
imaginaryC2
Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Comprehensive 100% Unrestricted Technical Analysis of JAGUAR_TOOTH Malware (APT28). High-precision reconstruction of Cisco IOS SNMP exploitation, ROP…

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Bro/Zeek script for detecting Apache Struts CVE-2017-5638 reconnaissance, compromise, and malware download tracking with automated IP extraction.

A Zeek based Agent Tesla malware C2 detector.

CVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

A powerful and flexible tool to apply active attacks for disrupting stegomalware

A Zeek protocol analyzer for the Facefish rootkit, based on Spicy.

Originally a Honeypot for CVE-2026-20131

Lightweight telnet honeypot for capturing IoT malware samples and identifying active command-and-control infrastructure, designed for educational…

Reference analysis of a Linux kernel Open vSwitch memory-corruption vulnerability, covering root cause, impact, detection commands, and mitigation…

eBPF-based toolkit for sniffing network traffic, extracting OpenSSL TLS keys, and intercepting/decrypting TLS 1.2 connections in real time using…

Advanced detection of port scanning, DoS and malware attacks using Machine Learning techniques

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…


DNSChef (NG) - DNS proxy for Penetration Testers and Malware Analysts