kernel exploit via [[collateral-damage]] (CVE-2024-30088; kernel 25398.4478/4908/4909) for console-emulator / Xbox RE. (source: wiki/sources/descriptions/exploits-forsale__collateral-damage.md); PVE lab helpers such as [[proxmox]] (dialog-driven Proxmox VE scripts) for standing up that research-host lane. (source: wiki/sources/descriptions/tteck__Proxmox.md); quick optimized QEMU guest create/run via [[quickemu]] (Windows/macOS/Linux; portable configs) for the same lane. (source: wiki/sources/descriptions/quickemu-project__quickemu.md); structured QEMU internals guide [[qemu-blog]] (Airbus SecLab; machine/device creation, memory regions, interrupts, timers, PCI, execution flow, TCG; Markdown + source refs; cheat / guide) for virtualization RE. (source: wiki/sources/descriptions/airbus-seclab__qemu_blog.md); browser-tab WASM QEMU via [[qemu-wasm]] (Emscripten; x86/other arch guests; VirtIO/network/storage through browser APIs; client-only VM lab) for the same lane. (source: wiki/sources/descriptions/ktock__qemu-wasm.md); C++ remake [[mvisor]] (kernel-level + rendering/audio) for the same QEMU/KVM/PVE/VBOX research lane. (source: wiki/sources/descriptions/tenclass__mvisor.md); Switch custom firmware platform [[atmosphere]] (Atmosphere-NX; C/C++; Fusee/Exosphere/Stratosphere; boot/runtime patches, TrustZone, sysmodules, emuMMC; console security + homebrew platform study; README [Customized firmware]). (source: wiki/sources/descriptions/Atmosphere-NX__Atmosphere.md); Switch GUI bootloader / CFW entry [[hekate]] (CTCaer; multi-environment boot, payload launch, firmware patches; eMMC/emuMMC backup-restore, partition tools, hardware diagnostics; console modding / firmware research; README [A GUI based Nintendo Switch Bootloader]). (source: wiki/sources/descriptions/CTCaer__hekate.md); Switch Atmosphere homebrew memory RE via [[se-tools]] (scanner / pointer search / cheat manager over `dmnt:cht`). (source: wiki/sources/descriptions/tomvita__SE-tools.md); LLE 3DS emulator [[3beans]] (Hydr8gon; C++; ARM9/ARM11 + Teak DSP interpreters; full OS boot from boot9/boot11/NAND dumps; HLE/LLE audio; software + hardware-accelerated GPU; Windows/macOS/Linux/Android; console-emulator / 3DS hardware RE). (source: wiki/sources/descriptions/Hydr8gon__3Beans.md); raw Luma3DS `.3gx` overlay engine template [[ctr-composer]] (self-rendered UI; any Title ID; revive `.plg`/`.3gx`). (source: wiki/sources/descriptions/samaBR85__CTRComposer.md); OoT3D Luma3DS `.3gx` memory RE / cheat overlay via [[ocarina-ctr-composer]] (on [[ctr-composer]]; search / hex / RAM dump). (source: wiki/sources/descriptions/samaBR85__OcarinaCTRComposer.md); general-purpose Switch read/extract via [[nstool]] (format introspection; console-emulator / Switch-area RE). (source: wiki/sources/descriptions/jakcron__nstool.md); Windows GUI Switch XCI/NSP package inspector [[xci-explorer]] (C# WinForms; XCI/NCA/HFS0/PFS0 browse, hash verify, extract, cert edit; Switch modding / package-structure RE; StudentBlake; README [XCI Explorer]). (source: wiki/sources/descriptions/StudentBlake__XCI-Explorer.md); yuzu-based Switch emulator mirror [[nuzu]] (unofficial fork) for console-emulator / Switch-area RE. (source: wiki/sources/descriptions/qqq26__nuzu.md); archival yuzu DMCA/takedown placeholder [[yuzu-archive]] (Logboy2000; README + DMCA notice record only—no emulator source; legal/ecosystem reference for emulator enforcement events). (source: wiki/sources/descriptions/Logboy2000__yuzu-archive.md); PS5 Linux loader [[ps5-linux-loader]] (kernel/HV exploits, IOMMU/GPU/TMR; custom bootloader) for PlayStation HV / console RE. (source: wiki/sources/descriptions/ps5-linux__ps5-linux-loader.md); PS4/PS5 extended-storage drive cloning via [[drive-cloning-for-ps4-ps5]] (DrYenyen; Linux `dd` + sparse images; imaging extended storage and transferring installed applications between consoles; PlayStation storage migration RE) for console storage forensics beside HV tooling. (source: wiki/sources/descriptions/DrYenyen__Drive-Cloning-For-PS4-PS5.md); WebKit CSSFontFace UAF [[cssfontface-exploit]] (PS4/PS5 browser userland R/W → optional kernel chain; jailbreak research) for PlayStation WebKit / console RE. (source: wiki/sources/descriptions/ntfargo__CSSFontFace-Exploit.md); multi-chain PS4 WebKit jailbreak host [[psfree-enhanced]] (ArabPixel; PSFree/Bad Hoist/CSSFontFace userland + Lapse/NetCtrl/sleirsgoevy kernel; FW 6.00–11.02; auto fw/console detection; GoldHEN/HEN selector; payload loader :9020; JavaScript + C kernel patches + Python cache manifests; PlayStation browser jailbreak hosting) for consolidated PS4 WebKit exploit delivery beside standalone chains. (source: wiki/sources/descriptions/ArabPixel__PSFree-Enhanced.md); BD-J sandbox escape [[bd-un-jb]] (Gezine; BD-J xlet + `jdk.internal.misc.Unsafe`; C `bdj_unpatch` BDMV tool; Python log client; RemoteJarLoader PS5 ≤12.00; network JAR load/logging; PlayStation BD-J exploit-chain RE) for console jailbreak research beside WebKit lanes. (source: wiki/sources/descriptions/Gezine__BD-UN-JB.md); PS4 module-loader IDA helper via [[ida-ps4-helper]] (companion to ps4-module-loader; cheat / IDA Plugins) for PlayStation static RE. (source: wiki/sources/descriptions/janisslsm__ida-ps4-helper.md); PS4 Orbis Ghidra extension via [[ghidra-orbis]] (loaders, analyzers, syscall/NID data, symbol recovery; Java/Gradle; Orbis OS file formats; cheat / Ghidra Plugins) for PlayStation static RE in Ghidra. (source: wiki/sources/descriptions/astrelsky__GhidraOrbis.md); PS5 ELF load/analysis via [[ida-ps5-elf-plugin]] (PS5-specific ELF extensions, segment types, dynamic linking; game/system binaries; cheat / IDA Plugins) for PlayStation static RE. (source: wiki/sources/descriptions/gmh5225__ida_ps5_elf_plugin.md); PS2 VU microcode search/disassembly in IDA via [[ps2-ida-vu-micro]] (Goatman13; Python; manual ranges + VIF MPG auto-discovery; vector-unit program RE; branch-target reconstruction limits; cheat / IDA Plugins) for PlayStation 2 static RE. (source: wiki/sources/descriptions/Goatman13__ps2_ida_vu_micro.md); PS2 VIF1 DMA packet and VIF command parser via [[vifterpreter]] (0x5abe; Rust; binrw + bilge; DMA tags, unpack/MPG/state opcodes; Serde export; mesh/graphics asset stream decode; cheat / RE Tools) for PlayStation 2 binary asset RE. (source: wiki/sources/descriptions/0x5abe__vifterpreter.md); PS3 SPU opcode annotation in IDA via [[spu2c]] (Goatman13; Python; C-style per-instruction comments; vector lane sizes + shuffle-byte mask resolution; instruction/selection/function scan shortcuts; PS3 SPU firmware/library/anti-cheat RE; cheat / IDA Plugins) for PlayStation 3 SPU static RE. (source: wiki/sources/descriptions/Goatman13__spu2c.md); PS5 Cortex-A53 code-execution PoC via [[a53-code-exec]] (fw 02.00; kernel-level / SDK generation; console emulator + PlayStation RE) for low-level PS5 CPU exploit study. (source: wiki/sources/descriptions/cragson__a53-code-exec.md); PS5 live ELF manual-map injector via [[nines]] (TCP :9033 server; remote process/thread injection; section load + relocations; PS5 SDK; console process-injection RE) for runtime payload delivery beside static IDA loaders. (source: wiki/sources/descriptions/buzzer-re__NineS.md) - **macOS research hosts:** Hackintosh OpenCore EFI packs such as [[x260-lenovo-opencore]] (ThinkPad X260) give security researchers a non-Apple macOS lab for testing. (source: wiki/sources/descriptions/x90skysn3k__x260-lenovo-opencore.md); QEMU VM host [[utm]] runs Windows/Linux guests on iOS/macOS via Hypervisor.framework or JIT (Apple-device VM lab; `IOS Emulator` lane). (source: wiki/sources/descriptions/utmapp__UTM.md); macOS native Roblox client RE/cheat samples such as [[roblox-cheats]] (Mach VM memory APIs, dylib injection, object/offset definitions, breakpoint hooks; offset discovery from test place) illustrate offensive macOS game-client memory layout study beside generic injectors like [[opainject]]. (source: wiki/sources/descriptions/notahacker8__RobloxCheats.md); Luau live-game analysis dumpers such as [[wontree-rblx-dumper]] (decompile pipeline, instance scan, remote call graphs, live remote logger, framework/AC keyword reports; markdown/CSV export) support Roblox experience script and remote-path RE beside client-memory cheats. (source: wiki/sources/descriptions/LyeDevGit__WonTree-RBLX-Dumper.md); Windows CMS v95 MapleStory client address/offset tables such as [[maplestory-cms95-client-address]] (gmh5225; function pointers, structure offsets, hook points; cheat / game:maplestory [CMS-095 Client Analysis]) document Chinese MapleStory official-client memory layout for modding and private-server RE beside live TWMS corpora such as [[twms-hacking-data]]. (source: wiki/sources/descriptions/gmh5225__MapleStory-CMS95-Client-Address.md); community GMS v95.1 client internals write-ups such as [[maple-research]] (Maxcloud; Markdown; client structures + CSecurityClient/HackShield integration; practical localhost-environment RE map; cheat / game:maplestory [GMS-095 Client Analysis]) (source: wiki/sources/descriptions/Maxcloud__MapleResearch.md); Unity WZ client reimplementations such as [[unistory]] (ppodds; official KMS/TMS WZ archives via WzComparerR2.WzLib; map/foothold/portal/sprite/BGM rendering for asset-format RE; Game Develop / source) complement WZ viewers such as [[wzcomparerr2]] for studying MapleStory client asset structure without the live official client. (source: wiki/sources/descriptions/ppodds__UniStory.md) [[maple-unity]] (ilia810; official NX v83 assets via reNX/NXWrapper; foothold map generation / attachment-point sprite math / legacy packet+AES protocol reference; Unity Editor NX node diagnostics; Game Develop / source) complements WZ-first clients for studying MapleStory v83 client mechanics without the live official client. (source: wiki/sources/descriptions/ilia810__MapleUnity.md) [[maplestory-unity]] (MapleStoryUnity; Unity WZ client; MapleCryptoLib packet encryption; JCSUnity networking stack; client architecture / network protocol / asset-format RE; Game Develop / source) (source: wiki/sources/descriptions/MapleStoryUnity__MapleStoryUnity.md) Discontinued legacy GMS bot frameworks such as [[msc]] (PrinceFroggy; C++/C#; bundled map/portal resources; incomplete published logic; historical study of older game-bot design patterns; cheat / game:maplestory [GMS Bot]) document pre-modern MapleStory automation architecture beside those client RE corpora. (source: wiki/sources/descriptions/PrinceFroggy__MSC.md) Legacy GMS trainer toolkits such as [[msb]] (PrinceFroggy; C++/C# launcher; injection/runtime-control modules; GMS 128–140; historical MMO trainer architecture study; cheat / game:maplestory [GMS Old Hack 128-140]) document the adjacent in-process trainer lane beside [[msc]]. (source: wiki/sources/descriptions/PrinceFroggy__MSB.md) Legacy TWMS MapleStory hook projects such as [[msdoggy]] (Inndy; C/C++ + inline assembly; mob behavior changes + item-filter logic; low-level patching + optional protector integration; Taiwan-community historical MMORPG cheat RE; cheat / game:maplestory [TMS Old Hack]) extend that lane beside live-client corpora such as [[twms-hacking-data]]. (source: wiki/sources/descriptions/Inndy__MSDoggy.md) - Game-targeted x86 ROP compiler [[rop-compiler]] (Speedi13; C++; assembly-like scripts → ROP chains with gadget scanning and offset handling; CS:GO/BF3/BF4 cheat payload examples—triggerbot, glow ESP, minimap spotting; exploit-style cheat execution and AC evasion research; cheat / ROP Generation) sits beside fast C++ gadget finder [[rp]] (0vercl0k; rp++; PE/ELF/Mach-O x86/x64/ARM/ARM64; instruction gadgets + useful pointer values; cross-platform build; exploit dev / binary attack-surface audit; cheat / ROP Finder), [[ropgadget]] (JonathanSalwan; Python CLI; Capstone; ELF/PE/Mach-O/raw multi-arch gadget search, filter, optional chain generation; cheat / ROP Finder), [[ropium]] (Boyan-MILANOV; C++ core + Python bindings; gadget extract/analyze + semantic query chain builder; CLI + scriptable workflows; exploit dev / binary security education; cheat / ROP Generation), [[ropgadget-rs]], [[agafi]], [[exrop]], and [[angrop]] in the ROP chain synthesis lane. (source: wiki/sources/descriptions/Speedi13__ROP-COMPILER.md) (source: wiki/sources/descriptions/JonathanSalwan__ROPgadget.md) (source: wiki/sources/descriptions/Boyan-MILANOV__ropium.md) (source: wiki/sources/descriptions/0vercl0k__rp.md) - Multi-version AssaultCube cheat practice such as [[assaultcube-cheat]] (201580ag; internal/external samples; aimbot, ESP, overlays, memory utilities, offset handling; C/C++/C#; ImGui and OpenGL hooks; controlled training for game hacking and RE) complements [[assault-cube-cheat]], [[simple-ac-internal-cheat]], and [[external-esp-hack-assaultcube]] on the open-source [[assaultcube]] learning title. (source: wiki/sources/descriptions/201580ag__AssaultCube_Cheat.md) ## Related concepts [[research-rigor]] · [[binary-evidence]] · [[binary-diffing]] · [[mixed-boolean-arithmetic]] · [[dynamic-binary-instrumentation]] · [[control-flow-flattening]] · [[il2cpp]] · [[frida]] · [[frida-scripts]] · [[0xdea-frida-scripts]] · [[fridascript]] · [[frida-stack]] · [[frida-watchpoint-tutorial]] · [[frida-boot]] · [[frida-usb-dump]] · [[thats-no-pipe]] · [[unflutter]] · [[flutter-re-demo]] · [[flatredball]] · [[obengine]] · [[murder]] · [[libgdx]] · [[stride]] · [[rbfx]] · [[panda3d]] · [[rpgmakerdecrypter]] · [[auto-open-cak]] · [[hivewe]] · [[jmap]] · [[paksmith]] · [[uassetgui]] · [[uassetapi]] · [[ue-explorer]] · [[rust-u4pak]] · [[godot]] · [[godot-demo-projects]] · [[gddumper]] · [[gdmaim]] · [[ue5-roll-a-ball-game]] · [[bt-modular-game-features]] · [[ue5-fps-crypt-raider]] · [[unrealengine5-ultimate-streetfighters]] · [[unturned-godot]] · [[houdini-engine-for-unreal]] · [[luamachine]] · [[unrealclr]] · [[patternsleuth]] · [[kernel-callbacks]] · [[patchguard]] · [[mutaben]] · [[mba-obfuscator]] · [[mixed-boolean-transform]] · [[limba]] · [[cobra]] · [[mbased]] · [[qsynthesis]] · [[drill-and-join]] · [[stp]] · [[smt-server]] · [[stitch]] · [[cirsat]] · [[ndisapi]] · [[pcapplusplus]] · [[npcap]] · [[umpmlib]] · [[eupmaccess]] · [[reclass-net]] · [[reclass-net-driverreader]] · [[reclass-dma]] · [[reclass-ex]] · [[kreclassex]] · [[reclass]] · [[shredder-rs]] · [[beatrice-py]] · [[r2morph]] · [[r2smt]] · [[deobf]] · [[deobfuscator]] · [[ricochet-deobfuscator]] · [[aurum-re]] · [[confuserex-idapython]] · [[xigncode3-blackdesert]] · [[idadeflat]] · [[ida-easy-life]] · [[pikabot-deobfuscator]] · [[d810-ng]] · [[obpo-plugin]] · [[opaque-predicates-detective]] · [[obfuscation-detection]] · [[obfuscation-analysis]] · [[ida-jm-xorstr-decrypt-plugin]] · [[ida-gameguard-str-dec]] · [[anti-xorstr]] · [[ida-ios-helper]] · [[ida-ps4-helper]] · [[ida-ps5-elf-plugin]] · [[ps2-ida-vu-micro]] · [[vifterpreter]] · [[spu2c]] · [[ida-android-breakpoint]] · [[aimachdec]] · [[pe32-password]] · [[packer]] · [[packer-tutorial]] · [[hm-pe-packer]] · [[huan]] · [[x64-exe-packer]] · [[pepacker]] · [[exe-packer]] · [[2pack]] · [[oxide]] · [[shibari]] · [[woody-woodpacker]] · [[elfpacker]] · [[elfcrypt]] · [[papaw]] · [[midgetpack]] · [[ward]] · [[embuche]] · [[elfuck]] · [[m0dern-p4cker]] · [[petoy]] · [[greym]] · [[pezor]] · [[xorpacker]] · [[hxor-packer]] · [[kagura]] · [[the-poor-mans-obfuscator]] · [[obscura]] · [[swiftshield]] · [[wprotect]] · [[wprotectsdk]] · [[furikuri]] · [[rel-fuscate]] · [[relocbonus]] · [[obfuscar]] · [[obfuscation-methods]] · [[alcatraz]] · [[perses]] · [[milfuscator]] · [[vxlang-page]] · [[nocturne]] · [[riscy-workshop]] · [[binprotect]] · [[obfusk8]] · [[sbox]] · [[xorstr]] · [[mystic-xorstr]] · [[obfuscxx]] · [[polymorphic-engine]] · [[skcrypter]] · [[xorlit]] · [[obfuscatxor]] · [[garble]] · [[bloatedhammer]] · [[encrypted-value]] · [[xor-float]] · [[e3]] · [[obfcoder]] · [[javascript-obfuscator]] · [[nodejs-tracer]] · [[lua-obfuscator-clyde-protection]] · [[vmdevirt-vtil]] · [[novmpy]] · [[vmdragonslayer]] · [[rumba]] · [[themida-research]] · [[tde]] · [[magicmida-rs]] · [[nuitka-themida-unpacker]] · [[execution-trace-viewer]] · [[vmunprotect]] · [[vmunprotect-dumper]] · [[vmpunpacker]] · [[vmpstatic]] · [[totalpe2]] · [[pe-bear]] · [[hexwalk]] · [[imhex]] · [[risoh-editor]] · [[retract]] · [[dotniet]] · [[die-engine-web]] · [[pandora]] · [[apkid]] · [[unmapper]] · [[fix-arxan]] · [[pdb]] · [[diasymbolview]] · [[pdbr]] · [[fakepdb]] · [[pdb-rs]] · [[pdblister]] · [[ida-unity-pdb-downloader]] · [[il2cpp-pdb]] · [[ntkernelwalkerlib]] · [[ntoskrnl-viewer]] · [[ntoskrnlwalker]] · [[rop-compiler]] · [[ropium]] · [[ropgadget]] · [[ropgadget-rs]] · [[agafi]] · [[exrop]] · [[angrop]] · [[cfb]] · [[drvtrace]] · [[ioctlpus]] · [[kpdb]] · [[dwex]] · [[ntsleuth]] · [[quickasm]] · [[chasm]] · [[raung]] · [[jdbg]] · [[xrefsext]] · [[find-xrefs]] · [[xrefgen]] · [[xrefxpert]] · [[copy-rva]] · [[cbs]] · [[ida-plugins]] · [[symbridge]] · [[symless]] · [[ida-kmdf]] · [[driver-buddy-reloaded]] · [[driver-vuln-analyzer-ida-plugin]] · [[deepzero]] · [[drveye]] · [[ida-bitfields]] · [[ntrays]] · [[ida-phnt-types]] · [[apply-callee-type-ex]] · [[ida-efiutils]] · [[efixplorer]] · [[efiseek]] · [[fiano]] · [[farm64]] · [[amd-sp-loader]] · [[idarem]] · [[idarling]] · [[labsync]] · [[ida-migrator]] · [[ida-minsc]] · [[idaref]] · [[ida2obj]] · [[idac]] · [[idacode]] · [[idacpp]] · [[ida-vmware-windows-gdb]] · [[ida-bochs-windows]] · [[ida-mcp-server-plugin]] · [[ida-pro-loadmap]] · [[ida-map-symbol-parser]] · [[ida-kallsyms-symbol-renamer]] · [[ida-screenshot]] · [[ida-security-scanner]] · [[rhabdomancer]] · [[augur]] · [[mcore-decompiler]] · [[static-analyzer-factory]] · [[long-night]] · [[ida-themer]] · [[idaskins]] · [[ida-nord-theme]] · [[ida-dark-plus]] · [[dp701]] · [[draw-ida]] · [[ida-slides]] · [[ida-spotlight]] · [[renamaida]] · [[finger]] · [[ida-names]] · [[ida-export-functions]] · [[ida-data-export-plus]] · [[ida-function-string-associate]] · [[idacomments]] · [[ida-find-.data-ptr]] · [[idafind]] · [[autorename]] · [[ida-pro-mcp]] · [[ida-codex-mcp]] · [[ida-no-mcp]] · [[iida-mcp]] · [[pcm]] · [[ida-assistant]] · [[aida]] · [[ida-llm-explainer]] · [[gepetto]] · [[ida-gepetto]] · [[aether]] · [[aetheris]] · [[idassist]] · [[luda]] · [[lazyida]] · [[ida-wakatime-py]] · [[openlumina]] · [[sark]] · [[ida-taskr]] · [[ida-rust-demangler]] · [[ida-rust-cargo]] · [[demumble]] · [[rtti-parser]] · [[pyclassinformer]] · [[ida-medigate]] · [[classy]] · [[classmaker]] · [[ida-vtable-tools]] · [[ida-vtable-explorer]] · [[ida-missinglink]] · [[genpatch]] · [[ida-genpatch]] · [[genmc]] · [[microavx]] · [[happyida]] · [[seh-helper]] · [[idaplugins]] · [[idaplugins-list]] · [[idawilli]] · [[idasdk-collection]] · [[ida-functioncolor]] · [[ida-func-outline]] · [[idaclu]] · [[yara4ida]] · [[yarascan-ida]] · [[yaravm]] · [[hyara]] · [[kiroshi]] · [[patch-finder]] · [[integrity-experiments]] · [[aho-corasick]] · [[ida-fusion]] · [[ida-sigmaker]] · [[ida-pro-sigmaker]] · [[sigmakerex]] · [[bndb2pat]] · [[avdebugger]] · [[ida-enums-helper]] · [[auto-enum]] · [[big5-decode-ida]] · [[systeminformer]] · [[cmdt]] · [[manipulating-token]] · [[x64dbg]] · [[koidbg]] · [[syser]] · [[x64dbgbinja]] · [[binja-kc]] · [[ptxninja]] · [[ariadne]] · [[binaryninja-pcode]] · [[binaryninja-themes]] · [[binsync]] · [[ghidra-svr-bridge]] · [[bn-ebpf-solana]] · [[slothbp]] · [[dotx64dbg]] · [[classroom]] · [[expomon]] · [[x64dbg-view-dll-notification]] · [[idenlib]] · [[sig-database]] · [[idenlibx]] · [[manytypes]] · [[steam-anti-anti-debug]] · [[titanhide]] · [[scyllahidedetector2]] · [[makin]] · [[anti-debugging]] · [[adbg]] · [[ttd-anti-debugging]] · [[gh-anti-debug-bypass-practice-tool]] · [[blackhat2012]] · [[hint-break]] · [[anticuckoo]] · [[awesome-anti-virtualization]] · [[ghidrametrics]] · [[ghidra-scripts]] · [[ghidra-vxd-tools]] · [[ghidra-headless-mcp]] · [[ghidrassist-mcp]] · [[gpt-wpre]] · [[gba-ghidra-loader]] · [[threatresearch]] · [[apktool]] · [[jadx]] · [[android-classyshark]] · [[bytecode-viewer]] · [[dexkit-android]] · [[dex2jar]] · [[dalivm]] · [[dalvikus]] · [[zygisk-dump-dex]] · [[pwatch]] · [[pwatch-c]] · [[btrace]] · [[ptrace-read-teb]] · [[apktool-mcp-server]] · [[delamain]] · [[memmcp]] · [[memdumper]] · [[zygisk-memdump]] · [[ce-tracer-ida]] · [[frinet]] · [[cheatengine-mcp-bridge]] · [[obfu-de-scate]] · [[asctool]] · [[apksigcopier]] · [[apksigner]] · [[payload-dumper]] · [[payload-dumper-go]] · [[android-proxy-mcp]] · [[oob-entry]] · [[dopamine]] · [[dopamine2-roothide]] · [[palera1n]] · [[lightsaber]] · [[lara]] · [[dirty-zero]] · [[darksword-kexploit-fun]] · [[xnu-1day-practice]] · [[humptylock]] · [[xnuspy]] · [[kfd-explorer]] · [[vermagic]] · [[vmlinux-to-elf]] · [[venom]] · [[veh]] · [[veh-dumper]] · [[no-access-protection]] · [[no-access-protection-x86]] · [[bincon]] · [[voidmaw]] · [[deepsleep]] · [[shellcode-fluctuation]] · [[memory-relocalloc]] · [[death-sleep]] · [[kvcforensic]] · [[ks-dumper]] · [[ksdumper-11]] · [[vmkatz]] · [[volatility]] · [[volatility3]] · [[xmalhunter]] · [[ephemera]] · [[file-recovery-tool]] · [[ntfstool]] · [[ntfs-linker]] · [[openpetya]] · [[usn]] · [[searchex]] · [[dfirtriage]] · [[grr]] · [[volatile-data-collector]] · [[pillager]] · [[windbg-scripts]] · [[windbg-cookbook]] · [[awesome-windbg-extensions]] · [[twindbg]] · [[swishdbgext]] · [[comon]] · [[comida]] · [[dk]] · [[mcp-windbg]] · [[windbg-tool]] · [[windbg-copilot]] · [[windbg-decompile-ext]] · [[ttddbg]] · [[tenet]] · [[tenet-ida9.0]] · [[kn-live-dbg]] · [[kdbg]] · [[kdbgdecryptor]] · [[kn-win32-api-monitor]] · [[nokd]] · [[ntoseye]] · [[pocsmith]] · [[mcp-gdb]] · [[gdb-mcp]] · [[gdbghidra]] · [[resim-ghidra-plugins]] · [[dsh-plugins]] · [[lisa-py]] · [[gdbserver9x]] · [[gdb-windows-binaries]] · [[winvisor]] · [[sogen]] · [[emulator]] · [[unicorn-pe]] · [[brovan]] · [[sk3wldbg]] · [[ews]] · [[levo]] · [[dynre-x86]] · [[covcane]] · [[zyemu]] · [[felix86]] · [[hyper-rev]] · [[smallworld]] · [[panda]] · [[glacierw-mba]] · [[qemu-nyx]] · [[winafl]] · [[apatchy]] · [[fuzzable]] · [[vfdynf]] · [[ispras-qemu]] · [[qemu-blog]] · [[ripr]] · [[cpp-veh-dbi]] · [[w1tn3ss]] · [[pyda]] · [[iaito]] · [[radius2]] · [[r2smt]] · [[garlic]] · [[r2garlic]] · [[r2ai]] · [[r2a]] · [[ouroboros]] · [[oxidizer]] · [[retdec]] · [[hyperion-disassembler]] · [[re-architect]] · [[proxmox]] · [[quickemu]] · [[mvisor]] · [[xqemu]] · [[xemu]] · [[kevboy]] · [[feather-gb]] · [[zelda3]] · [[devilution]] · [[doomretro]] · [[rsdkv5-decompilation]] · [[gzdoom]] · [[uzdoom]] · [[gta-reversed-modern]] · [[regta]] · [[grand-theft-auto-modding-source]] · [[game-gta-re3]] · [[gtav-sourcecode-build-guide]] · [[gta5view]] · [[dead-by-daylight]] · [[cnc-red-alert]] · [[redalert2]] · [[phobos]] · [[python-plants-vs-zombies]] · [[regamedll-cs]] · [[regs]] · [[goldsource-rebuild]] · [[source-engine]] · [[source-engine-2003]] · [[source-engine-2007]] · [[oxware]] · [[cod7-tools]] · [[splitgate-internal]] · [[xenia]] · [[xenia-mac]] · [[xbox360-emu]] · [[idaxex]] · [[toastylink]] · [[recompiler]] · [[se-tools]] · [[ctr-composer]] · [[ocarina-ctr-composer]] · [[nstool]] · [[nuzu]] · [[yuzu-archive]] · [[ps5-linux-loader]] · [[cssfontface-exploit]] · [[ida-ps4-helper]] · [[ida-ps5-elf-plugin]] · [[x260-lenovo-opencore]] · [[utm]] · [[reverse-engineering]] · [[game-reversing]] · [[game-reversed-study]] · [[dark-souls-iii-cheat-engine-guide]] · [[windows-kernel-debugging-guide]] · [[retools]] · [[retoolkit]] · [[rev-tools-setup]] · [[flare-vm]] · [[tools]] · [[infosec-reference]] · [[gamehacking-cheatsheet]] · [[mytechnotalent-reverse-engineering]] · [[hacking-windows]] · [[hacking-rust]] · [[go-hacking]] · [[golang-loader-assist]] · [[embedded-hacking]] · [[sjcam]] · [[overviews/anti-cheat]] · [[overviews/windows-kernel]] · [[overviews/mobile-security]] ## README map Cheat (~2812) Debugging / RE Tools (game file-format/asset reversing lists + [[pc-wackywheels-doc]] Wacky Wheels DOS archive/sprite RE doc + sosso33/[[omikron-tns-omk-engine]] Omikron: The Nomad Soul (1999) script VM/game-state/asset format RE with trace validation + Ghidra install/plugin managers + [[scalpel]] + williballenthin/ida-settings IDA plugin settings manager + [[binarylens]] IDA Pro LLM plugin + [[ida-pro-agent]] IDA Pro 9.4 AI console + MCP gateway (pseudocode, bounded caller tracing, guard-evidence extraction, preview/apply/rollback IDB ChangeSets) + [[hikarisystem-hexcore]] VS Code native RE IDE (Capstone/Unicorn/Remill/Rellic, YARA/IOC, headless `.hexcore_job.json`) + [[sako-restudio]] mobile-first Android disassembler/decompiler (APK/ELF/PE/DEX; ptrace debugger; SakoScript plugins; offline) (source: wiki/sources/descriptions/Maxamedxasa__SakoREStudio.md) + [[reverify]] AI-assisted RE with deterministic byte-level verification (MCP + CLI) + [[dereferencing]] IDA Pro dereferenced register/stack debugger views (source: wiki/sources/descriptions/danigargu__deREferencing.md) + [[resim-ghidra-plugins]] RESim/Simics Ghidra Debugger integration + [[dsh-plugins]] DSH PyGhidra bridge (import/decompile/strings/xrefs) (source: wiki/sources/descriptions/GalaxyBatMan111__dsh-plugins.md) + 1-3-7/[[disrobe]] modular static recovery pipeline + [[anti-anti-debugger-driver]] ETW-hook anti-anti-debug driver + KSwordDEV/[[ksword]] Qt ARK (Windows Kernel Explorer) (source: wiki/sources/descriptions/KSwordDEV__KSword.md); [[intro-to-gamehacking]] + [[hacking-rust]]/[[go-hacking]]/[[embedded-hacking]] mytechnotalent RE course lanes + mobile AC/shielding RE such as [[g-presto-anti-cheat-reverse-engineered]] + [[appsealing-reversal]]) / Mixed boolean-arithmetic / DBI / Fix VMP|Themida|OLLVM (plus DimaReverse/[[nuitka-themida-unpacker]] Themida+Nuitka two-stage unpack + IDA/BN/Ghidra/x64dbg plugin ecosystems); Anti Cheat (~734) Anti Debugging / Analysis Framework / Binary Packer (incl. [[pe-protector]] x86 PE protection + beto2-dev/Hyapk Android HyVm/dex2c packer with anti-Frida/root/tamper) (incl. [[blc-gamesec-lab]] authorized validation/regression orchestration + [[dead-anticheat]] FiveM server-side Lua AC + aeterna/aeterna-rongroi offline FiveM PC-check evidence tool + [[ff-ace-anticheat-analysis]] Tencent ACE Free Fire libanogs/libanort byte-level RE + [[pokealliance-anti-cheat-analysis]] PokeAlliance OTCv8 client audit) / Disassembly / Dump Fix / Binary Packer (plus structured AC/kernel/VT-x/graphics-integrity research index xhscfq/anti-cheat-research-index + thexin7/kernel-cve-analysis defensive kernel CVE lane + [[minecraft-anticheat-list]] Minecraft Java/Bedrock anticheat catalog + [[are-we-anti-cheat-yet]] GNU/Linux/Proton AC compatibility + IZxMD/[[ac-compat-research]] Linux kernel AC architecture feasibility tracking + IDELd/[[sac-the-server-anticheat]] CS2 Metamod/CSS server-side AC + Charlie328402/Sentinel-Anti-Cheat NeoForge server-side MC mod + NaySurGithub/Amethyst PowerNukkitX Bedrock prediction AC + BoondockSulfur/[[bs-anticheat]] Paper/Folia heuristic MC AC + XuJun05/[[faircount]] Fabric mod/resource-pack whitelist AC + [[cobra-snake]] web Snake server-side score AC + SloMR/[[rootect]] Android RASP + [[noimportz]] kernel zero-IAT lazy importer); adjacent `Windows Emulator` (~7; user-space + WHP trap-driven guests + hybrid [[kdemu]] kernel-driver emulation for rootkit/AC RE (source: wiki/sources/descriptions/ShallowFeather__KDemu.md)), `Linux Emulator` (~1; [[felix86]] x86/x64-on-RISC-V Linux userspace JIT; OFFTKP) (source: wiki/sources/descriptions/OFFTKP__felix86.md), and console cats (`Xbox` ~8 LLE/HLE + X360 patch + SystemOS kernel exploit / `Game Boy` ~4 incl. [[openfpga-gbc-cheats-ui]] / Switch ~8 / `PlayStation` ~7 HV+BD-UN-JB / PSFree-Enhanced / WebKit CSSFontFace / `Nintendo 3DS` ~3 incl. 3Beans LLE + Luma `.3gx` overlays / `GameCube/Wii` ~1 ioncodes/gecko / Dreamcast browser exploit [[defcon-dreamcast-planetweb-research]]) for binary-translation, hypervisor, and hardware-abstraction RE. (source: wiki/sources/README-categories.md)