
reverse-SynthID
reverse engineering Gemini's SynthID detection

reverse engineering Gemini's SynthID detection

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

Linux Distro for Mobile Security, Malware Analysis, and Forensics

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Filesystem monitor tool for Linux/Android iOS/macOS

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

Collection of materials relating to FORCEDENTRY

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

Framework for hashing declared permissions in Chromium extensions and APKs, enabling clustering, hunting, and pivoting across potentially malicious…

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Manage WhatsApp .crypt12, .crypt14 and .crypt15 files.

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive…

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…