
dynmx
Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!

Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!

Embedded GRU neural network for real-time human behavior verification via mouse movement analysis, detecting automated analysis systems, sandboxes,…

Command-line and Python debugger for instrumenting and modifying native software behavior on Windows and Linux.

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

A python script developed to process Windows memory images based on triage type.

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office RCE) with a hosted server for DLL payload delivery, based on…

DLL hijacking proof-of-concept that weaponizes Microsoft Defender's MpClient.dll to load Cobalt Strike, demonstrating LockBit-style defense evasion.

Kernel-mode filter driver that monitors ConDrv traffic to detect mimikatz execution in real-time, logging detection events via ETW for incident…

Sandboxed malware detection tool that executes Windows binaries in an isolated environment, monitors dynamic behavior via DynamoRIO instrumentation,…

A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis

Malicious DOCX generator exploiting CVE-2021-40444 for remote code execution via crafted Office documents, with integrated hosting server for payload…

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted Office documents, with an integrated hosting…

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office Word RCE) with a built-in HTTP server for payload delivery and…

An x86-64 code virtualizer for VM based obfuscation

Retargetable machine-code decompiler based on LLVM that translates executable binaries (ELF, PE, Mach-O) into C or Python-like high-level code with…

Platform independent peCloak fork based on Capstone

VBScript & VBA source-to-source deobfuscator with partial-evaluation