
oversight
A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia,…

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

A simple tool to allows users to search for and analyze android apps for potential security threats and vulnerabilities

A tool to assist with network-based hunting for GRU's Drovorub malware c2

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool



Malcom - Malware Communications Analyzer

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

Detect and respond to Cobalt Strike beacons using ETW.

A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.