
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Static vulnerability findings tracker with parallel search across 11 CVE databases, EPSS enrichment, CISA KEV badges, coordinated disclosure…


Signatures and IoCs from public Volexity blog posts.

Sophos-originated indicators-of-compromise from published reports

Collection of extracted Microsoft Defender data for security research purposes


Gets updates from various clearnet domains and ransomware threat actor domains

Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

Rules generated from our investigations.

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Python library for extracting Indicators of Compromise, URLs, IP addresses, hashes, and email addresses from text using declarative grammars instead…

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

Curated dataset of confirmed phishing URLs from JPCERT/CC, including confirmation date, full URL, and spoofed brand for threat intelligence and…

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…