
doublepulsar-usermode-injector
A utility to use the usermode shellcode from the DOUBLEPULSAR payload to reflectively load an arbitrary DLL into another process, for use in testing…

A utility to use the usermode shellcode from the DOUBLEPULSAR payload to reflectively load an arbitrary DLL into another process, for use in testing…

A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck


A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

Proof-of-concept for CVE-2025-55891: heap corruption in TIFFCP.EXE via malformed TIFF file, triggering segmentation fault during LZW decompression in…

A free utility that finds malware, adware and other security threats

A small utility to deal with malware embedded hashes.

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…

Tool that can be used to trim useless things from a PE file such as the things a file pumper would add.

A utility for playing with cryptography, geared towards ransomware analysis.

Generates obfuscated VBA macros with AV/sandbox evasion for command execution payloads, supporting domain, disk, memory, and process checks.

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

An advanced memory forensics framework