
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Runs packed malware in a controlled environment, waits for self-unpacking, dumps PE files and shellcodes from memory, and terminates the process.

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

bad stuffs by bad guys

Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Fuzzes CPU implementations by generating test inputs from software proxies, then executes them on real hardware to detect microarchitecture defects…

Discover DYLD_INSERT_LIBRARIES hijacks on macOS

Exports disassembly from IDA Pro, Ghidra, and Binary Ninja into compact protobuf files for fast, standalone binary analysis and program manipulation…

Tools and PoCs for Windows syscall investigation.


IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix…

Select Bugs From Binary Where Pattern Like CVE-1337-Days

IDA python script for deobfuscating Astaroth/Guildma injector DLL

IDA python scripts to decrypt strings from KPOT and set those as comments