
Process-Dump
Windows tool for dumping malware PE files from memory back to disk for analysis.

Windows tool for dumping malware PE files from memory back to disk for analysis.

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Spoof file icons and extensions in Windows

CryptoLocker is open source files encrypt-er. Crypto is developed in Visual C++. It has features encrypt all file, lock down the system and send keys…

RetDec is a retargetable machine-code decompiler based on LLVM.

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

Make an Linux Kernel rootkit visible again.

Educational analysis of the Log4Shell (CVE-2021-44228) vulnerability, detailing its exploitation in a cryptocurrency mining campaign with IoCs, MITRE…

Proof-of-concept that abuses Windows Enclave to implement anti-tamper and anti-cheat evasion techniques at the driver level.

EXOCET - AV-evading, undetectable, payload delivery tool


Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…