
p-invoke.net
Curated collection of P/Invoke definitions from pinvoke.net with Microsoft documentation links, enabling quick Windows API prototyping for security…

Curated collection of P/Invoke definitions from pinvoke.net with Microsoft documentation links, enabling quick Windows API prototyping for security…

Generate bulk YARA rules from YAML input

Extract payload URLs from Follina (CVE-2022-30190) docx and rtf files

Automated YARA rule generation from the Cert Central compromised certificate database.

Tool that can be used to trim useless things from a PE file such as the things a file pumper would add.

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Rules Shared by the Community from 100 Days of YARA 2023 -

Rules shared by the community from 100 Days of YARA 2026

Universal signature generation for any system function from all Windows Builds using Winbindex

Scans a list of raccoon servers from Tria.ge and extracts the config

Extracts nanocore sample from compile AutoIT script

Malware analysis from the domain goxlr.net

Rules shared by the community from 100 Days of YARA 2026

IDA python scripts to decrypt strings from KPOT and set those as comments

Live cryptojacking toolkit with CVE-2026-31431 LPE exploit, container escape, kernel rootkit, and XMRig Monero miner, captured from real attacks for…

IOCs and a read-only triage checklist from a real Linux root compromise: RedTail miner, XorDDoS persistence, MoneroOcean miner, DirtyFrag LPE…

RTF Cleaner, tries to extract URL from malicious RTF samples using CVE-2017-0199 & CVE-2017-8759

Analysis for stage1 shellcode loader from hacking