
tricorne
a Fedora remix focused on pentesting and purple hat tooling
defensive-toolsexploitationforensics+8
5

a Fedora remix focused on pentesting and purple hat tooling

Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution,…

Semantic analysis engine for detecting vulnerability fixes in Windows kernel driver patches — 58 YAML rules, Ghidra decompilation, reachability…

Extracts and decrypts malware configuration data from captured samples, automating C2 endpoint discovery, credential extraction, and indicator triage…

Tools developed by the Zscaler ThreatLabz Threat Intelligence team