
m3
A simple and scalable Android bot emulation framework, as presented at Black Hat Europe 2021's Arsenal, as well as atHack 2021's Arsenal

A simple and scalable Android bot emulation framework, as presented at Black Hat Europe 2021's Arsenal, as well as atHack 2021's Arsenal

An API hooking framework for intercepting and monitoring Windows applications

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

Image-based Android malware detection framework tackling obfuscation and concept drift. Includes curated datasets and Python code for training…

CrowdStrike Feed Management System. CrowdFMS is a framework for automating collection and processing of samples from VirusTotal, by leveraging the…

Binary analysis and management framework

A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis

Static and dynamic Android application security analysis

Android Malware Tracker

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Yet Another APK Static Analyzer

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking,…

Malicious HTTP traffic explorer

Patch Binaries via MITM: BackdoorFactory + mitmProxy.

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…

Script to generate malicious debian packages (debain trojans).

Local privilege escalation exploit for CVE-2026-31431 in the Linux kernel crypto subsystem, providing root access and container breakout with a…