
Nim-RunPE
A Nim implementation of reflective PE-Loading from memory

A Nim implementation of reflective PE-Loading from memory

Suspicious DGA from PDNS and Sandbox.

Automatically exported from code.google.com/p/jsunpack-n

Sigma rules from Joe Security

Generates pseudo-malicious files from YARA rules to trigger AV/EDR detection, enabling malware research, rule QA, and network sensor pressure testing…

A database of RAT collected from Internet

Enumerate various traits from Windows processes as an aid to threat hunting

Vba2Graph - Generate call graphs from VBA code, for easier analysis of malicious documents.

Ransomware decryption and script deobfuscation utilities from a threat intelligence team, designed for incident responders and malware analysts.

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

A YARA rules repository continuously updated for monitoring the old and new threats from articles, incidents responses ...

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

Rules shared by the community from 100 Days of YARA 2024

Rules Shared by the Community from 100 Days of YARA 2023

Hides Process From Task Manager Using NT API Hooking (NtQuerySystemInformation)

Generates unique fingerprints of malware HTTP requests from pcap files using Tshark, enabling identification and grouping of malware families through…

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…