r2inspect is a professional malware analysis framework that automates deep static inspection for PE, ELF, and Mach-O binaries using the radare2 ecosystem. It combines format parsing, detection heuristics, and rich reporting to support reverse engineers, incident responders, and threat analysts.
☆53Jul 1, 2026Updated last month
Alternatives and similar repositories for r2inspect
Users that are interested in r2inspect are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Collection of scripts to automate the Malware Analysis process☆34Oct 27, 2025Updated 9 months ago
- C++ tool and library for converting .bin files to shellcode in multiple output formats.☆32Aug 4, 2026Updated 2 weeks ago
- This central repository is crafted for cybersecurity enthusiasts, researchers, and professionals aiming to advance their skills. It offer…☆23Jun 10, 2026Updated 2 months ago
- Repository of different kernel drivers written while studying Windows NT Driver development☆12Apr 14, 2024Updated 2 years ago
- Offensive Security & Red Teaming Labs and Projects☆28Aug 26, 2025Updated 11 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Proof-of-Concept implementation of Reflective DLL Injection (RDI) specifically for Windows on ARM64. Demonstrates PEB access via the x1…☆38May 30, 2025Updated last year
- SVG Analysis and generation tools for commonly seen SVG attachment phishing☆57Sep 24, 2025Updated 10 months ago
- Module to generate and verify Authenticode signatures☆87Dec 31, 2025Updated 7 months ago
- A C# PE loader for x64 and x86 PE files.☆57Mar 9, 2026Updated 5 months ago
- A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representat…☆54Aug 11, 2026Updated last week
- ☆31Feb 28, 2025Updated last year
- A C++ REPL for IDA Pro / IDA C++ SDK☆97Mar 26, 2026Updated 4 months ago
- Sh3ller is a lightweight C2 framework in its simplest form.☆33Sep 5, 2025Updated 11 months ago
- Defanged malware stages from the telnyx 4.87.1/4.87.2 PyPI supply chain compromise — WAV steganography, credential stealer, Windows persi…☆21Mar 29, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.☆17Apr 20, 2026Updated 3 months ago
- A Fast, Modular, and Scalable TLS/SSL Security Scanner Written in Rust☆22Updated this week
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆42Jun 4, 2026Updated 2 months ago
- ☆169Mar 4, 2025Updated last year
- A no-reboot, in-memory Linux persistence PoC leveraging namespace joining, user-namespace elevation, and self‑deletion.☆65Aug 6, 2025Updated last year
- Library that provides Python examples for interacting with the Cobalt Strike REST API☆25Nov 26, 2025Updated 8 months ago
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Jul 28, 2026Updated 3 weeks ago
- Boot loader and emulator for real mode written in C/Python.☆45Jun 6, 2026Updated 2 months ago
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆55May 15, 2026Updated 3 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus …☆83Jul 28, 2026Updated 3 weeks ago
- Modified version of PEAS client for offensive operations☆51May 18, 2026Updated 3 months ago
- Poc of using youtube comments for C2 communications☆10Jul 6, 2021Updated 5 years ago
- Polymorphic AV/AMSI bypass toolkit - Donut shellcode runner for offensive .NET/PE tools☆37May 26, 2026Updated 2 months ago
- Whitepaper☆16Dec 1, 2025Updated 8 months ago
- Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-kno…☆24Jul 24, 2026Updated 3 weeks ago
- Install multiple versions of r2 and its plugins via Pip on any system!☆25Aug 30, 2024Updated last year
- skill-veil is an open source static analysis and policy tool for the agent extension supply chain.☆26Jul 5, 2026Updated last month
- The DataExplorer plugin integrates the pattern language from ImHex into x64dbg.☆92Mar 15, 2026Updated 5 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A cross-platform, collaborative C2 for red-teaming. Agents are cross-compilable (e.g, you can generate Windows DLLs on Linux), cross-comp…☆23Mar 7, 2025Updated last year
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆171Aug 23, 2024Updated last year
- A powerful Windows command-line tool for analyzing and searching ETW (Event Tracing for Windows) provider permissions from the Windows re…☆90Jul 29, 2025Updated last year
- PowerShell para Administradores☆13Feb 18, 2020Updated 6 years ago
- MCP server for .NET reverse engineering automation☆25Apr 10, 2026Updated 4 months ago
- This is an AI Agent for Students☆10Jan 26, 2025Updated last year
- This project is an Ansible Role to execute Atomic Red Team tests against multiple machines by wrapping Invoke-AtomicRedTeam☆28Jul 4, 2024Updated 2 years ago