
Lumma-Stealer-dllhost-Hollowing-C2-Domains-Payload-Extraction-Analysis
In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

An API hooking framework for intercepting and monitoring Windows applications

Open-source Windows kernel-level EDR lab for understanding and testing detection methods against process injection, credential dumping, and other…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for…

CVE-2025-61301 proof-of-concept demonstrating denial-of-analysis in CAPEv2 via recursive process forking that triggers MongoDB BSON limits and orjson…

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

Red Team C code repo

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Windows kernel driver that removes Process Protection (PP) and Process Protection Light (PPL).

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

A small utility to deal with malware embedded hashes.