RetDec is a retargetable machine-code decompiler based on LLVM. The decompiler supports various file formats such as ELF, PE, Mach-O, COFF, AR, Intel HEX, and raw machine code, as well as architectures like Intel x86, ARM, MIPS, PIC32, PowerPC, x86-64, and ARM64. It offers features like static analysis, compiler and packer detection, instruction decoding, library code removal, debugging information extraction, instruction idiom reconstruction, and C++ class hierarchy detection.
FEATURES
ALTERNATIVES
A strings statistics calculator for YARA rules to aid malware research.
A detailed analysis of malicious packages and how they work
A script to detect and remove Canary Tokens with simple signature-based detections.
A blog post discussing INF-SCT fetch and execute techniques for bypass, evasion, and persistence
A simple XSS scanner tool for identifying Cross-Site Scripting vulnerabilities
Generates a YARA rule to match basic blocks of the current function in IDA Pro
PINNED

InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

CTIChef.com Detection Feeds
A tiered cyber threat intelligence service providing detection rules from public repositories with varying levels of analysis, processing, and guidance for security teams.

ImmuniWeb® Discovery
ImmuniWeb Discovery is an attack surface management platform that continuously monitors an organization's external digital assets for security vulnerabilities, misconfigurations, and threats across domains, applications, cloud resources, and the dark web.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.