
LOLDrivers
Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

Modular file scanning/analysis framework

ML-based detection of Zombie ZIP archive header evasion attacks (CVE-2026-0866)

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

Asclepius validates backup integrity by restoring files and actively testing their recoverability. Instead of trusting metadata, it attempts to parse…

Graphical interface for PortEx, a Portable Executable and Malware Analysis Library

Python implementation of the CaRT library for (un)inerting files.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Static analysis tool for investigating potentially malicious Microsoft Excel files, extracting metadata, macros, and embedded objects to aid digital…