
BruteRatel-DetectionTools
A collection of Tools and Rules for decoding Brute Ratel C4 badgers

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Tools and Techniques for Blue Team / Incident Response

A collection of small scripts and tools for deobfuscation and malware analysis.

Pre-configured bundle of reverse engineering and malware analysis tools for x86/x64 Windows systems, with desktop integration and plugin-ready…

Curated collection of EDR bypass resources including PoCs, tools, workshops, presentations, and blogs for ethical hacking and red team operations.

A collection of tools for dealing with TrickBot

An advanced memory forensics framework

CrowdStrike Feed Management System. CrowdFMS is a framework for automating collection and processing of samples from VirusTotal, by leveraging the…

A centralized and enhanced memory analysis platform

A collection of malware samples and relevant dissection information, most probably referenced from http://blog.inquest.net

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Cortex: a Powerful Observable Analysis and Active Response Engine

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Live hunting of code injection techniques

Collection of private Yara rules.

Volatility plugin for extracts configuration data of known malware