
vol-rs
Volatility 3 ported to Rust. Same output, much faster.

Volatility 3 ported to Rust. Same output, much faster.

Tamper-evident audit trails for AI agents: hash-chained Runtime Records, dependency-free, verifiable by anyone.

Cross-platform Yara scanner written in Go

Linux Process Discovery. C Library, Go bindings, Runtime.

DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the…

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.

CVE-2023-21036 detection in Go

The modern, high-speed successor to nsec3walker. A specialized NSEC3 forensics engine built in Go for rapid zone harvesting and automated hash…

Free educational content on reverse engineering and malware analysis from the FLARE team


Detect images that likely exploit CVE-2022-44268

Some setup scripts for security research tools.

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…