
quark-engine
Rule-based Android malware scoring engine that analyzes APKs using static and dynamic analysis to detect vulnerabilities, identify malware families,…

Rule-based Android malware scoring engine that analyzes APKs using static and dynamic analysis to detect vulnerabilities, identify malware families,…

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Static config extractor for SmokeLoader samples that deobfuscates, unpacks, and emulates protected routines to recover final-stage C2 settings.

Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

.NET/PowerShell/VBA Offensive Security Obfuscator

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

CVE-2022-1292 OpenSSL c_rehash Vulnerability

Kalim backdooe Malware Report

Collection of scripts for malware analysis, deobfuscation, and configuration extraction. Supports static analysis, unpacking, shellcode conversion,…

Config extractor for AgentTesla - Discord/Telegram Variant

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.