
Random-Scripts
Collection of DFIR and OSINT Python scripts for parsing malicious LNK samples, extracting OLE objects from MHTML, and hashing favicons to hunt…

Collection of DFIR and OSINT Python scripts for parsing malicious LNK samples, extracting OLE objects from MHTML, and hashing favicons to hunt…

Offset Independent Credential Extraction Tool

Advanced Static malware analyzer that reveals 8 injection techniques, critical API calls, hidden strings, exports PE sections (.text, .rdata) as…

Open YARA scan- and search engine

Assortment of hashing algorithms used in malware

Imphash-like calculation on Golang binaries

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

A Binary Genetic Traits Lexer Framework

A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.

Yara Rules for Modern Malware

CLI client for bulk DIARIO API consumption: upload PDF/Office documents, query file hashes, and automate malware analysis workflows via command-line…

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

An easy to use, light-weight, on-demand virus scanner for Linux systems. For additional help, see the <a…

Recursively scan folders with VirusTotal API to detect malware. Features hash lookup, CSV export, real-time progress, and rate-limit handling for…

Static binary analysis with Detect It Easy — 100% in your browser, no uploads.

CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.