New Tools from Hakai Security

Tools2026-09-02, 13:35
At DefCon 34, the Hakai Security team introduced four new tools designed to expand offensive security research capabilities.
Beerus Framework — a penetration testing toolkit for Android devices. It provides a unified interface that runs directly on the device to perform a wide range of tasks, such as: • application instrumentation using the built-in Frida Core; • sandbox data exfiltration; • memory dumping; • proxying; • Magisk module control. The tool has already received positive feedback from the community and has a fairly high rating on GitHub.
Lyra — an LLVM IR obfuscator for Rust. It runs against an unmodified rustc and cargo, requires no changes to the target project's source code, and supports Windows, macOS, and Linux.
MonProcessEX-killer — an exploit that abuses the privileges of the MonProcessEX.sys driver, allowing protected processes to be terminated on Windows.
Mirage — a Rust library for network traffic morphing. Mirage reshapes the sizes, timing, and burst patterns of network traffic so that statistical flow classifiers and behavioral machine learning have less signal to work with.
Vendors
Hakai Security
Products
Beerus Framework
Lyra
Mirage
Monprocessex-Killer