
PortEx
Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

ETW based POC to identify direct and indirect syscalls

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

amavis is a high-performance email content filter framework written in Perl.

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

PETriage: A symbol-unified PE file reader for triage, built for multi-platform and multi-interface use.

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

Zeek plugin to detect and decrypt XOR-encrypted EXEs

Zeek detector for QuasarRat

Detection for SUNBURST C2 Stage-1 using Shannon Entropy

A Zeek based AsyncRAT malware detector.

Simple Anti-cheat library for applications that use C++ on windows. #PastedProtection

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk