
aether
Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Virtual Machine Introspection, Tracing & Debugging

Tool to make in memory man in the middle

Drltrace is a library calls tracer for Windows and Linux applications.

A dynamic unpacking tool

DrSemu - Sandboxed Malware Detection and Classification Tool Based on Dynamic Behavior

Web-based tool for browsing mobile application sandboxes, previewing SQLite databases and binary files, and downloading app data via Frida…

An API hooking framework for intercepting and monitoring Windows applications

Linux system-call monitor using ptrace to trace file, process, network, and memory activity, with namespace isolation and machine learning…

Advanced macOS system monitor leveraging Apple Endpoint Security to collect, enrich, and display process, file, memory, and XPC events for malware…

a PE Loader and Windows API tracer. Useful in malware analysis.

Critical Vulnerability (9.8) - RecordedFuture Triage dynamic analysis engine can fail to record malicious behavior when samples produce very…

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

A lightweight dynamic instrumentation library

Detect Linux rootkits which use signals to elevate process privileges.

Reproduces fuzzing and crash analysis for CVE-2024-1441 using AFL++ and CASR, with detailed setup and commands for libvirt.

Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls.