iamsopotatoe-coder/TinyLoad: PE packer/crypter for Windows. compresses and encrypts executables with a custom virtual machine into a self extracting stub.
https://github.com/iamsopotatoe-coder/TinyLoad
🎖@malwr
https://github.com/iamsopotatoe-coder/TinyLoad
🎖@malwr
GitHub
GitHub - iamsopotatoe-coder/TinyLoad: Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a…
Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub. - iamsopotatoe-coder/TinyLoad
Inside the OS-Aware Phishing Kit Profiling Your Device
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.
https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device
🎖@malwr
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.
https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device
🎖@malwr
Knowbe4
Inside the OS-Aware Phishing Kit Profiling Your Device
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.
zhaoxuya520/reverse-skill: Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
https://github.com/zhaoxuya520/reverse-skill#about
🎖@malwr
https://github.com/zhaoxuya520/reverse-skill#about
🎖@malwr
GitHub
GitHub - zhaoxuya520/reverse-skill: Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack…
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Cod...
❤1
tmm35/ScheduledSpy: A command line process execution monitor for Windows.
https://github.com/tmm35/ScheduledSpy
🎖@malwr
https://github.com/tmm35/ScheduledSpy
🎖@malwr
GitHub
GitHub - tmm35/WindowsExecutionMonitor: A command line process execution monitor for Windows.
A command line process execution monitor for Windows. - tmm35/WindowsExecutionMonitor
jobehi/macos-process-killer: A simple tool for a simple task
https://github.com/jobehi/macos-process-killer
🎖@malwr
https://github.com/jobehi/macos-process-killer
🎖@malwr
GitHub
GitHub - jobehi/macos-process-killer: A simple tool for a simple task
A simple tool for a simple task. Contribute to jobehi/macos-process-killer development by creating an account on GitHub.
bsmensah-ctrl/DLL-Injection-Lab: Simulate and detect the full DLL-injection telemetry chain—no VM, no admin, zero live processes touched. ATT&CK T1055.001 · JSONL · SARIF
https://github.com/bsmensah-ctrl/DLL-Injection-Lab
🎖@malwr
https://github.com/bsmensah-ctrl/DLL-Injection-Lab
🎖@malwr
GitHub
GitHub - bsmensah-ctrl/DLL-Injection-Lab: 🧪 Simulate and detect the full DLL-injection telemetry chain—no VM, no admin, zero live…
🧪 Simulate and detect the full DLL-injection telemetry chain—no VM, no admin, zero live processes touched. ATT&CK T1055.001 · JSONL · SARIF - bsmensah-ctrl/DLL-Injection-Lab
ANTIPHISHING PANEL
Free Software Suricata rules frequently updated with phishing threat vectors.
https://julioliraup.github.io/AT/
🎖@malwr
Free Software Suricata rules frequently updated with phishing threat vectors.
https://julioliraup.github.io/AT/
🎖@malwr
Antiphishing
Antiphishing Threat Intelligence Panel | Suricata
Threat Intelligence and Suricata detection rules for phishing across DNS, TLS and HTTP.
2026-7-31: SmartApeSG ClickFix campaign pushes unidentified RAT
https://www.malware-traffic-analysis.net/2026/07/31/index.html
🎖@malwr
https://www.malware-traffic-analysis.net/2026/07/31/index.html
🎖@malwr
❤2
2026-07-31: Seven days of scans and probes and web traffic hitting my web server
https://www.malware-traffic-analysis.net/2026/07/31/index2.html
🎖@malwr
https://www.malware-traffic-analysis.net/2026/07/31/index2.html
🎖@malwr
❤1
zyekhabdul/volatility3-ai-triage
https://github.com/zyekhabdul/volatility3-ai-triage
🎖@malwr
https://github.com/zyekhabdul/volatility3-ai-triage
volatility3-ai-triage performs high-utility memory triage by executing Volatility 3 plugins in parallel, cross-correlating raw memory artifacts across plugins, detecting advanced 2026 evasion techniques, and generating deterministic SIEM JSON / STIX 2.1 Threat Intel alongside executive Markdown & HTML Triage Reports via Local LLMs (Ollama) or Cloud APIs (Gemini, OpenAI).
🎖@malwr
GitHub
GitHub - zyekhabdul/volatility3-ai-triage: 🤖 AI-powered automated memory forensics & triage pipeline integrated with Volatility…
🤖 AI-powered automated memory forensics & triage pipeline integrated with Volatility 3 for rapid incident response. - zyekhabdul/volatility3-ai-triage
Static Devirtualization of Tencent VM
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.
https://back.engineering/blog/31/07/2026/
🎖@malwr
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.
https://back.engineering/blog/31/07/2026/
🎖@malwr
aftermathlabs.net
Static Devirtualization of Tencent VM
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.
🔥1
Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine — plus every structural blind spot. How Falcon sees you, and where the seams are.
https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/
🎖@malwr
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine — plus every structural blind spot. How Falcon sees you, and where the seams are.
https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/
🎖@malwr
DbgMan
Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud…
Turning Chrome Remote Desktop into Pure Red Team Ops
How to hide the Chrome Remote Desktop connection banner by patching a single dialog resource, then abuse host.json and MSI packaging to turn CRD into a quiet persistent access channel.
https://zerotracelab.com/blog/chrome-remote-desktop-red-ops
🎖@malwr
How to hide the Chrome Remote Desktop connection banner by patching a single dialog resource, then abuse host.json and MSI packaging to turn CRD into a quiet persistent access channel.
https://zerotracelab.com/blog/chrome-remote-desktop-red-ops
🎖@malwr
Zerotracelab
Turning Chrome Remote Desktop into Pure Red Team Ops
How to hide the Chrome Remote Desktop connection banner by patching a single dialog resource, then abuse host.json and MSI packaging to turn CRD into a quiet persistent access channel.
JoasASantos/NeuroPurple: The AI Autonomous SOC & Purple-Team Engine
https://github.com/JoasASantos/NeuroPurple
🎖@malwr
https://github.com/JoasASantos/NeuroPurple
🎖@malwr
❤1
oldwalls/pyghidra-PAL: A defensive decompilation layer: Ghidra facts, lifted into runnable Python & artifacts aiding analysis.
https://github.com/oldwalls/pyghidra-PAL
🎖@malwr
https://github.com/oldwalls/pyghidra-PAL
🎖@malwr
GitHub
GitHub - oldwalls/pyghidra-PAL: A defensive decompilation layer: Ghidra facts, lifted into runnable Python & artifacts aiding analysis.
A defensive decompilation layer: Ghidra facts, lifted into runnable Python & artifacts aiding analysis. - oldwalls/pyghidra-PAL
aelassas/servy: Professional-Grade Windows Service Wrapper with Real-Time Monitoring
https://github.com/aelassas/servy
🎖@malwr
https://github.com/aelassas/servy
Servy lets you run any app as a native Windows service with full control over the working directory, startup type, process priority, CPU affinity, logging, health checks, environment variables, dependencies, pre-launch and post-launch hooks, pre-stop and post-stop hooks, and parameters.
🎖@malwr
GitHub
GitHub - aelassas/servy: Enterprise-Grade Windows Service Wrapper with Real-Time Monitoring
Enterprise-Grade Windows Service Wrapper with Real-Time Monitoring - aelassas/servy
winterknife/PLATINUMPICK: Windows Kernel-Mode Shellcode Development Framework (WKMSDF)
https://github.com/winterknife/PLATINUMPICK
🎖@malwr
https://github.com/winterknife/PLATINUMPICK
🎖@malwr
GitHub
GitHub - winterknife/PLATINUMPICK: Windows Kernel-Mode Shellcode Development Framework (WKMSDF)
Windows Kernel-Mode Shellcode Development Framework (WKMSDF) - winterknife/PLATINUMPICK
ioallocate/Ira: Ira - Interactive Reverser Analyzation is a POC of detecting Software Debuggers trough Machine Learning.
https://github.com/ioallocate/Ira
🎖@malwr
https://github.com/ioallocate/Ira
🎖@malwr
GitHub
GitHub - ioallocate/Cinnamon: Cinnamon is a POC of detecting Software Debuggers trough Machine Learning.
Cinnamon is a POC of detecting Software Debuggers trough Machine Learning. - ioallocate/Cinnamon