
refinery
Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…


IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix…


Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Python Decoders for Common Remote Access Trojans

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

Extract useful information from PANOS support file for CVE-2024-3400

Scans Discord links across mutual guilds to extract profiles, cross‑references 700+ sites, searches usernames with 30+ tools, and generates an…

Exploit for the CVE-2023-23397

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…


Automated OSINT tool for phone number discovery, pattern detection, and cross-platform correlation.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Extract indicators of compromise from text, including "escaped" ones.

Lua plugin to extract data from Wireshark and convert it into MISP format

This is a repo for fetching Applocker event log by parsing the win-event log

InfoHound is an OSINT to extract a large amount of data given a web domain name.