
PortEx
Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…

amavis is a high-performance email content filter framework written in Perl.

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

Advanced detection of port scanning, DoS and malware attacks using Machine Learning techniques

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

This is a bash script focus on hardening linux. This is a custom think of windows defender but unlike of their privacy issue. User can feel freedom…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Enumerate various traits from Windows processes as an aid to threat hunting

A tool for malicious behavior detection in IoT devices

Forensic intelligence platform that analyzes files, correlates threat indicators, maps behavior to MITRE ATT&CK, and generates actionable security…