
Driver-PiDqSerializationWrite-Example
How to use PiDqSerializationWrite. Introduces how to safely read and write from mapped driver

How to use PiDqSerializationWrite. Introduces how to safely read and write from mapped driver

Proof-of-concept tool for detecting AMSI (Antimalware Scan Interface) bypasses and malicious in-memory script activity on Windows endpoints.

A list of covert channels and steganography/steganalysis resources (books, papers & tools)

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

POC about how to detect windows kernel debug by pool tag.

A guide on how to write fast and memory friendly YARA rules

A tutorial on how to write a packer for Windows!

Detection of Linux Malware C2 RedXOR - demonstration

Cortex: a Powerful Observable Analysis and Active Response Engine

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

Lightweight telnet honeypot for capturing IoT malware samples and identifying active command-and-control infrastructure, designed for educational…

PoC demonstrating SHA-1 code signing forgery and missing High Entropy ASLR in CyberGhostVPN installer, enabling trust bypass and predictable memory…

NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements

It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have…

Spoof file icons and extensions in Windows

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

Backdooring Claude Code via hooks in settings.json. Authorized use only!

Experimental Linux strace LLM agent