
Silverseal
Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

Research and proof-of-concept for module stomping, a technique to hide malicious code in legitimate Windows modules, with documentation and…

Research and detection toolkit for Linux kernel LPE CVE-2026-31431, including exploit analysis, YARA rules, auditd/Falco detection, patching guide,…

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

machofile is a module to parse Mach-O binary files

GreyEnergy Mini Module Malware Analysis (Turkish)

Android Malware Tracker

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

node-ipc is malware / protestware!

Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101

Stack overflow in LibXMP

pefile is a Python module to read and work with PE (Portable Executable) files

LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)

The Web Exploit Detector is a Node.js application used to detect possible infections, malicious code and suspicious files in web hosting environments

A PowerShell Module Dedicated to Reverse Engineering

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…