
ThreatScraper
Python tool that queries the VirusTotal API to check file hashes against 70+ antivirus engines, schedules recurring scans, and exports detection…

Python tool that queries the VirusTotal API to check file hashes against 70+ antivirus engines, schedules recurring scans, and exports detection…

A comprehensive Python-based security tool for file scanning, malware detection, and analysis in an ever-evolving cyber landscape.

A small utility to deal with malware embedded hashes.

A modular Python application to pull intelligence about malicious files


Offset Independent Credential Extraction Tool

A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

Collection of DFIR and OSINT Python scripts for parsing malicious LNK samples, extracting OLE objects from MHTML, and hashing favicons to hunt…

CLI client for bulk DIARIO API consumption: upload PDF/Office documents, query file hashes, and automate malware analysis workflows via command-line…

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

A Binary Genetic Traits Lexer Framework

CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…

YARA-based scanner that detects obfuscated PHP malware and webshells using semantic pattern matching instead of file hashes, with a whitelist system…

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.