
BlueTeam-Tools
Tools and Techniques for Blue Team / Incident Response

Tools and Techniques for Blue Team / Incident Response

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Quickly find differences and similarities in disassembled code

Static analyzer for PE executables with plugin-based detection of packers, compilers, suspicious imports, cryptographic constants, and ClamAV…

Security Scanner for Agent Skills

Android virtual machine and deobfuscator

JA4+ is a suite of network fingerprinting standards

RAT And C&C Resources. 250+ Open Source Projects, 1200+ RAT/C&C blog/video.

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

Python Decoders for Common Remote Access Trojans

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Multi-cipher shellcode encryptor and obfuscator with automatic output conversion to C, C#, Rust, Nim, Python, and more. Supports ROT, XOR, RC4, AES,…

A PowerShell Module Dedicated to Reverse Engineering

Automated hypervisor-level malware analysis sandbox with agentless guest introspection, web-based result exploration, and guided installer for…

Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…