
fake-sandbox
👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Collection of some easy of use tools - in powershell.

PowerShell module for automatic detection of P/Invoke, Dynamic P/Invoke, and D/Invoke in .NET assemblies. Reveals unmanaged API calls, MDTokens, and…

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

A PowerShell Module Dedicated to Reverse Engineering

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

AutoIt HackTool, Shortcuts .lnk Payloads Generator As LNK-KISSER.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.