r2inspect is a professional malware analysis framework that automates deep static inspection for PE, ELF, and Mach-O binaries using the radare2 ecosystem. It combines format parsing, detection heuristics, and rich reporting to support reverse engineers, incident responders, and threat analysts.
☆52Jul 1, 2026Updated 3 weeks ago
Alternatives and similar repositories for r2inspect
Users that are interested in r2inspect are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Collection of scripts to automate the Malware Analysis process☆34Oct 27, 2025Updated 8 months ago
- A Rust library along with a Win32 GUI application to determine the driver load order of a Windows system (cf. https://colinfinck.de/posts…☆13Jan 26, 2025Updated last year
- This central repository is crafted for cybersecurity enthusiasts, researchers, and professionals aiming to advance their skills. It offer…☆23Jun 10, 2026Updated last month
- C++ tool and library for converting .bin files to shellcode in multiple output formats.☆33Aug 18, 2025Updated 11 months ago
- Repository of different kernel drivers written while studying Windows NT Driver development☆12Apr 14, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Offensive Security & Red Teaming Labs and Projects☆27Aug 26, 2025Updated 11 months ago
- A Proof-of-Concept implementation of Reflective DLL Injection (RDI) specifically for Windows on ARM64. Demonstrates PEB access via the x1…☆37May 30, 2025Updated last year
- SVG Analysis and generation tools for commonly seen SVG attachment phishing☆57Sep 24, 2025Updated 10 months ago
- Module to generate and verify Authenticode signatures☆87Dec 31, 2025Updated 6 months ago
- A C# PE loader for x64 and x86 PE files.☆56Mar 9, 2026Updated 4 months ago
- A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representat…☆54Jul 13, 2026Updated last week
- ☆31Feb 28, 2025Updated last year
- Various techniques used to bypass SMEP in the Windows Kernel.☆18Apr 20, 2025Updated last year
- A C++ REPL for IDA Pro / IDA C++ SDK☆96Mar 26, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Sh3ller is a lightweight C2 framework in its simplest form.☆33Sep 5, 2025Updated 10 months ago
- Defanged malware stages from the telnyx 4.87.1/4.87.2 PyPI supply chain compromise — WAV steganography, credential stealer, Windows persi…☆20Mar 29, 2026Updated 3 months ago
- A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.☆17Apr 20, 2026Updated 3 months ago
- A Fast, Modular, and Scalable TLS/SSL Security Scanner Written in Rust☆20Jul 10, 2026Updated 2 weeks ago
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆40Jun 4, 2026Updated last month
- ☆169Mar 4, 2025Updated last year
- A no-reboot, in-memory Linux persistence PoC leveraging namespace joining, user-namespace elevation, and self‑deletion.☆66Aug 6, 2025Updated 11 months ago
- Library that provides Python examples for interacting with the Cobalt Strike REST API☆25Nov 26, 2025Updated 8 months ago
- Tests for LFI in PHP apps and automates the process of leveraging LFI's to recursively download source code and discover new files via in…☆14Sep 29, 2022Updated 3 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36May 2, 2026Updated 2 months ago
- Boot loader and emulator for real mode written in C/Python.☆45Jun 6, 2026Updated last month
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆55May 15, 2026Updated 2 months ago
- Scripts to help and speed up reversing activities☆14Jun 30, 2026Updated 3 weeks ago
- PowerShell toolkit for AMSI/Defender detection-boundary analysis — maps byte offsets to detection triggers in scripts and binaries. Compa…☆36Updated this week
- Modified version of PEAS client for offensive operations☆51May 18, 2026Updated 2 months ago
- Poc of using youtube comments for C2 communications☆10Jul 6, 2021Updated 5 years ago
- Polymorphic AV/AMSI bypass toolkit - Donut shellcode runner for offensive .NET/PE tools☆36May 26, 2026Updated 2 months ago
- Whitepaper☆15Dec 1, 2025Updated 7 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-kno…☆19Updated this week
- Install multiple versions of r2 and its plugins via Pip on any system!☆25Aug 30, 2024Updated last year
- The DataExplorer plugin integrates the pattern language from ImHex into x64dbg.☆92Mar 15, 2026Updated 4 months ago
- A cross-platform, collaborative C2 for red-teaming. Agents are cross-compilable (e.g, you can generate Windows DLLs on Linux), cross-comp…☆23Mar 7, 2025Updated last year
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆172Aug 23, 2024Updated last year
- A boilerplate for dApps on Lisk☆12Jul 3, 2025Updated last year
- A powerful Windows command-line tool for analyzing and searching ETW (Event Tracing for Windows) provider permissions from the Windows re…☆65Jul 29, 2025Updated 11 months ago