
YARA_for_config_extraction
Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)

Generate HDCP source and sink keys from the leaked master key

Decrypt and extract FortiOS 8.0.0 firmware images.

Malicious DOCX generator exploiting CVE-2021-40444 for remote code execution via crafted Office documents, with integrated hosting server for payload…

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

A post-processing script for TinyTracer

Python script using r2pipe to detect CVE-2017-13208 in Android libnetutils.so by checking for missing dhcp_size validation via static binary analysis.

Rust Demangler & Normalizer plugin for IDA

Reverse engineering scripts designed for extracting Yealink VOIP upgrade files

Extract AutoIt scripts embedded in PE binaries

This repository contains a IDA Python script to recover PrideLocker ESX encryptor strings and a YARA rule

A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.

IDA python script for deobfuscating Astaroth/Guildma injector DLL

Educational exploit for CVE-2019-1663 targeting a stack-based buffer overflow in Cisco RV routers. Includes a Python exploit script, reverse shell…