
mimicry
Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

An extensible, end-to-end encrypted reverse shell that works across networks without port forwarding.

Terminal-based security auditor that statically analyzes shell scripts and commands, dynamically enforces sandboxing via Linux Landlock, and provides…

Exploit tool that bypasses BitLocker encryption by leveraging Windows Recovery Environment (WinRE) and Defender offline scan state to gain…

USB port access control tool for Debian with whitelist management, automatic background scanning daemon, and CLI interface to block or allow USB…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Filesystem monitor tool for Linux/Android iOS/macOS

Portable forensic acquisition tool for Android devices that extracts SMS, APKs, system logs, and process lists to identify spyware and compromise…

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

GUI-based memory forensics tool for Volatility 2, enabling process/PE/handle inspection, file extraction, registry view, MFT analysis, and suspicious…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

A powerful and flexible tool to apply active attacks for disrupting stegomalware

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool