
darknet-mcp-server
66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit…

66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit…

Header-only Windows x64 indirect syscall library. Zero CRT, zero IAT, VEH anti-BP, AMSI/ETW bypass, W^X memory, per-call dynamic stubs.

Python-based crypter that obfuscates payloads to bypass antivirus and EDR, generating FUD stubs for red team operations.

Research and proof-of-concept for module stomping, a technique to hide malicious code in legitimate Windows modules, with documentation and…

Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging

Generates obfuscated .lnk files exploiting CVE-2026-21510 with LNK stomping, encrypted payloads, and anti-forensics for authorized penetration…

A Python pickling decompiler and static analyzer

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

PoC MSI payload based on ASEC/AhnLab's blog post

Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks. Jasmin helps security researchers to…

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Security Scanner for Agent Skills

Reverse engineered android malware, and this is a C&C server for it

Red team operator and malware developer specializing in evasion techniques, reverse engineering, and initial access operations. Active CVE researcher…

A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end…

Scripts for communication with Bunitu Trojan C&Cs