neeraj

Advanced
@knight0x07

Security Researcher | Malware Loving Homo Sapien

ImpulsiveDLLHijack. C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be weaponized during Red Team Operations to evade EDR's.

554

pyc2bytecode. A Python Bytecode Disassembler helping reverse engineers in dissecting Python binaries by disassembling and analyzing the compiled python byte-code(.pyc) files across all python versions (including Python 3.10.*)

142

OneNoteAnalyzer. A C# based tool for analysing malicious OneNote documents

119

BumbleCrypt. A Bumblebee-inspired Crypter

78

PoC-Malware-TTPs. PoC-Malware-TTPs

48

DarkGate-Install-Script-via-DNS-TXT-Record. PoC showcasing new DarkGate Install Script retrieval technique via DNS TXT Record

45

WinRAR-CVE-2025-8088-PoC-RAR. WinRAR 0day CVE-2025-8088 PoC RAR Archive

44

WinRAR-Code-Execution-Vulnerability-CVE-2023-38831. Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)

40

Lnk2Vbs. A Python script that embeds Target VBS into LNK and when executed runs the VBS script from within.

33

NailaoLoader-Hiding-Execution-Flow. NailaoLoader: Hiding Execution Flow via Patching

24

onMouseMove-HtmlFile-PoC. PoC for onMouseMove HTML file used in the Russian APT Group campaign targeting Ukraine

10

BiBi-Windows-Wiper-Analysis. Technical Analysis of Bibi-Windows Wiper Targeting Israeli Organizations

8

Kimsuky-PS-Backdoor. Kimsuky PowerShell Backdoor Analysis

6

BlackSuit-Ransomware-CobaltStrike-Infra. BlackSuit Ransomware Cobalt Strike Infrastructure

4

CVE-2023-43770-PoC. PoC for Stored XSS (CVE-2023-43770) Vulnerability

3

windlls-hash-db. Precomputed hashes of Windows Dll names and their export function names using various hashing algorithms.

3

CaptureX. CaptureX - C++ Windows Screen Capture Tool

1
17
Apply