ald3ns
sr detection engineer @ huntress | interested in reverse engineering, malware analysis, detection engineering, and threat research
Huntress
Pinned Repositories
2020submissions
Pwn2Win CTF 2020 flag submissions
beautifulhugo
Theme for the Hugo static website generator
build-vmware-drivers
A quick script to solve the annoying issue of VMware kernel drivers not building on cutting edge kernels.
copy-as-yara
This is a little plugin to copy disassembly in a way that is usable in YARA rules!
geacon-config-extract
A small binja script to extract the config from ungarbled geacon/geacon plus samples.
lightspy-emulation
A reimplementation of the LightSpy malware targeting both macOS and iOS.
XPR-dump
Helper scripts to automate the extraction of YARA rules from XProtectRemediators
xz-backdoor-github-analysis
A simple Jupyter Notebook to graph a users commit history over time, specifically looking at the author of the xz backdoor.
ald3ns's Repositories
ald3ns/copy-as-yara
This is a little plugin to copy disassembly in a way that is usable in YARA rules!
ald3ns/xz-backdoor-github-analysis
A simple Jupyter Notebook to graph a users commit history over time, specifically looking at the author of the xz backdoor.
ald3ns/XPR-dump
Helper scripts to automate the extraction of YARA rules from XProtectRemediators
ald3ns/geacon-config-extract
A small binja script to extract the config from ungarbled geacon/geacon plus samples.
ald3ns/2020submissions
Pwn2Win CTF 2020 flag submissions
ald3ns/beautifulhugo
Theme for the Hugo static website generator
ald3ns/build-vmware-drivers
A quick script to solve the annoying issue of VMware kernel drivers not building on cutting edge kernels.
ald3ns/CTFd
CTFs as you need them
ald3ns/dawgctf-2020-writeups
ald3ns/jawa-font
Made a font from the "Jawa Trade Language".
ald3ns/otx-hash-grabber
A simple script to grab all of the hashes for a malware family from OTX
ald3ns/DefenderYara
Extracted Yara rules from Windows Defender mpavbase and mpasbase
ald3ns/I-S00N
ald3ns/pokemon-theme
ald3ns/shadowsocksr-native
翻墙 从容穿越党国敏感日 ShadowsocksR (SSRoT) native implementation for all platforms, GFW terminator
ald3ns/tart
macOS and Linux VMs on Apple Silicon to use in CI and other automations
ald3ns/vt-cli
VirusTotal Command Line Interface
ald3ns/yara-rules
YARA rules