
fnprint
match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

A script to detect stack-strings by using emulation (leveraging Unicorn)

A ProcessMonitor visualization application written in rust.

x64 Dynamic Reverse Engineering Toolkit

Golang bindings for PE-sieve

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.


A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

cPanel CVE-2026-41940 nuclear.x86 Security Audit & Cleanup Script

Example InSpec profile to detect presence of a malicious rest-client gem (CVE-2019-15224)

This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

CuckooDroid - Automated Android Malware Analysis with Cuckoo Sandbox.

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会