
MalPipe
Malware/IOC ingestion and processing engine

Malware/IOC ingestion and processing engine

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

Different methods to get current username without using whoami

Telegram Desktop Session Stealer

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Automated steganography detection tool that scans websites, web servers, and local directories using AI-driven object/text recognition and deep file…

Created a VERY SIMPLE remote access Trojan that will establish administrative control over any windows machine it compromises.

Educational guide and code repository for understanding APT attack techniques, covering reconnaissance, web and service exploitation, trojans, C2,…

Code developed to steal certain browser config files (history, preferences, etc)

Neto | A tool to analyse browser extensions

DNSChef (NG) - DNS proxy for Penetration Testers and Malware Analysts

Cisco ASA Software and ASDM Security Research

Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Modular malware analysis artifact collection and correlation framework

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…

Agentic memory for CTI in Python — STIX knowledge graphs, threat-actor alias resolution, offline-first RAG, MCP server for Claude Code and LangChain…