ANTIPHISHING PANEL
Free Software Suricata rules frequently updated with phishing threat vectors.
https://julioliraup.github.io/AT/
π@malwr
Free Software Suricata rules frequently updated with phishing threat vectors.
https://julioliraup.github.io/AT/
π@malwr
Antiphishing
Antiphishing Threat Intelligence Panel | Suricata
Threat Intelligence and Suricata detection rules for phishing across DNS, TLS and HTTP.
2026-7-31: SmartApeSG ClickFix campaign pushes unidentified RAT
https://www.malware-traffic-analysis.net/2026/07/31/index.html
π@malwr
https://www.malware-traffic-analysis.net/2026/07/31/index.html
π@malwr
β€2
2026-07-31: Seven days of scans and probes and web traffic hitting my web server
https://www.malware-traffic-analysis.net/2026/07/31/index2.html
π@malwr
https://www.malware-traffic-analysis.net/2026/07/31/index2.html
π@malwr
β€1
zyekhabdul/volatility3-ai-triage
https://github.com/zyekhabdul/volatility3-ai-triage
π@malwr
https://github.com/zyekhabdul/volatility3-ai-triage
volatility3-ai-triage performs high-utility memory triage by executing Volatility 3 plugins in parallel, cross-correlating raw memory artifacts across plugins, detecting advanced 2026 evasion techniques, and generating deterministic SIEM JSON / STIX 2.1 Threat Intel alongside executive Markdown & HTML Triage Reports via Local LLMs (Ollama) or Cloud APIs (Gemini, OpenAI).
π@malwr
GitHub
GitHub - zyekhabdul/volatility3-ai-triage: π€ AI-powered automated memory forensics & triage pipeline integrated with Volatilityβ¦
π€ AI-powered automated memory forensics & triage pipeline integrated with Volatility 3 for rapid incident response. - zyekhabdul/volatility3-ai-triage
Static Devirtualization of Tencent VM
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.
https://back.engineering/blog/31/07/2026/
π@malwr
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.
https://back.engineering/blog/31/07/2026/
π@malwr
aftermathlabs.net
Static Devirtualization of Tencent VM
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.
π₯1
Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine β plus every structural blind spot. How Falcon sees you, and where the seams are.
https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/
π@malwr
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine β plus every structural blind spot. How Falcon sees you, and where the seams are.
https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/
π@malwr
DbgMan
Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloudβ¦
Turning Chrome Remote Desktop into Pure Red Team Ops
How to hide the Chrome Remote Desktop connection banner by patching a single dialog resource, then abuse host.json and MSI packaging to turn CRD into a quiet persistent access channel.
https://zerotracelab.com/blog/chrome-remote-desktop-red-ops
π@malwr
How to hide the Chrome Remote Desktop connection banner by patching a single dialog resource, then abuse host.json and MSI packaging to turn CRD into a quiet persistent access channel.
https://zerotracelab.com/blog/chrome-remote-desktop-red-ops
π@malwr
Zerotracelab
Turning Chrome Remote Desktop into Pure Red Team Ops
How to hide the Chrome Remote Desktop connection banner by patching a single dialog resource, then abuse host.json and MSI packaging to turn CRD into a quiet persistent access channel.
JoasASantos/NeuroPurple: The AI Autonomous SOC & Purple-Team Engine
https://github.com/JoasASantos/NeuroPurple
π@malwr
https://github.com/JoasASantos/NeuroPurple
π@malwr
β€1
oldwalls/pyghidra-PAL: A defensive decompilation layer: Ghidra facts, lifted into runnable Python & artifacts aiding analysis.
https://github.com/oldwalls/pyghidra-PAL
π@malwr
https://github.com/oldwalls/pyghidra-PAL
π@malwr
GitHub
GitHub - oldwalls/pyghidra-PAL: A defensive decompilation layer: Ghidra facts, lifted into runnable Python & artifacts aiding analysis.
A defensive decompilation layer: Ghidra facts, lifted into runnable Python & artifacts aiding analysis. - oldwalls/pyghidra-PAL
aelassas/servy: Professional-Grade Windows Service Wrapper with Real-Time Monitoring
https://github.com/aelassas/servy
π@malwr
https://github.com/aelassas/servy
Servy lets you run any app as a native Windows service with full control over the working directory, startup type, process priority, CPU affinity, logging, health checks, environment variables, dependencies, pre-launch and post-launch hooks, pre-stop and post-stop hooks, and parameters.
π@malwr
GitHub
GitHub - aelassas/servy: Enterprise-Grade Windows Service Wrapper with Real-Time Monitoring
Enterprise-Grade Windows Service Wrapper with Real-Time Monitoring - aelassas/servy
winterknife/PLATINUMPICK: Windows Kernel-Mode Shellcode Development Framework (WKMSDF)
https://github.com/winterknife/PLATINUMPICK
π@malwr
https://github.com/winterknife/PLATINUMPICK
π@malwr
GitHub
GitHub - winterknife/PLATINUMPICK: Windows Kernel-Mode Shellcode Development Framework (WKMSDF)
Windows Kernel-Mode Shellcode Development Framework (WKMSDF) - winterknife/PLATINUMPICK
ioallocate/Ira: Ira - Interactive Reverser Analyzation is a POC of detecting Software Debuggers trough Machine Learning.
https://github.com/ioallocate/Ira
π@malwr
https://github.com/ioallocate/Ira
π@malwr
GitHub
GitHub - ioallocate/Cinnamon: Cinnamon is a POC of detecting Software Debuggers trough Machine Learning.
Cinnamon is a POC of detecting Software Debuggers trough Machine Learning. - ioallocate/Cinnamon
NHCM-dev/BytecodeVM: Obfuscator obfuscate using pure java bytecode virtual machine to interpret mutated java bytecodes of original java program.
https://github.com/NHCM-dev/BytecodeVM
π@malwr
https://github.com/NHCM-dev/BytecodeVM
π@malwr
GitHub
GitHub - NHCM-dev/BytecodeVM: Obfuscator obfuscate using pure java bytecode virtual machine to interpret mutated java bytecodesβ¦
Obfuscator obfuscate using pure java bytecode virtual machine to interpret mutated java bytecodes of original java program. - NHCM-dev/BytecodeVM
Oros42/IMSI-catcher: This program show you IMSI numbers of cellphones around you.
https://github.com/Oros42/IMSI-catcher
π@malwr
https://github.com/Oros42/IMSI-catcher
π@malwr
GitHub
GitHub - Oros42/IMSI-catcher: This program show you IMSI numbers of cellphones around you.
This program show you IMSI numbers of cellphones around you. - Oros42/IMSI-catcher
VMMap Basics: How to Read a Windows Process's Memory Layout Β» TrainSec
Pavel Yosifovich uses VMMap to break down a process's memory layout, for developers and researchers who want to see what memory a process really uses.
https://trainsec.net/library/windows-internals/vmmap-basics-how-to-read-a-windows-processs-memory-layout/
π@malwr
Pavel Yosifovich uses VMMap to break down a process's memory layout, for developers and researchers who want to see what memory a process really uses.
https://trainsec.net/library/windows-internals/vmmap-basics-how-to-read-a-windows-processs-memory-layout/
π@malwr
TrainSec - CyberSecurity online training
VMMap Basics: How to Read a Windows Process's Memory Layout Β» TrainSec
Pavel Yosifovich uses VMMap to break down a process's memory layout, for developers and researchers who want to see what memory a process really uses.
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Hunt.io and NetAskari trace a leaked Android RAT framework across 170 active servers, analyze the APK builder internals, and document a successor platform called Night Dragon targeting Chinese users.
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
π@malwr
Hunt.io and NetAskari trace a leaked Android RAT framework across 170 active servers, analyze the APK builder internals, and document a successor platform called Night Dragon targeting Chinese users.
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
π@malwr
hunt.io
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Hunt.io and NetAskari trace a leaked Android RAT framework across 170 active servers, analyze the APK builder internals, and document a successor platform called Night Dragon targeting Chinese users.
gavamedia/deltafin: Run full Kimi K3 on a single device. And an OpenAI-compatible API server for local chat and coding agents.
https://github.com/gavamedia/deltafin
π@malwr
https://github.com/gavamedia/deltafin
π@malwr
GitHub
GitHub - gavamedia/deltafin: Run full Kimi K3 on a single device. And an OpenAI-compatible API server for local chat and codingβ¦
Run full Kimi K3 on a single device. And an OpenAI-compatible API server for local chat and coding agents. - gavamedia/deltafin
OctLurk and SilkLurk: new Backdoors in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/
π@malwr
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/
π@malwr