
hexalocker-analysis
HexaLocker ransomware analysis

HexaLocker ransomware analysis

Curated collection of indicators of compromise extracted from real-world malware investigations, including hashes, domains, and IPs for threat…

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

A fully functional DanderSpritz lab in 2 commands


Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…

PoC MSI payload based on ASEC/AhnLab's blog post

Post CVE-2024-7344 analysis of Howyar SysReturn NetCopy - reverse engineering notes, vulnerable binaries, vendor correspondence, and proof-of-concept…

Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving…

An Open-Source Pre and Post Callback-Based Framework for macOS Kernel Monitoring.

Decrypted content of odd.tar.xz.gpg, swift.tar.xz.gpg and windows.tar.xz.gpg

Post-exploitation and evasion research toolkit for Linux.

WinDbg plugin for automated malware dynamic analysis and IOC extraction. Executes within the debugger to collect predefined indicators and writes…

PoC C&C for the Industroyer malware

KrustyLoader Analysis

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

This repository contains a IDA Python script to recover PrideLocker ESX encryptor strings and a YARA rule