
CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules
Proof-of-concept exploit for CVE-2026-33057, an unauthenticated RCE in Mesop, with accompanying YARA rules for detection.

Proof-of-concept exploit for CVE-2026-33057, an unauthenticated RCE in Mesop, with accompanying YARA rules for detection.

pefile is a Python module to read and work with PE (Portable Executable) files

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

Academic Research Edition - T1: User-mode evasion (obfuscation + syscall gateway), T2: BYOVD kernel bridge, T3: DMA hardware (future work).

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Threat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.

IOC scanner for agentic AI coding tools — detects Mini Shai-Hulud, Gemini CLI RCE, Cursor CVE-2026-26268, and DPRK PromptMink.

A True Instrumentable Binary Emulation Framework

Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution,…


scripts/plugins for IDA Pro

Modular malware analysis artifact collection and correlation framework