
pftriage
Python tool and library to help analyze files during malware triage and analysis.

Python tool and library to help analyze files during malware triage and analysis.


Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Intercepts and analyzes USB Mass Storage traffic at the block and file level, emulates USB devices, and supports custom Python stubs for security…

Reverse engineering notes, deobfuscated source, IOCs, and YARA rules for the Tourmaline ClickFix Python RAT, covering its DNS tunnel and blockchain…


Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

OSINT & recon toolkit // 100+ tools, one-command installer, SOCMINT, GEOINT, network recon, dark web, forensics & more.

Reverse engineering analysis of DarkTortilla RAT, a sophisticated malware that steals credit card data, decrypts browser passwords, and exfiltrates…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!


Windows host DFIR triage console that chains artefact collection, Sigma-correlated timelines, YARA scans, socket and account inspection, indicator…

Curated guide to becoming a malware analyst, covering essential knowledge, reverse engineering, analysis tools, and LLM-assisted learning with…