Stars
SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.
ClamAV - Documentation is here: https://docs.clamav.net
Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks
A machine learning tool that ranks strings based on their relevance for malware analysis.
FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.
A repository of Windows Shellcode runners and supporting utilities. The applications load and execute Shellcode using various API calls or techniques.
Scripts to run within Ghidra, maintained by the Trellix ARC team
SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also contains its own custom disassembler, with many innovative featur…
A utility to dump all Protobuf file descriptors from a given binary as *.proto files
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
An List of my own Powershell scripts, commands and Blogs for windows Red Teaming.
An awesome collection of aesthetic wallpapers
A launch point for your personal nvim configuration
Windows Privilege Escalation from User to Domain Admin.
A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.
Get up and running with Llama 3.3, Phi 4, Gemma 2, and other large language models.
A Ghidra script that enables the analysis of selected functions and instructions using Large Language Models (LLMs). It aims to make reverse-engineering more efficient by using Ollama's API directl…
😸 Soothing pastel theme for the high-spirited!
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.
Application: Collect ALL UniFi Controller, Site, Device & Client Data - Export to InfluxDB or Prometheus