#1Tools for dissecting, understanding, and reverse engineering malicious software behavior.
Kitploit recommended

Proof-of-concept demonstrating a Windows Defender bypass technique for CVE-2026-5000, intended for controlled testing and defensive research.
Detect Linux rootkits which use signals to elevate process privileges.

Set of tools to analyze Windows sandboxes for exposed attack surface.

Python based tool for generating Shellcode from PIC C

CVE-2017-0144

Patches the zero-click Apple Mail vulnerability (CVE-2020-9922) on macOS, preventing remote code execution without user interaction.

I have documented all of the AMSI patches that I learned till now

Proof-of-concept exploit for CVE-2025-53964: remote file read/write via malicious XDXF dictionary in GoldenDict 1.5.0/1.5.1, leveraging unsanitized…

This repository contains indicators of compromise (IOCs) of our various investigations.

Windows 11 24H2-25H2 Runtime PatchGuard Bypass

Proof-of-concept exploit and technical analysis for a WinRAR path traversal vulnerability enabling code execution via crafted archives with binary…

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

The new bridge between Burp Suite and Frida!

The official Python 3 client library for VirusTotal

UEFI rootkit under development focusing on privilege escalation, C2 integration, and anti-EDR/AV evasion for real-world malware deployment.

The official Go client library for VirusTotal API

Technical libraries for XWiki projects, providing reusable components for vulnerability analysis, code analysis, and static analysis across…

A POC exploit for WinRAR vulnerability (CVE-2025-8088) affecting versions 7.12 and lower