
Tourmaline
Reverse engineering notes, deobfuscated source, IOCs, and YARA rules for the Tourmaline ClickFix Python RAT, covering its DNS tunnel and blockchain…

Reverse engineering notes, deobfuscated source, IOCs, and YARA rules for the Tourmaline ClickFix Python RAT, covering its DNS tunnel and blockchain…

Educational guide and code repository for understanding APT attack techniques, covering reconnaissance, web and service exploitation, trojans, C2,…

The official Python 3 client library for VirusTotal

The official Go client library for VirusTotal API

DNSChef (NG) - DNS proxy for Penetration Testers and Malware Analysts

Simple Webshell Scanner

Suspicious DGA from PDNS and Sandbox.

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

Scripts and utilities to help your hacking needs

ioc2rpz is a place where threat intelligence meets DNS.

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

Extract payload URLs from Follina (CVE-2022-30190) docx and rtf files

🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB…

Bro/Zeek script for detecting Apache Struts CVE-2017-5638 reconnaissance, compromise, and malware download tracking with automated IP extraction.

CVE-2023-20052 information leak vulnerability in the DMG file parser of ClamAV

Automated steganography detection tool that scans websites, web servers, and local directories using AI-driven object/text recognition and deep file…