#1Tools for dissecting, understanding, and reverse engineering malicious software behavior.
Kitploit recommended

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking,…

Context of CVE-2021-26291 minimal replicator

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

A scanner and testter of the CVE-2025-11001 of 7-zip

Detection for CVE-2025-4427 and CVE-2025-4428

Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (2), Version: 0.0.4, CVE: CVE-2017-5941

We are expected to investigate a critical alert reporting a Windows OLE zero-click RCE exploitation (CVE-2025-21298) delivered via a malicious RTF…

A curated list of resources related to Industrial Control System (ICS) security.

Example Vulnerable application for CVE-2025–57833

Decrypt TP-Link Firmware

Hybrid kernel combining Mach, FreeBSD, and IOKit for macOS and iOS. Provides core OS services, driver framework, and security policy enforcement on…

A Zeek based STRRAT malware detector.

Zeek detector for QuasarRat

A collection of scripts and documents to help future XProtect Remediator (XPR) research

Multi-engine framework for unpacking and analyzing VM-protected binaries using dynamic taint tracking, symbolic execution, pattern classification,…

In-depth technical analysis and proof-of-concept for CVE-2017-9822, an insecure deserialization vulnerability in DotNetNuke leading to remote code…

Static Binary Instrumentation tool for Windows x64 executables

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.