
malwarescanner
Hash-based malware scanner for incident response. Scans files recursively using known malware hashes, supports multithreading, extension filtering,…

Hash-based malware scanner for incident response. Scans files recursively using known malware hashes, supports multithreading, extension filtering,…

An LLM extension for Ghidra to enable AI assistance in RE.

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

Malicious Extension Database

Incident Response & Digital Forensics Debugging Extension

CERT Kaiju is a binary analysis framework extension for the Ghidra software reverse engineering suite. This repository is a "mirror" -- please file…

WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

Extension to grab github token from VSCode

A comprehensive browser extension (.xpi) malware scanner which checks for many common malware tricks like:, credential-stealers obfuscation tactics,…

The FLARE team's open-source extension to add Python 3 scripting to Ghidra.

CuckooDroid - Automated Android Malware Analysis with Cuckoo Sandbox.

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

Technical dissection of CVE-2026-0628, a Chromium WebView privilege escalation vulnerability, including root cause analysis, PoC exploit, detection…

CVE-2023-38831 - WinRAR