
Simple-Polymorphic-Engine-SPE32
Generates unique polymorphic decryption code for encrypting data, using randomly selected instructions and keys, with junk opcode generation. Written…

Generates unique polymorphic decryption code for encrypting data, using randomly selected instructions and keys, with junk opcode generation. Written…

Ransomware source code artifact for analyzing encryption routines, payload mechanics, and building detection and incident-response countermeasures.

Collection of some easy of use tools - in powershell.

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

IDA python scripts to decrypt strings from KPOT and set those as comments

Extracts and decrypts malware configuration data from captured samples, automating C2 endpoint discovery, credential extraction, and indicator triage…

Decrypts Covenant C2 communications by extracting RSA private keys from minidumps, recovering AES session keys, and converting network captures to…

Python implementation of the CaRT library for (un)inerting files.

Hive v5 file decryption algorithm

Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks. Jasmin helps security researchers to…

Pack/Encrypt/Obfuscate ELF + SHELL scripts

Python tool for decrypting W32/Phase modules

ParanoiDF - PDF Analysis Suite based on PeePDF by Jose Miguel Esparza (http://peepdf.eternal-todo.com/). Tools added: Password cracking, redaction…

Decodes PlugX traffic and encrypted/compressed artifacts

Simple decrypter for Java AdWind, jRAT, jBifrost trojan

A python2 script for processing a PCAP file to decrypt C2 traffic sent to DOUBLEPULSAR implant

A set of functions to increase productivity while hacking with Bash

Detection and sanitization for Acropalypse Now - CVE-2023-21036