
forensictools
Collection of forensic tools

Collection of forensic tools

Collection of Offensive C# Tooling

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

Technical Analysis of Bibi-Windows Wiper Targeting Israeli Organizations

This module fixes an issue in the kernels filesystem layer (CVE-2021-33909) by kprobe-replacing vulnerable functions during runtime

Some setup scripts for security research tools.

Collection of some easy of use tools - in powershell.

Program for determining types of files for Windows, Linux and MacOS.

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).


Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

A malware analysis and classification tool.

Visually inspect and force decode YARA and regex matches found in both binary and text data with colors. Lots of colors.

NeuroCore is a native macOS application that visualizes the internal structure of binary files using a Hilbert Curve mapping and Shannon Entropy…