Thomza's starred repositories

miasm

Reverse engineering framework in Python

Language:PythonLicense:GPL-2.0Stargazers:3457Issues:0Issues:0

frinet

Frida-based tracer for easier reverse-engineering on Android, iOS, Linux, Windows and most related architectures.

Language:CLicense:MITStargazers:452Issues:0Issues:0

Katalina

Katalina is like Unicorn but for Dalvik bytecode. It provides an environment that can execute Android bytecode one instruction at a time.

Language:PythonLicense:MITStargazers:136Issues:0Issues:0

ved-ebpf

VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF

Language:C++License:AGPL-3.0Stargazers:149Issues:0Issues:0

conf-presentations

Quarkslab conference talks

Stargazers:268Issues:0Issues:0

TEE-reversing

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

Stargazers:880Issues:0Issues:0

windiff

Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS.

Language:RustLicense:GPL-3.0Stargazers:319Issues:0Issues:0

refinery

High Octane Triage Analysis

Language:PythonLicense:NOASSERTIONStargazers:633Issues:0Issues:0

DFIRArtifactMuseum

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts that may no longer be readily available anymore.

Language:HTMLLicense:MITStargazers:545Issues:0Issues:0

pi-defender

Kernel Security driver used to block past, current and future process injection techniques on Windows Operating System.

Language:C++License:LGPL-3.0Stargazers:147Issues:0Issues:0

de4dot

.NET deobfuscator and unpacker.

Language:C#License:GPL-3.0Stargazers:6912Issues:0Issues:0

usbmuxd2

A socket daemon written in C++ to multiplex connections from and to iOS devices over USB and WIFI

Language:C++License:LGPL-3.0Stargazers:187Issues:0Issues:0

IDAGraphity

IDAGraphity: An Interactive Binary Data Visualization Plugin for IDA Pro

Language:PythonLicense:Apache-2.0Stargazers:8Issues:0Issues:0

multicast_bytecopy

kernel r/w exploit for iOS 15.0 - 15.1.1

Language:CStargazers:256Issues:0Issues:0

pe_to_shellcode

Converts PE into a shellcode

Language:C++License:BSD-2-ClauseStargazers:2346Issues:0Issues:0

Windows_Malware_Emulator

Emulator for Windows Malware Analysis

Language:PythonLicense:Apache-2.0Stargazers:12Issues:0Issues:0

binlex

A Binary Genetic Traits Lexer Framework

Language:C++License:UnlicenseStargazers:385Issues:0Issues:0

hollows_hunter

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

Language:CLicense:BSD-2-ClauseStargazers:2008Issues:0Issues:0

karton

Distributed malware processing framework based on Python, Redis and S3.

Language:PythonLicense:BSD-3-ClauseStargazers:386Issues:0Issues:0

caldera

Automated Adversary Emulation Platform

Language:PythonLicense:Apache-2.0Stargazers:5536Issues:0Issues:0

sigma

Main Sigma Rule Repository

Language:PythonLicense:NOASSERTIONStargazers:8191Issues:0Issues:0

pe-sieve

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Language:C++License:BSD-2-ClauseStargazers:3052Issues:0Issues:0

Malware-analysis-and-Reverse-engineering

Some of my publicly available Malware analysis and Reverse engineering.

Language:PythonStargazers:749Issues:0Issues:0

drakvuf

DRAKVUF Black-box Binary Analysis

Language:C++License:NOASSERTIONStargazers:1047Issues:0Issues:0

malware_training_vol1

Materials for Windows Malware Analysis training (volume 1)

Language:AssemblyStargazers:1920Issues:0Issues:0

mimikatz

A little tool to play with Windows security

Language:CStargazers:19297Issues:0Issues:0

mwdb-core

Malware repository component for samples & static configuration with REST API interface.

Language:PythonLicense:NOASSERTIONStargazers:320Issues:0Issues:0

DetectionLab

Automate the creation of a lab environment complete with security tooling and logging best practices

Language:HTMLLicense:MITStargazers:4615Issues:0Issues:0

impacket

Impacket is a collection of Python classes for working with network protocols.

Language:PythonLicense:NOASSERTIONStargazers:13350Issues:0Issues:0

Apollo-11

Original Apollo 11 Guidance Computer (AGC) source code for the command and lunar modules.

Language:AssemblyLicense:NOASSERTIONStargazers:57572Issues:0Issues:0