
GC2-sheet
GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…

Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

Automated hypervisor-level malware analysis sandbox with agentless guest introspection, web-based result exploration, and guided installer for…

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

Curated repository of live malware samples and source code for educational malware analysis and research, with an organized database and CLI tools…

RetDec is a retargetable machine-code decompiler based on LLVM.

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

No-root network monitor, firewall and PCAP dumper for Android

A curated list of cybersecurity tools and resources.


Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

InjectProc - Process Injection Techniques [This project is not maintained anymore]

makin - reveal anti-debugging and anti-VM tricks [This project is not maintained anymore]

Kaspersky's GReAT KLara

Disassemble ANY files including .so (NDK, JNI), Windows PE(EXE, DLL, SYS, etc), linux binaries, libraries, and any other files such as pictures,…

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Simulate the behavior of AV/EDR for malware development training.