
awesome-yara
A curated list of awesome YARA rules, tools, and people.

A curated list of awesome YARA rules, tools, and people.

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking,…

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…


Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Malicious Extension Database

A continuously updated resource that catalogs confirmed data breaches from across the globe. Each entry includes the breach name, usually aligned…


Defanged Indicator of Compromise (IOC) Extractor.


WinDbg plugin for automated malware dynamic analysis and IOC extraction. Executes within the debugger to collect predefined indicators and writes…

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

KrustyLoader Analysis

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…


Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

HexaLocker ransomware analysis
