
RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis
"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

DShield Sensor Log Collection with ELK

A repository that maps commonly used attacks using MSRPC protocols to ATT&CK


Recognizing the most likely APT groups responsible for an incident

I-SOON/Anxun leak related stuff

Detection of Linux Malware C2 RedXOR - demonstration

Mapping Corelight or Zeek data to Elastic Common Schema logs

Mapping Corelight or Zeek data to Elastic Common Schema fields

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

A Wordpress Honeypot

Python Decoders for Common Remote Access Trojans

Botnet command & control monitor

Scripts to detect Fast-Flux and DGA using DNS query responses

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…