
packer-tutorial
A tutorial on how to write a packer for Windows!

A tutorial on how to write a packer for Windows!

A guide on how to write fast and memory friendly YARA rules

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

POC about how to detect windows kernel debug by pool tag.

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have…

How to use PiDqSerializationWrite. Introduces how to safely read and write from mapped driver

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Cortex: a Powerful Observable Analysis and Active Response Engine

Spoof file icons and extensions in Windows

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements

WinDbg plugin for automated malware dynamic analysis and IOC extraction. Executes within the debugger to collect predefined indicators and writes…

A list of covert channels and steganography/steganalysis resources (books, papers & tools)

Backdooring Claude Code via hooks in settings.json. Authorized use only!

Proof-of-concept tool for detecting AMSI (Antimalware Scan Interface) bypasses and malicious in-memory script activity on Windows endpoints.