
FalconEye
Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

x64 Dynamic Reverse Engineering Toolkit

Enumerate various traits from Windows processes as an aid to threat hunting

Lightweight macOS malware analysis sandbox that monitors system activity via OpenBSM or Monitor.app, generating detailed reports and timelines of…

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

DrSemu - Sandboxed Malware Detection and Classification Tool Based on Dynamic Behavior

Drltrace is a library calls tracer for Windows and Linux applications.

Red Team C code repo

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Rebuild of Windows kernel driver functions KeAttachProcess and KeDetachProcess, used for process attachment and anti-cheat bypass research.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Automates repair of malformed UPX headers in ELF binaries, restoring magic, filesize, blocksize, and overlay fields so standard unpackers can process…

Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for…