
IPED
IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

pefile is a Python module to read and work with PE (Portable Executable) files

JA4+ is a suite of network fingerprinting standards

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking,…

The world's first agentic reverse engineer.

A Binary Genetic Traits Lexer Framework

SSMA - Simple Static Malware Analyzer [This project is not maintained anymore by me]

Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)

Use YARA rules on Time Travel Debugging traces


Decodes PlugX traffic and encrypted/compressed artifacts

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

Real-world attack log analysis of CVE-2025-66478 (Next.js Server Actions RCE) with malware samples, attacker IP tracking, and container security…

PoC demonstrating SHA-1 code signing forgery and missing High Entropy ASLR in CyberGhostVPN installer, enabling trust bypass and predictable memory…