

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

Proper sandboxing for agentic coding and web browsing

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Fast and accurate AI powered file content types detection

0-day malware detection for binaries, source & scripts (that doesn't suck)

Real-time geospatial OSINT platform aggregating 60+ public telemetry feeds (ADS-B, AIS, satellites, CCTV) into a unified map with server-side recon…

Sandboxie Plus & Classic

Clusters and elements to attach to MISP events or attributes (like threat actors)

Simple, effective, and modular package for parsing observables (indicators of compromise (IOCs), network data, and other, security related…

The Python Code Tutorials

A centralized and enhanced memory analysis platform

IoCs and YARA rules from Threatray's Threat Research

This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports