


Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

OS-level runtime auditing for unpredictable automation.

Evtx Log (xml) Browser

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain