Pinned Repositories
APT32_Deobfuscate
My scripts to deobfuscate APT32 malware
FLARE-ON9-Chal11_Unpacking-Pyarmor
My write-up for challenge 11 flareon 9: unpacking pyarmor
FLareOn10Note
PE_Packer
Simple Packer PE File
Shellcode_Infection
Shellcode for infect PEFile
levanvn's Repositories
levanvn/FLARE-ON9-Chal11_Unpacking-Pyarmor
My write-up for challenge 11 flareon 9: unpacking pyarmor
levanvn/APT32_Deobfuscate
My scripts to deobfuscate APT32 malware
levanvn/PE_Packer
Simple Packer PE File
levanvn/FLareOn10Note
levanvn/Shellcode_Infection
Shellcode for infect PEFile
levanvn/al-khaser
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
levanvn/APT_Digital_Weapon
Indicators of compromise (IOCs) collected from public resources and categorized by Qi-AnXin.
levanvn/atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
levanvn/awesome-threat-intelligence
A curated list of Awesome Threat Intelligence resources
levanvn/CobaltStrike
CobaltStrike's source code
levanvn/code
my code
levanvn/COM-Code-Helper
Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code
levanvn/cuckoo
Cuckoo Sandbox is an automated dynamic malware analysis system
levanvn/cuckoo-modified
Modified edition of cuckoo
levanvn/Dreadnought
PoC for detecting and dumping code injection (built and extended on UnRunPE)
levanvn/injection
levanvn/KernelBhop
Cheat that uses a driver instead WinAPI for Reading / Writing memory.
levanvn/levanvn.github.io
levanvn/malware
Malware Samples. Uploaded to GitHub for those want to analyse the code. Code mostly from: http://www.malwaretech.com
levanvn/memory_collector
levanvn/MemoryModule
Library to load a DLL from memory.
levanvn/mimikatz
A little tool to play with Windows security
levanvn/monitor
The new Cuckoo Monitor.
levanvn/reactos
A free Windows-compatible Operating System
levanvn/rootkit
Linux rootkit for Ubuntu 16.04 and 10.04 (Linux Kernels 4.4.0 and 2.6.32), both i386 and amd64
levanvn/Scylla
Imports Reconstructor
levanvn/SkyGate
Original name was localhost_safer, but, now, I change the name to SkyGate
levanvn/TitanEngine
levanvn/TitanHide
Hiding kernel-driver for x86/x64.
levanvn/WEEK3