llnl/OGhidra: OGhidra bridges Large Language Models (LLMs) via Ollama with the Ghidra reverse engineering platform, enabling AI-driven binary analysis through natural language. Interact with Ghidra using conversational queries and automate complex reverse engineering workflows.
https://github.com/llnl/OGhidra
π@malwr
https://github.com/llnl/OGhidra
π@malwr
GitHub
GitHub - llnl/OGhidra: OGhidra bridges Large Language Models (LLMs) via Ollama with the Ghidra reverse engineering platform, enablingβ¦
OGhidra bridges Large Language Models (LLMs) via Ollama with the Ghidra reverse engineering platform, enabling AI-driven binary analysis through natural language. Interact with Ghidra using convers...
2026-08-09: Traffic Analysis Exercise - First to Last
https://www.malware-traffic-analysis.net/2026/08/09/index.html
π@malwr
https://www.malware-traffic-analysis.net/2026/08/09/index.html
π@malwr
alpha-omega-security/threat-model: Agent skill for producing threat models for open-source projects
https://github.com/alpha-omega-security/threat-model
π@malwr
https://github.com/alpha-omega-security/threat-model
π@malwr
GitHub
GitHub - alpha-omega-security/threat-model: Agent skill for producing threat models for open-source projects
Agent skill for producing threat models for open-source projects - alpha-omega-security/threat-model
Poly0n/WinGuard: WinGuard
https://github.com/Poly0n/WinGuard
π@malwr
https://github.com/Poly0n/WinGuard
A User-Mode Windows Threat Detection Tool Inspired by EDR Techniques, To Help Monitor And Log Any Suspicious Activity On Your PC.
π@malwr
GitHub
GitHub - Poly0n/WinGuard: WinGuard - User-Mode Windows Threat Detection Tool
WinGuard - User-Mode Windows Threat Detection Tool - Poly0n/WinGuard
DosX-dev/obfus.h: Macro-header for compile-time C obfuscation (tcc, win x86/x64)
https://github.com/DosX-dev/obfus.h
π@malwr
https://github.com/DosX-dev/obfus.h
π@malwr
GitHub
GitHub - DosX-dev/obfus.h: Macro-header for compile-time C obfuscation (tcc, win x86/x64)
Macro-header for compile-time C obfuscation (tcc, win x86/x64) - DosX-dev/obfus.h
Osxninja/cybersecurity-projects: This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level development. It brings together the research, experiments, implementations, findings, and progress made throughout the project, providing a structured overview of the work from basic to advanced stages.
https://github.com/Osxninja/cybersecurity-projects
π@malwr
https://github.com/Osxninja/cybersecurity-projects
π@malwr
GitHub
GitHub - Osxninja/cybersecurity-projects: This repository contains the complete record of my three-year research journey, coveringβ¦
This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level development. It brings together the research, exper...
2026-08-07: Seven days of scans and probes and web traffic hitting my web server
https://www.malware-traffic-analysis.net/2026/08/07/index.html
π@malwr
https://www.malware-traffic-analysis.net/2026/08/07/index.html
π@malwr
2026-08-06: Remcos RAT (7.2.5 Pro) infection
https://www.malware-traffic-analysis.net/2026/08/06/index.html
π@malwr
https://www.malware-traffic-analysis.net/2026/08/06/index.html
π@malwr
KriyosArcane/TrustMeBro: Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types, WinVerifyTrust FinalPolicy bypass, PKCS#7 payload embedding, SIP execution surface implants, Smart App Control Bypass, and analyst-triggered persistence via OID handlers.
https://github.com/KriyosArcane/TrustMeBro
π@malwr
https://github.com/KriyosArcane/TrustMeBro
π@malwr
GitHub
GitHub - KriyosArcane/TrustMeBro: Authenticode signature manipulation toolkit for Red Team operations and security research. Coversβ¦
Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types, WinVerifyTrust FinalPolic...
DdUdle/ctxdebug: MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools.
https://github.com/DdUdle/ctxdebug
π@malwr
https://github.com/DdUdle/ctxdebug
π@malwr
GitHub
GitHub - DdUdle/ctxdebug: MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessibleβ¦
MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools. - DdUdle/ctxdebug
2026-08-10: Lumma Stealer or variant
https://www.malware-traffic-analysis.net/2026/08/10/index.html
π@malwr
https://www.malware-traffic-analysis.net/2026/08/10/index.html
π@malwr
NHCM-dev/JVMRTDP: A Java debugger & library which allows user and programmer to control remote JavaVMs
https://github.com/NHCM-dev/JVMRTDP
π@malwr
https://github.com/NHCM-dev/JVMRTDP
π@malwr
GitHub
GitHub - NHCM-dev/JVMRTDP: A Java debugger & library which allows user and programmer to control remote JavaVMs
A Java debugger & library which allows user and programmer to control remote JavaVMs - NHCM-dev/JVMRTDP
thomasxm/BOAZ_beta: Multilayered AV/EDR Evasion Framework (no longer actively maintained)
https://github.com/thomasxm/BOAZ_beta
π@malwr
https://github.com/thomasxm/BOAZ_beta
π@malwr
GitHub
GitHub - thomasxm/BOAZ_beta: Multilayered AV/EDR Evasion Framework (no longer actively maintained)
Multilayered AV/EDR Evasion Framework (no longer actively maintained) - thomasxm/BOAZ_beta
β€1
Shattering the Dream β When a Job Offer Becomes a Zero-Day Attack
https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
π@malwr
https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
π@malwr
Check Point Research
Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack - Check Point Research
Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviationβ¦
π1
Inside a Russian-Speaking Operator's Ukrainian IP Camera Toolkit
A Russian-speaking operator's open directory exposed the tools used to exploit and watch Ukrainian IP cameras, alongside attempts to breach government and military sites.
https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit
π@malwr
A Russian-speaking operator's open directory exposed the tools used to exploit and watch Ukrainian IP cameras, alongside attempts to breach government and military sites.
https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit
π@malwr
hunt.io
Inside a Russian-Speaking Operator's Ukrainian IP Camera Toolkit
A Russian-speaking operator's open directory exposed the tools used to exploit and watch Ukrainian IP cameras, alongside attempts to breach government and military sites.
A sample uses EnumWindows to iterate through all top-level windows and checks the window class name against a list. If a match is found, it calls PostMessage with WM_CLOSE. What is the malware targeting?
Final Results
33%
Preventing user intervention during ransomware execution
28%
Identifying and terminating sandbox monitoring tools
11%
Closing explorer.exe windows to force a shell restart
28%
Terminating security software windows to disable user interaction
Dynamic Analysis of VEH Dispatch and Exception-Context RIP Modification Using ROP Gadgets in ntdll.dll
Reverse engineering ntdll's VEH dispatch chain, RtlDispatchException, and RtlRestoreContext to understand VEHguard internals.
https://mooofin.github.io/portfolio/blog/vehguard.html?latex=1
π@malwr
Reverse engineering ntdll's VEH dispatch chain, RtlDispatchException, and RtlRestoreContext to understand VEHguard internals.
https://mooofin.github.io/portfolio/blog/vehguard.html?latex=1
π@malwr
mooofin.github.io
Dynamic Analysis of VEH Dispatch and Exception-Context RIP Modification Using ROP Gadgets in ntdll.dll
Reverse engineering ntdll's VEH dispatch chain, RtlDispatchException, and RtlRestoreContext to understand VEHguard internals.
Binary Ninja - The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html
π@malwr
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html
π@malwr
Binary Ninja
Binary Ninja - The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
2026-08-12: SmartApeSG ClickFix leads to two RATs
https://www.malware-traffic-analysis.net/2026/08/12/index.html
π@malwr
https://www.malware-traffic-analysis.net/2026/08/12/index.html
π@malwr