
RevShell
A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

Contains a simple yara rule to hunt for possible compromised KeePass config files

It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have…

this is my simple article about CVE 2022-30190 (Follina) analysis. I use the lab from Letsdefend.

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Generates obfuscated VBA macros with AV/sandbox evasion for command execution payloads, supporting domain, disk, memory, and process checks.

metame is a metamorphic code engine for arbitrary executables

Quickly debug shellcode extracted during malware analysis

Cross-platform Yara scanner written in Go

Safe ransomware simulation tool for testing antivirus detection. Simulates macro staging, volume shadow copy deletion, document encryption, and note…


Platform independent peCloak fork based on Capstone

Lightweight macOS malware analysis sandbox that monitors system activity via OpenBSM or Monitor.app, generating detailed reports and timelines of…

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…

A LSTM based framework for handling multiclass imbalance in DGA botnet detection

YARA-based file scanner that monitors directories, detects malware in document archives, and outputs CSV results for SIEM integration.

A sample POC for CVE-2021-30657 affecting MacOS