
-Remcos-RAT-Fileless-svchost-Injection-Obfuscated-Payload-Analysis-
"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

Lua-based Wireshark postdissector that decrypts and parses Ubiquiti AirMAX/RouterBoard 802.11 vendor IEs into filterable fields.

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

Python program to steganography files into images using the Least Significant Bit.

Linux Distro for Mobile Security, Malware Analysis, and Forensics

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…

A low pin count sniffer for ICEStick - targeting TPM chips


Create and enumerate hidden desktops.

Audit Preference Pane and Log Reader for OS X

Post-Exploitation EVTX Analyzer for BloodHound Mapping

A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner

A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and…


Scan files or process memory for CobaltStrike beacons and parse their configuration

Hashes for vulnerable LOG4J versions