Security Researcher | Malware Loving Homo Sapien
ImpulsiveDLLHijack. C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be weaponized during Red Team Operations to evade EDR's.
554pyc2bytecode. A Python Bytecode Disassembler helping reverse engineers in dissecting Python binaries by disassembling and analyzing the compiled python byte-code(.pyc) files across all python versions (including Python 3.10.*)
142OneNoteAnalyzer. A C# based tool for analysing malicious OneNote documents
119BumbleCrypt. A Bumblebee-inspired Crypter
78PoC-Malware-TTPs. PoC-Malware-TTPs
48DarkGate-Install-Script-via-DNS-TXT-Record. PoC showcasing new DarkGate Install Script retrieval technique via DNS TXT Record
45WinRAR-CVE-2025-8088-PoC-RAR. WinRAR 0day CVE-2025-8088 PoC RAR Archive
44WinRAR-Code-Execution-Vulnerability-CVE-2023-38831. Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)
40Lnk2Vbs. A Python script that embeds Target VBS into LNK and when executed runs the VBS script from within.
33NailaoLoader-Hiding-Execution-Flow. NailaoLoader: Hiding Execution Flow via Patching
24onMouseMove-HtmlFile-PoC. PoC for onMouseMove HTML file used in the Russian APT Group campaign targeting Ukraine
10BiBi-Windows-Wiper-Analysis. Technical Analysis of Bibi-Windows Wiper Targeting Israeli Organizations
8Kimsuky-PS-Backdoor. Kimsuky PowerShell Backdoor Analysis
6BlackSuit-Ransomware-CobaltStrike-Infra. BlackSuit Ransomware Cobalt Strike Infrastructure
4CVE-2023-43770-PoC. PoC for Stored XSS (CVE-2023-43770) Vulnerability
3windlls-hash-db. Precomputed hashes of Windows Dll names and their export function names using various hashing algorithms.
3CaptureX. CaptureX - C++ Windows Screen Capture Tool
1