YaraHunter : A Comprehensive Malware Scanning Tool
YaraHunter, developed by Deepfence, is a versatile malware scanner designed for cloud-native environments.
It leverages YARA rulesets to detect indicators of compromise (IOCs) in...
Stuxnet : The Blueprint Of Modern WMI-Based Cyber Threats
Stuxnet, a groundbreaking cyberweapon first discovered in 2010, targeted Iran's nuclear facilities, marking a significant evolution in cyber warfare.
It exploited four zero-day vulnerabilities...
WhacAMole : A Comprehensive Malware Analysis Tool
WhacAMole (WAM) is a cutting-edge tool designed for in-depth memory and process analysis to detect, investigate, and document anomalies caused by malware.
It offers...
Relocatable : A Tool For Position Independent Code
Relocatable is an innovative tool designed to simplify the creation of Position Independent Code (PIC) in C.
This tool enables developers to write C...
StoneKeeper C2 : A Research-Oriented Command-And-Control Framework For EDR Evasion
The StoneKeeper C2 is an experimental command-and-control (C2) framework designed for research purposes, focusing on modern Windows malware tactics and Endpoint Detection and Response...
LitterBox : The Ultimate Sandbox Environment For Malware Testing And Red Team Operations
Your malware's favorite sandbox - where red teamers come to bury their payloads.
A sandbox environment designed specifically for malware development and payload testing.
This Web...
Minegrief : Unpacking A Crafty Minecraft Malware
Self-spreading to other Minecraft servers using an extendable, module-based lateral movement system.
Crafty Controller Auth'd RCE - undisclosed, unpatched, intentional(?) Auth'd RCE in Crafty Controller,...
HellBunny : Advanced Shellcode Loader For EDR Evasio
HellBunny is a malleable shellcode loader written in C and Assembly utilizing direct and indirect syscalls for evading EDR hooks. It can be built...
hrtng IDA Plugin : Elevating IDA’s Capabilities For Advanced Malware Analysis
hrtng IDA plugin is a collection of tools, ideas and experiments from different sources I've found interesting and useful in my reversing work.
A practical...
EmbedPayloadInPng : A Guide To Embedding And Extracting Encrypted Payloads In PNG Files
Embed a payload within a PNG file by splitting the payload across multiple IDAT sections. Each section is encrypted individually using its own 16-byte...