
jd
Go CLI that deobfuscates javascript-obfuscator (obfuscator.io) output and unminifies JavaScript using AST transforms, static decoding, and a goja…

Go CLI that deobfuscates javascript-obfuscator (obfuscator.io) output and unminifies JavaScript using AST transforms, static decoding, and a goja…

Defense Against the Shai-Hulud Supply Chain Attack

Static analysis tool for investigating potentially malicious Microsoft Excel files, extracting metadata, macros, and embedded objects to aid digital…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

A tool written in Go that scans files & directories for the Follina exploit (CVE-2022-30190)

Multi-cipher shellcode encryptor and obfuscator with automatic output conversion to C, C#, Rust, Nim, Python, and more. Supports ROT, XOR, RC4, AES,…

EXOCET - AV-evading, undetectable, payload delivery tool

Chepy is a python lib/cli equivalent of the awesome CyberChef tool.

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the…

A tool written in Go that scans files & directories for the Follina exploit (CVE-2022-30190)

A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.

bad stuffs by bad guys

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

Imphash-like calculation on Golang binaries

Detect images that likely exploit CVE-2022-44268