
scan
0-day malware detection for binaries, source & scripts (that doesn't suck)

0-day malware detection for binaries, source & scripts (that doesn't suck)

Detects CanaryTokens in Office docs and PDFs (docx, xlsx, pptx, pdf) without triggering alerts

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

Research environment and validation scripts for evaluating deserialization behaviors in MLflow and MLServer.

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android

A framework for automated extraction of static and dynamic features from Android applications

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Workshop on firmware reverse engineering

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

Scanner for the keyv/cacheable supply-chain attack: detects compromised npm packages, verifies payload hashes, and finds persistence implants in repo…

Provides supplemental files and Debian package sources for a specialized Linux distro focused on malware analysis, reverse engineering, and digital…

Modular file scanning/analysis framework

Ghidra is a software reverse engineering (SRE) framework

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification…

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…