
inside-pegasus
A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks.

Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Open-source Android client for VirusTotal. Scan files, URLs, and installed apps against 70+ antivirus engines. View detailed reports with hashes,…

Android Antivirus which doesn't require root, adb, ca install and cloud with many features and ways to detect more zero-day malware

Endpoint detection & Malware analysis software

Yara Rules for Modern Malware

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

A frida tool to dump dex in memory to support security engineers analyzing malware.

All-in-One malware analysis tool.

Mobile Edge-Dynamic Unified Security Analysis

Malicious Extension Database

AV/EDR Lab environment setup references to help in Malware development

Sigma rules from Joe Security