Skip to content
Change the repository type filter

All

    Repositories list

    • DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely
      C++
      3928900Updated Dec 13, 2024Dec 13, 2024
    • ShimMe

      Public
      C++
      1813320Updated Oct 29, 2024Oct 29, 2024
    • NoFilter

      Public
      C
      4829620Updated Oct 29, 2024Oct 29, 2024
    • UAC-0099 is a threat actor that targets Ukraine since mid-2022
      1330Updated Dec 21, 2023Dec 21, 2023
    • Updated Repository for the Cyber Community Regarding Cyber Threats Affecting Israel
      21010Updated Nov 21, 2023Nov 21, 2023
    • LnkMaker used by APT37 - IOCs
      1100Updated Sep 27, 2023Sep 27, 2023
    • A tool to decrypt the information sent by the Rusty Flag malware to the C2
      Rust
      1100Updated Sep 14, 2023Sep 14, 2023
    • A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.
      C++
      3830310Updated Aug 31, 2023Aug 31, 2023
    • Recent Campaign abusing CVE-2023-36884
      1100Updated Jul 13, 2023Jul 13, 2023
    • MuddyWater C2 framework research
      21100Updated Jun 28, 2023Jun 28, 2023
    • JS dropper used recently for Bumblebee and IcedID infection
      1200Updated Jun 20, 2023Jun 20, 2023
    • CVE-2023-34362-IOCs. More information on Deep Instinct's blog site.
      2200Updated Jun 6, 2023Jun 6, 2023
    • Full details of the research can be found on our blog page
      2110Updated May 23, 2023May 23, 2023
    • Emotet IOCs of the new wave in 2023
      3200Updated Mar 10, 2023Mar 10, 2023
    • DuckTail campaign IOCs
      2100Updated Mar 9, 2023Mar 9, 2023
    • VSTO-POC

      Public
      A proof-of-concept created for academic/learning purposes, demonstrating both local and remote use of VSTO "Add-In's" maliciously
      C#
      53101Updated Feb 3, 2023Feb 3, 2023
    • C++
      4137812Updated Jan 19, 2023Jan 19, 2023
    • A python script that extracts the "command & control" server address from Ratty malware
      Python
      1300Updated Jan 11, 2023Jan 11, 2023
    • A simple PoC of a polyglot HTML + JAR file.
      2600Updated Jan 11, 2023Jan 11, 2023
    • C
      8462511Updated Dec 23, 2022Dec 23, 2022
    • Unchain AMSI by patching the provider’s unmonitored memory space
      PowerShell
      158800Updated Nov 24, 2022Nov 24, 2022
    • Exceller

      Public
      Replaces VBA cells function calls with their content, to make the VBA code less obfuscated and easier to detect by AV vendors.
      Python
      3200Updated Apr 25, 2022Apr 25, 2022
    • DeMotet

      Public
      Unpacking and decryption tools for the Emotet malware
      C++
      94600Updated Dec 5, 2021Dec 5, 2021
    • Command line interface to dump LSASS memory to disk via SilentProcessExit
      C++
      6044220Updated Dec 23, 2020Dec 23, 2020
    • dsc_fix

      Public
      Aids in reverse engineering libraries from dyld_shared_cache in IDA
      Python
      GNU General Public License v3.0
      2910230Updated Apr 30, 2017Apr 30, 2017
    • Mach-O

      Public
      Python
      GNU General Public License v3.0
      20200Updated Apr 16, 2017Apr 16, 2017
    • Extract the original ransomware binary from an NSIS installer
      C++
      111200Updated Mar 22, 2017Mar 22, 2017