
MalConfScan
Volatility plugin for extracts configuration data of known malware

Volatility plugin for extracts configuration data of known malware

This repository contains a list of new remediation scripts.

Detect and respond to Cobalt Strike beacons using ETW.

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

Collects and organizes malware indicators of compromise (IOCs) for rapid threat detection, incident response, and actionable intelligence sharing.

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

IoCs and YARA rules from Threatray's Threat Research

A powerful and flexible tool to apply active attacks for disrupting stegomalware

Just my findings of malwares

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Technical Analysis of Bibi-Windows Wiper Targeting Israeli Organizations