taogoldi's Stars
PwCUK-CTO/TheSAS2021-Red-Kelpie
Indicators of compromise, YARA rules, and Python scripts to supplement the TheSAS2021 talk "Learning to ChaCha with Red Kelpie"
boku7/Ninja_UUID_Runner
Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!
BushidoUK/Exploring-APT-campaigns
Further investigation in to APT campaigns disclosed by private security firms and security agencies
telekom-security/malware_analysis
This repository contains analysis scripts, YARA rules, and additional IoCs related to our Telekom Security blog posts.
Cloud-Architekt/AzureAD-Attack-Defense
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.
Sentinel-One/CobaltStrikeParser
nidhaloff/igel
a delightful machine learning tool that allows you to train, test, and use models without writing code
1d8/Coqui
Bare Bones Banking malware coded for research & educational purposes
sslab-gatech/pwn2own2020
Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities
StrangerealIntel/DailyIOC
IOC from articles, tweets for archives
malrev/ABD
Course materials for Advanced Binary Deobfuscation by NTT Secure Platform Laboratories
advanced-threat-research/Yara-Rules
Repository of YARA rules made by Trellix ATR Team
k-vitali/Malware-Misc-RE
Miscellaneous Malware RE
JPCERTCC/MalConfScan
Volatility plugin for extracts configuration data of known malware
gnebbia/pdlist
A passive subdomain finder
mnemonic-no/grafeo
Open platform for modelling, collection and exchange of knowledge
CIRCL/AIL-framework
AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project
InQuest/yara-rules
A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.
avast/ioc
Threat Intel IoCs + bits and pieces of dark matter
albertzsigovits/malware-writeups
Personal research and publication on malware families
Rurik/Noriben
Noriben - Portable, Simple, Malware Analysis Sandbox
mzfr/gtfo
Search gtfobins and lolbas files from your terminal
SafeBreach-Labs/pinjectra
Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)
Kevin-Robertson/Invoke-TheHash
PowerShell Pass The Hash Utils
blackorbird/APT_REPORT
Interesting APT Report Collection And Some Special IOC
Yelp/elastalert
Easy & Flexible Alerting With ElasticSearch
Yelp/amira
AMIRA: Automated Malware Incident Response & Analysis