
hacksguard
A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing, YARA scanning, and heuristic risk scoring.

A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing, YARA scanning, and heuristic risk scoring.

PETriage: A symbol-unified PE file reader for triage, built for multi-platform and multi-interface use.

A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck

Extracts and decrypts malware configuration data from captured samples, automating C2 endpoint discovery, credential extraction, and indicator triage…

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

C-based tool exploiting the vulnerable wsftprm.sys kernel driver to terminate protected EDR/AV processes on Windows, including PPL processes, via…

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware…

Obfuscate specific windows apis with different apis

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

A Runtime Crypter in C for Linux ELF binaries.

Python config extractors for malware families including PlugX, Remcos, templateX, and RedLine Stealer, supporting C2 configuration extraction for…

Open-source malware analysis platform with static PE analysis, YARA pattern matching, VirusTotal integration, REST API, and Docker deployment for…

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).

Highly advanced Linux anti-exploitation and anti-tamper binary protector for ELF.

PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA,…

🛡️ Open-source binary protection toolkit for Windows PE. Nanomite, VM protection, anti-debug, and more.