Skip to content
Change the repository type filter

All

    Repositories list

    • Supplementary material for LABScon 2024 talk "Knowledge IIS power"
      YARA
      Apache License 2.0
      0000Updated Oct 2, 2024Oct 2, 2024
    • IDA Pro plugin to aid with the analysis of native IIS modules
      Python
      Apache License 2.0
      41300Updated Aug 1, 2024Aug 1, 2024
    • Port of Mandiant ShellcodeHashes plugin from IDA to BinaryNinja
      Python
      Apache License 2.0
      21010Updated Jul 24, 2024Jul 24, 2024
    • rtfsig

      Public
      A tool to help malware analysts signature unique parts of RTF documents
      Rich Text Format
      22900Updated Jan 26, 2024Jan 26, 2024
    • SmartJump

      Public
      IDA Pro plugin to enhance the 'g' keyboard shortcut
      Python
      43700Updated Jul 24, 2023Jul 24, 2023
    • YARA
      Apache License 2.0
      0000Updated Apr 4, 2023Apr 4, 2023
    • Scripts to aid analysis of files obfuscated with ScatterBee.
      Python
      Apache License 2.0
      61500Updated Jan 6, 2023Jan 6, 2023
    • Indicators of compromise, YARA rules, and Python scripts to supplement the TheSAS2021 talk "Learning to ChaCha with Red Kelpie"
      YARA
      Apache License 2.0
      11100Updated Dec 21, 2022Dec 21, 2022
    • Indicators of compromise and YARA rules related to the BlackHat USA 2022 talk "Talent Need Not Apply"
      YARA
      Apache License 2.0
      0200Updated Aug 8, 2022Aug 8, 2022
    • Indicators of compromise, YARA rules, and Python scripts to supplement the SANS CTI Summit 2021 talk: "xStart when you're ready".
      Python
      Apache License 2.0
      21400Updated Jul 12, 2021Jul 12, 2021
    • Indicators of compromise relating to our report on APT10's targeting of global MSPs
      41000Updated Sep 26, 2017Sep 26, 2017