
drakvuf-sandbox
Automated hypervisor-level malware analysis sandbox with agentless guest introspection, web-based result exploration, and guided installer for…

Automated hypervisor-level malware analysis sandbox with agentless guest introspection, web-based result exploration, and guided installer for…

A Full-Featured HexEditor compatible with Linux/Windows/MacOS

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

Curated repository of live malware samples and source code for educational malware analysis and research, with an organized database and CLI tools…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Rust tool to detect cell site simulators on an orbic mobile hotspot

No-root network monitor, firewall and PCAP dumper for Android

Awesome-Cellular-Hacking

A curated list of cybersecurity tools and resources.


Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Disassemble ANY files including .so (NDK, JNI), Windows PE(EXE, DLL, SYS, etc), linux binaries, libraries, and any other files such as pictures,…

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

StalkPhish - The Phishing kits stalker, harvesting phishing kits for investigations.

The Open-Source AWS Cyber Range

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.

This project is a SIEM with SIRP and Threat Intel, all in one.