
astaroth-deobfuscator
IDA python script for deobfuscating Astaroth/Guildma injector DLL

IDA python script for deobfuscating Astaroth/Guildma injector DLL

This repository has both an attack detection tool and a Proof-of-Concept (PoC) Python script for the WinRAR CVE-2023-38831 vulnerability.

Extract AutoIt scripts embedded in PE binaries

YARA rule and python script to detect potential exploits for the CVE-2026-21509 vulnerability in MS Office

A helper script for unpacking and decompiling EXEs compiled from python code.

Detection and sanitization for Acropalypse Now - CVE-2023-21036

Proof-of-concept exploit for CVE-2025-20260, a buffer overflow in ClamAV's PDF scanning. Includes a Python script to generate a malicious PDF and…

Local privilege escalation exploit for CVE-2026-31431 in the Linux kernel crypto subsystem, providing root access and container breakout with a…

A script that automatically submits files to Hybrid Analysis (API)

Extracts and analyzes PE file security characteristics (ASLR, DEP, CFG, NO_SEH) from DLLs and EXEs across directories, storing results in a SQLite…

IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix…

A post-processing script for TinyTracer

A python script developed to process Windows memory images based on triage type.

Auto Installer Script for Cuckoo Sandbox

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

This repository contains a IDA Python script to recover PrideLocker ESX encryptor strings and a YARA rule

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Decodes PlugX traffic and encrypted/compressed artifacts