
ThreatCheck
Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

Generates obfuscated .lnk files exploiting CVE-2026-21510 with LNK stomping, encrypted payloads, and anti-forensics for authorized penetration…

Shell script to detect the CVE-2024-3094 backdoor in XZ Utils by checking for malicious code in liblzma build artifacts and identifying affected…

Script to create templates to use with VirtualBox to make vm detection harder

Security review of CVE-2024-3094 (XZ Utils backdoor) including threat modeling, static/dynamic code analysis, fuzzing with AFL++, and a…

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

Proof-of-concept and analysis tools for CVE-2024-3094, the XZ Utils backdoor vulnerability, including detection and exploitation scripts.

Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)