
ALPC-Enumerator
A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Active HTTP fingerprinting algorithm and tool that sends 8 crafted probes to generate unique, reversible server profiles for threat detection, server…

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Automated observable analysis engine for threat intelligence, digital forensics, and incident response, integrating with diverse analyzers via a…

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

Reverse engineering repository for malware samples from goxlr.net and related domains, focusing on stealer variants, C2 infrastructure analysis, and…

Message-queue-based threat intelligence feed collector and processor for CSIRTs. Automates ingestion, normalization, and sharing of security…

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

Practical labs, notes, and reports for CEH v13 modules — covering web hacking, network pentesting, malware analysis, social engineering, and security…

This is An Offensive Hacking Tool which can be used by hackers and for penetration testing purposes. Hack Responsibly!!!!!!!

Threat hunting framework that scans websites for malicious objects using Yara rules, URLhaus feeds, TLSH hashing, and deep object extraction, with…

Defanged Indicator of Compromise (IOC) Extractor.

Multi-purpose penetration testing framework bundling tools for information gathering, web hacking, password attacks, phishing, malware creation,…

Different methods to get current username without using whoami

Proof-of-concept exploit for CVE-2023-20052, an XXE vulnerability in ClamAV's DMG parser that leaks file contents via crafted DMG images.

Python tool that queries the VirusTotal API to check file hashes against 70+ antivirus engines, schedules recurring scans, and exports detection…

Generates unique fingerprints of malware HTTP requests from pcap files using Tshark, enabling identification and grouping of malware families through…

Proof-of-concept exploit for CVE-2023-20052, an information leak vulnerability in ClamAV's DMG file parser. Generates a malicious DMG file to trigger…