
anticuckoo
A tool to detect and crash Cuckoo Sandbox

A tool to detect and crash Cuckoo Sandbox

wsb-detect enables you to detect if you are running in Windows Sandbox ("WSB")

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

A script to detect stack-strings by using emulation (leveraging Unicorn)

SafeForge is an open-source mobile app hub built on GitLab that enables developers to build, upload, and share applications in a secure, AI-verified…

Zeek plugin to detect and decrypt XOR-encrypted EXEs

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware…

Rule-based Android malware scoring engine that analyzes APKs using static and dynamic analysis to detect vulnerabilities, identify malware families,…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research the…

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…

The Web Exploit Detector is a Node.js application used to detect possible infections, malicious code and suspicious files in web hosting environments

Strafer: A tool to detect potential infections in Elasticsearch instances

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)