
awesome-threat-intelligence
Curated directory of threat intelligence sources, feeds, frameworks, tools, and research for SOC/CTI teams—covering IOCs, STIX/TAXII formats, and…

Curated directory of threat intelligence sources, feeds, frameworks, tools, and research for SOC/CTI teams—covering IOCs, STIX/TAXII formats, and…

RetDec is a retargetable machine-code decompiler based on LLVM.

Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!

Cosa Nostra, a FOSS graph based malware clusterization toolkit.

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

Python based tool for generating Shellcode from PIC C

A LSTM based framework for handling multiclass imbalance in DGA botnet detection

Katana Botnet used for DDoS attacks based on the Mirai Botnet. TEACHING PURPOSES ONLY! I CANNOT BE HELD RESPONSIBLE FOR ANYTHING YOU DO WITH IT! I…

Rust Weaponization for Red Team Engagements.

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…


Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution,…

Interactive documentation and visual reference for binary formats and system memory layouts.

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Detection of Linux Malware C2 RedXOR - demonstration

Technical analysis and reproduction of CVE-2023-21716, a critical heap-based buffer overflow in Microsoft Word's RTF parser, including root cause,…

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…