
Cheshire
Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

Lightweight macOS malware analysis sandbox that monitors system activity via OpenBSM or Monitor.app, generating detailed reports and timelines of…

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

eBPF-based runtime security agent for Kubernetes that detects unknown processes and file changes, enforces pre-registered constraints, and automates…

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the…

Rogue Binary Model Context Protocol (MCP): a Docker-packaged binary analysis lab for AI agents. It supports reverse engineering, malware triage, and…

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

This is a little plugin to copy disassembly in a way that is usable in YARA rules!

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

A tool written in Go that scans files & directories for the Follina exploit (CVE-2022-30190)

AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and generates…

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Tool that can be used to trim useless things from a PE file such as the things a file pumper would add.

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.