
MaliciousBrowserExtensions
This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

Vthunting is a tiny script used to generate report about Virus Total hunting and send it by email, slack or telegram.

A MITM (monster-in-the-middle) detection tool. Used to build MALCOLM:

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Python Decoders for Common Remote Access Trojans

A utility to safely generate malicious network traffic patterns and evaluate controls.

Your Swiss Army knife to analyze malicious web traffic based on the popular Fiddler web debugger.

Just-Metadata is a tool that gathers and analyzes metadata about IP addresses. It attempts to find relationships between systems within a large…

A modular Python application to collect intelligence for malicious hosts.

A modular Python application to pull intelligence about malicious files

Scripts to detect Fast-Flux and DGA using DNS query responses

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

A Wordpress Honeypot

A python package for use in generating fake data for SOC and security automation.

Detection of Linux Malware C2 RedXOR - demonstration

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Mapping Corelight or Zeek data to Elastic Common Schema fields