
oversight
Terminal-based security auditor that statically analyzes shell scripts and commands, dynamically enforces sandboxing via Linux Landlock, and provides…

Terminal-based security auditor that statically analyzes shell scripts and commands, dynamically enforces sandboxing via Linux Landlock, and provides…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Multi-engine threat hunting tool for triaging malware samples, URLs, IPs, and IOCs across 20+ services including VirusTotal, Hybrid Analysis, and…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Portable forensic acquisition tool for Android devices that extracts SMS, APKs, system logs, and process lists to identify spyware and compromise…

A simple tool to allows users to search for and analyze android apps for potential security threats and vulnerabilities

A tool to assist with network-based hunting for GRU's Drovorub malware c2

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool

Rule-based pattern matching engine for identifying and classifying malware samples using textual and binary patterns, with Python bindings and…

Rust-based pattern matching engine for malware researchers. Create YARA rules with textual/binary patterns, wildcards, and regex to identify and…

Analyzes network traffic to detect C&C servers, peer-to-peer networks, and DNS fast-flux infrastructures, cross-referencing with known malware…

Curated list of awesome projects and resources related to Rust and computer security

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

Detect and respond to Cobalt Strike beacons using ETW.

A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Zeek package and Suricata rules to detect ICMP ping tunnels associated with the Pingback C2 malware, enabling network defense against covert…