
radare2-scripts
Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

Static analysis tool for investigating potentially malicious Microsoft Excel files, extracting metadata, macros, and embedded objects to aid digital…

Generate bulk YARA rules from YAML input

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

NeuroCore is a native macOS application that visualizes the internal structure of binary files using a Hilbert Curve mapping and Shannon Entropy…

Python toolkit for malware analysis, designed to inspect suspicious files and extract indicators of compromise for security investigations.

Scripts for extracting useful information from infected memory dumps

Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

Technical Analysis of Bibi-Windows Wiper Targeting Israeli Organizations

Contains tools to perform malware and forensic analysis in Memory


Parsing Ramnit's traffic

Scanner for the keyv/cacheable supply-chain attack: detects compromised npm packages, verifies payload hashes, and finds persistence implants in repo…

Technical analysis of a multi-stage Adobe Acrobat PDF JavaScript sample, detailing environment triage, Acrobat API abuse, and in-memory payload…

Technical dissection of CVE-2026-0628, a Chromium WebView privilege escalation vulnerability, including root cause analysis, PoC exploit, detection…

CVE-2017-0199 XLS --> HTA --> VBS --> STEGANOGRAPHY --> DBATLOADER/GULOADER STYLE MALWARE

Extracts and exports certificate information from digitally signed PE files using Python and pefile, enabling forensic analysis of code-signing…

CVE-2024-3094