
stegowiper
A powerful and flexible tool to apply active attacks for disrupting stegomalware

A powerful and flexible tool to apply active attacks for disrupting stegomalware

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Python tool that queries the VirusTotal API to check file hashes against 70+ antivirus engines, schedules recurring scans, and exports detection…

Hive v5 file decryption algorithm

Strafer: A tool to detect potential infections in Elasticsearch instances

Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.

This repository has both an attack detection tool and a Proof-of-Concept (PoC) Python script for the WinRAR CVE-2023-38831 vulnerability.

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Drltrace is a library calls tracer for Windows and Linux applications.

A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

Simulate the behavior of AV/EDR for malware development training.

DrSemu - Sandboxed Malware Detection and Classification Tool Based on Dynamic Behavior

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

A tool for malicious behavior detection in IoT devices

Proof-of-concept for CVE-2025-55891: heap corruption in TIFFCP.EXE via malformed TIFF file, triggering segmentation fault during LZW decompression in…