
msidump
MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.

MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solutions that clash…

Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows

C++ tool that patches Windows API calls to bypass sandbox RAM size checks, enabling malware to evade detection in isolated analysis environments.

Incarcero is a tool that creates Virtual Machines (VMs) preconfigured with malware analysis tools and security settings tailored for malware analysis…

Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.

Created a VERY SIMPLE remote access Trojan that will establish administrative control over any windows machine it compromises.

A collection of various and sundry code snippets that leverage .NET dynamic tradecraft

WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.

NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

Python virus that will make your pc paralyzed once it opened :D

A scanner that files with compromised or untrusted code signing certificates written in python.