
ShadowMem
Defensive framework that maintains a safety-focused shadow memory to detect and block prompt-injection and long-horizon threats against LLM agents…

Defensive framework that maintains a safety-focused shadow memory to detect and block prompt-injection and long-horizon threats against LLM agents…
Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

Volatility 3 ported to Rust. Same output, much faster.

Local privilege escalation exploit for CVE-2026-31431 in the Linux kernel crypto subsystem, providing root access and container breakout with a…

Cisco ASA Software and ASDM Security Research

a small wiper malware programmed in c#

Framework for hashing declared permissions in Chromium extensions and APKs, enabling clustering, hunting, and pivoting across potentially malicious…

A Binary Genetic Traits Lexer Framework

Digital Forensics Intelligence Framework

idahunt is a framework to analyze binaries with IDA Pro and hunt for things in IDA Pro

amavis is a high-performance email content filter framework written in Perl.

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Image-based Android malware detection framework tackling obfuscation and concept drift. Includes curated datasets and Python code for training…

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

A LSTM based framework for handling multiclass imbalance in DGA botnet detection

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

Patch Binaries via MITM: BackdoorFactory + mitmProxy.

Snoopy: A distributed tracking and data interception framework