
RansomCoinPublic
A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Signature finder (from PE-bear)

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

IoCs and YARA rules from Threatray's Threat Research

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

Python based tool for generating Shellcode from PIC C

This Repository Talks about the Follina MSDT from Defender Perspective

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

A tool to extract RTTI information from Delphi executables, written in pure Python

Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents