Static and dynamic analysis of an ARM64 ELF sample from the Mirai/Gafgyt family.
Minimal bare-metal kernel for AArch64, built from scratch and executed on QEMU’s virt machine.
Windows kernel driver for malware analysis, logging process, image load, network, and registry activity in real time.
Collection of Python scripts automating operations on MISP instances through PyMISP.
CLI tool that generates MITRE ATT&CK heatmaps from ATT&CK Navigator JSON layers.
Discord bot for static file triage and analysis.
Ghidra script framework for automated static detection of malware behaviors: anti-debug, anti-VM, packing, C2 indicators, process injection, persistence and defense impairment.
WinDbg extension for automated Windows malware analysis. Sets breakpoints, dumps memory regions in PE format and generates structured reports.