
ProcDump-for-Linux
A Linux version of the ProcDump Sysinternals tool

A Linux version of the ProcDump Sysinternals tool

Detects CanaryTokens in Office docs and PDFs (docx, xlsx, pptx, pdf) without triggering alerts

An strace-like program for the Windows 'native' API

🔵 Threat analysis writeup for Follina (CVE-2022-30190) — Microsoft MSDT RCE zero-day exploited in the wild. Covers static analysis, VirusTotal,…

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

A free utility that finds malware, adware and other security threats

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…

Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.

Validation report for the RoguePlanet Microsoft Defender PoC in a controlled Windows 11 lab environment, including build notes, Defender detection…


Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE


Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.

MAPS cloud scanner and response parser for Microsoft Defender research.

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…


Universal signature generation for any system function from all Windows Builds using Winbindex