
AntiVE-BehaviorWatch
Embedded GRU neural network for real-time human behavior verification via mouse movement analysis, detecting automated analysis systems, sandboxes,…

Embedded GRU neural network for real-time human behavior verification via mouse movement analysis, detecting automated analysis systems, sandboxes,…

An API hooking framework for intercepting and monitoring Windows applications

🔵 Threat analysis writeup for Follina (CVE-2022-30190) — Microsoft MSDT RCE zero-day exploited in the wild. Covers static analysis, VirusTotal,…

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

No-root network monitor, firewall and PCAP dumper for Android

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

Multi-session IDALib MCP router for coding agents. Analyze multiple binaries in parallel with IDA-compatible reverse engineering tools.

Technical Analysis of Bibi-Windows Wiper Targeting Israeli Organizations


Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

:key: (THIS CODE IS OUTDATED FOR NEW CHROME VERSIONS) Decrypt chromium based browsers passwords, cookies, credit cards, history, bookmarks, autofill.…

This repository contains a list of new remediation scripts.

A YARA rules repository continuously updated for monitoring the old and new threats from articles, incidents responses ...

Kaspersky's GReAT KLara

HashDB API hash lookup plugin for IDA Pro

Botnet command & control monitor

Suspicious DGA from PDNS and Sandbox.