{"id":6500,"url":"https://github.com/Spacial/awesome-csirt","name":"awesome-csirt","description":"Awesome CSIRT is an curated list of links and resources in security and CSIRT daily activities.","projects_count":3225,"last_synced_at":"2026-09-01T19:00:51.087Z","repository":{"id":41766863,"uuid":"59441906","full_name":"Spacial/awesome-csirt","owner":"Spacial","description":"Awesome CSIRT is an curated list of links and resources in security and CSIRT daily activities.","archived":false,"fork":false,"pushed_at":"2025-11-25T17:45:31.000Z","size":1345,"stargazers_count":644,"open_issues_count":3,"forks_count":110,"subscribers_count":38,"default_branch":"master","last_synced_at":"2026-08-09T21:39:27.938Z","etag":null,"topics":["awesome","awesome-list","csirt","cve","exfiltration","exploits","malware-analysis","pentesting","poc","reverse-engineering","secure-programming","security","threat-intelligence"],"latest_commit_sha":null,"homepage":"","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Spacial.png","metadata":{"files":{"readme":"README.md","changelog":"News.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SecurityProjects.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2016-05-23T00:49:39.000Z","updated_at":"2026-08-06T04:12:54.000Z","dependencies_parsed_at":"2024-07-29T20:08:12.820Z","dependency_job_id":"1d7b73ec-075f-4217-9761-13383a81be68","html_url":"https://github.com/Spacial/awesome-csirt","commit_stats":null,"previous_names":["spacial/csirt"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/Spacial/awesome-csirt","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Spacial%2Fawesome-csirt","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Spacial%2Fawesome-csirt/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Spacial%2Fawesome-csirt/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Spacial%2Fawesome-csirt/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Spacial","download_url":"https://codeload.github.com/Spacial/awesome-csirt/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Spacial%2Fawesome-csirt/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36592161,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"online","status_checked_at":"2026-08-13T02:00:06.325Z","response_time":111,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2024-01-07T06:20:32.933Z","updated_at":"2026-09-01T19:00:51.088Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Malware Analysis","Pentesting","Reverse Engineering","Secure Programming","CTFs","Archs","Forensics","Blue Team","Browsers","Operating Systems","Books","Links","CVEs","Patching","Hardening","Tools","Credentials","Phreak","DNS","Exfiltration","Phishing","Mobile","Risk Assessment and Vulnerability Management","ICS (SCADA)","Radio","Social Engineering","Privacy","General","Resources","Sources","Fun","Articles","psyops","Frameworks","Other Repos"],"sub_categories":["Hashing","ARM","Malware Samples","Malware Articles and Sources","Payloads","Tokens","API","CTFs tools","Exploits","Reconnaissance","Enumeration","WebShells","ShellCodes","Reporting","OSINT - Open Source INTelligence","Steganography","Vulnerability","Volatility","SIEM","Windows","macOS/iOS","WAFs","Incident Response","SAST","Secure Web dev","Web Malwares","Repos","Ransomwares","Virus/Anti-Virus","Trojans/Loggers","Decompilers","Yara","Ghidra","Satellite","WebServers","Formal Analysis","Fuzzing","Hardware","Red Team","Purple Team","PDF","Email Headers","Distros","Threat Hunting","IoCs","Browsers Addons","UEFI","Android","Linux/ *Nix","Cloud","AWS","GCP/Google","Azure","Guidelines","Note-taking","IP Reputation","Shell tools","Search Engines","VPN","Secure Sharing","Training and Certifications","Sans","Configs","Conferences and Slides","Kali","Web Training"],"readme":"# CSIRT [![Awesome](https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg)](https://github.com/sindresorhus/awesome)\n\n **Please contribute through pull requests*- ;)\n\n Another great list: [awesome-incident-response](https://github.com/meirwah/awesome-incident-response)\n\n## Books\n\n- Nice list [here](https://github.com/Spacial/csirt/blob/master/books.md) by [Cert.BR](http://www.cert.br)\n- [Practical Cryptography for Developers](https://cryptobook.nakov.com/), [github](https://github.com/nakov/practical-cryptography-for-developers-book)\n- [The Book of Secret Knowledge](https://github.com/trimstray/the-book-of-secret-knowledge)\n- [Security Engineering](https://www.cl.cam.ac.uk/~rja14/book.html) — Third Edition\n- [The Cyber Plumber's Handbook](https://cph.opsdisk.com/index.html#students)\n\n## Links\n\n- [FIRST](http://www.first.org)\n  - [Malware Analysis Resources](https://www.first.org/global/sigs/malware/resources/)\n- [Cert.BR](http://www.cert.br) - useful [links](https://www.cert.br/links/)\n  - [7º Fórum Brasileiro de CSIRTs](https://www.cert.br/forum2018/)\n  - [9º Fórum Brasileiro de CSIRTs](https://cert.br/forum2020/)\n- SANS Pen-Testing Resources: [Downloads](https://pen-testing.sans.org/resources/downloads)\n- Some [list](https://github.com/Spacial/csirt/blob/master/SecurityProjects.md) of security projects\n- [APT \u0026 CyberCriminal Campaign Collection](https://github.com/CyberMonitor/APT_CyberCriminal_Campagin_Collections)\n- [Encoding vs. Encryption vs. Hashing vs. Obfuscation](https://danielmiessler.com/study/encoding-encryption-hashing-obfuscation/)\n- [Shodan](https://www.shodan.io/): is the world's first search engine for Internet-connected devices. [Shodan 2000](https://2000.shodan.io/)\n- [CriminalIP](https://www.criminalip.io/): Criminal IP is a specialized Cyber Threat Intelligence (CTI) search engine that allows users to search for various security-related information such as malicious IP addresses, domains, banners, etc. It can be widely integrated\n- [hacking-tutorials](https://github.com/maestron/hacking-tutorials)\n- [crypto](https://github.com/boazbk/crypto): Lecture notes for a course on cryptography\n- [tink](https://github.com/google/tink/): Tink is a multi-language, cross-platform library that provides cryptographic APIs that are secure, easy to use correctly, and hard(er) to misuse.\n- [SPLOITUS](https://sploitus.com/): Exploit search engine.\n- [Vulmon](https://vulmon.com/): Vulmon is a vulnerability search engine.\n- [Vulert](https://vulert.com/vuln-db/search): Vulert secures software by detecting vulnerabilities in open-source dependencies—without accessing your code. It supports Js, PHP, Java, Python, and more.\n- [CIS SecureSuite® Membership](https://www.cisecurity.org/cis-securesuite/)\n- [CRYPTO101](https://www.crypto101.io/): Crypto 101 is an introductory course on cryptography, freely available for programmers of all ages and skill levels.\n- [SMHasher](https://github.com/rurban/smhasher/) is a test suite designed to test the distribution, collision, and performance properties of non-cryptographic hash functions. [another repo](https://github.com/aappleby/smhasher)\n- [CPDoS](https://cpdos.org/): Cache Poisoned Denial of Service\n- [cacao](https://github.com/oasis-tcs/cacao): OASIS CACAO TC: Official repository for work of the [CACAO TC](https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=cacao)\n- [cti-documentation](https://github.com/oasis-open/cti-documentation)\n- [The 4th in the 5th: Temporal Aspects of Cyber Operations](https://www.recordedfuture.com/cyber-operations-time/)\n- [SOCless](https://twilio-labs.github.io/socless/): [The SOCless automation framework](https://github.com/twilio-labs/socless)\n- [Open CSIRT Foundation](https://opencsirt.org/) - [SIM v3 Model](http://opencsirt.org/wp-content/uploads/2019/12/SIM3-mkXVIIIc.pdf) and [SIM3 Self Assessment](https://sim3-check.opencsirt.org).\n- [Global Forum on Cyber Expertise (GFCE)](https://thegfce.org/).\n- [Ten strategies of a world-class cybersecurity operations center](https://www.mitre.org/publications/all/ten-strategies-of-a-world-class-cybersecurity-operations-center)\n- [my-infosec-awesome](https://github.com/pe3zx/my-infosec-awesome).\n- [How to Secure Anything](https://github.com/veeral-patel/how-to-secure-anything). How to systematically secure anything: a repository about security engineering\n- [Metasploitable3](https://github.com/rapid7/metasploitable3): is a VM that is built from the ground up with a large amount of security vulnerabilities.\n- [Institute for Security and Technology](https://securityandtechnology.org/about-ist/): builds solutions to enhance the security of the global commons. Our goal is to provide the tools and insights needed for companies and governments to outpace emerging global security threats. Our non-traditional approach has a bias towards action, as we build trust across domains, provide unprecedented access, and deliver and implement solutions.\n- [NIST'S CYBERSECURITY FRAMEWORK](https://www.nist.gov/cyberframework)\n- [pluto-eris](https://github.com/daira/pluto-eris): Generator and supporting evidence for security of the Pluto/Eris half-pairing cycle of elliptic curves.\n- [cset](https://github.com/cisagov/cset): Cybersecurity Evaluation Tool by CISA.gov.\n- [comply](https://github.com/strongdm/comply): Compliance automation framework, focused on SOC2.\n- [Illustrated X.509 Certificate](https://darutk.medium.com/illustrated-x-509-certificate-84aece2c5c2e)\n- [Open Security Controls Assessment Language (OSCAL)](https://github.com/usnistgov/OSCAL): NIST is developing the Open Security Controls Assessment Language (OSCAL), a set of hierarchical, XML-, JSON-, and YAML-based formats that provide a standardized representations of information pertaining to the publication, implementation, and assessment of security controls.\n- [DWF](https://github.com/distributedweaknessfiling/dwflist): The DWF Identifiers dataset, distributed weakness filing.\n- [OASIS Common Security Advisory Framework (CSAF)](https://oasis-open.github.io/csaf-documentation/) [repo](https://github.com/oasis-tcs/csaf) [secvisogram](https://github.com/secvisogram/secvisogram) [editor](https://secvisogram.github.io/)\n- [notrandom](https://github.com/fx5/not_random): reverse the Mersenne Twister.\n- [OpenEX](https://www.openex.io/en/): Crisis drills planning platform. [repo](https://github.com/OpenEx-Platform/openex)\n- [NCSI](https://ncsi.ega.ee/): The National Cyber Security Index is a global index, which measures the preparedness of countries to prevent cyber threats and manage cyber incidents.\n- [THE EVOLUTION OF TRUST](https://ncase.me/trust/)\n- [Cybersecurity](https://github.com/Berkanktk/CyberSecurity): A collection of essential and foundational cybersecurity knowledge, thoughtfully organized for easy comprehension.\n\n### Incident Response\n\n- [Applying DevOps Principles in Incident Response](https://insights.sei.cmu.edu/devops/2015/09/applying-devops-principles-in-incident-response.html)\n- [Pagerduty Incident Response](https://response.pagerduty.com/): This documentation covers parts of the PagerDuty Incident Response process.\n  - [security-training](https://github.com/PagerDuty/security-training): Public version of PagerDuty's employee security training courses.\n  - [incident-response-docs](https://github.com/PagerDuty/incident-response-docs): PagerDuty's Incident Response Documentation.\n- [global-irt](https://github.com/FIRSTdotorg/global-irt): Global IRT (Incident Response Team) is a project to describe common IRT and abuse contact information\n- [atc-react](https://github.com/atc-project/atc-react): A knowledge base of actionable Incident Response techniques\n- [Request Tracker for Incident Response](https://bestpractical.com/rtir/)\n- [Request Tracker](https://bestpractical.com/request-tracker)\n- [Beagle](https://github.com/yampelo/beagle) is an incident response and digital forensics tool which transforms security logs and data into graphs.\n- [CSIRT Schiltron: Training, Techniques, and Talent](https://www.first.org/resources/papers/conf2019/1100-CSIRT-Schiltron-Final.pdf)\n- [Practical Tabletop Drills for CSIRTS - Pre-session Material](https://www.first.org/resources/papers/conf2019/FIRST-Conference-2019-06-Edinburgh-Practical-Tabletops-for-CSIRTs.pdf)\n- [DFIRTrack](https://github.com/dfirtrack/dfirtrack): The Incident Response Tracking Application\n- [FIR](https://github.com/certsocietegenerale/FIR/) (Fast Incident Response): is an cybersecurity incident management platform designed with agility and speed in mind.\n- [Aurora Incident Response](https://github.com/cyb3rfox/Aurora-Incident-Response): Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders.\n- [timesketch](https://github.com/google/timesketch): Collaborative forensic timeline analysis.\n- [FastIR Collector Linux](https://github.com/SekoiaLab/Fastir_Collector_Linux) (no longer maintained)\n- [Critical Log Review Checklist for Security Incidents](https://zeltser.com/security-incident-log-review-checklist/)\n- [Exercise in a Box](https://www.ncsc.gov.uk/information/exercise-in-a-box)\n- [Incident response overview](https://docs.microsoft.com/en-us/security/compass/incident-response-overview)\n- [How to Write and Execute Great Incident Response Playbooks](https://www.praetorian.com/blog/writing-great-ir-playbooks/)\n- [Incident Response: Windows Cheatsheet](https://www.hackingarticles.in/incident-response-windows-cheatsheet/)\n- [Incident Response: Windows Account Logon and logon Events](https://www.hackingarticles.in/incident-response-windows-account-logon-and-logon-events/)\n- [Incident Response: Windows Account Management Event (Part 2)](https://www.hackingarticles.in/incident-response-windows-account-management-event-part-2/)\n- [Incident Response- Linux Cheatsheet](https://www.hackingarticles.in/incident-response-linux-cheatsheet/)\n- [Building Better CSIRTs Using Behavioral Psychology](https://i.blackhat.com/EU-21/Wednesday/EU-21-Orlando-Building-Better-CSIRTs-Using-Behavioral-Psychology.pdf) [link](https://www.blackhat.com/eu-21/briefings/schedule/index.html#building-better-csirts-using-behavioral-psychology-24331)\n- [The features all Incident Response Plans need to have](https://blog.talosintelligence.com/2021/11/the-features-of-incident-response-plan.html)\n- [Maltrail](https://github.com/stamparm/maltrail):  Malicious traffic detection system\n\n### Hashing\n\n- [MD5 Decryption](https://www.md5online.org/md5-decrypt.html)\n- [SHA-1 is a Shambles](https://sha-mbles.github.io/): First Chosen-Prefix Collision on SHA-1 and Application to the PGP Web of Trust\n- [Sha256 Algorithm Explained](https://sha256algorithm.com/) [code](https://github.com/dmarman/sha256algorithm)\n\n## CVEs\n\n- Some CVEs stuff and links [here](https://github.com/Spacial/csirt/blob/master/CVEsPoCs.md) and in [here](https://github.com/Spacial/csirt/tree/master/PoCs)\n- [MikroTik](https://www.shodan.io/report/Re9jsGpB) search on shodan.\n- [TROMMEL](https://github.com/CERTCC-Vulnerability-Analysis/trommel/): Sift Through Directories of Files to Identify Indicators That May Contain Vulnerabilities\n- [cve_manager](https://github.com/aatlasis/cve_manager): A python script that a) parses NIST NVD CVEs, b) prcoesses and exports them to CSV files, c) creates a postgres database and imports all the data in it, d) provides query capabilities for this CVEs database.\n- [dorkbot](https://github.com/utiso/dorkbot): Command-line tool to scan Google search results for vulnerabilities.\n- [NotQuite0DayFriday](https://github.com/grimm-co/NotQuite0DayFriday): This is a repo which documents real bugs in real software to illustrate trends, learn how to prevent or find them more quickly.\n- [Exploit Prediction Scoring System (EPSS)](https://www.first.org/epss/): The Exploit Prediction Scoring System (EPSS) is an open, data-driven effort for predicting when software vulnerabilities will be exploited. Our goal is to assist network defenders to better prioritize vulnerability remediation efforts.\n- [CVE PoC](https://github.com/trickest/cve): Almost every publicly available CVE PoC.\n\n## Malware Analysis\n\n- [Awesome Malware Analysis](https://github.com/rshipp/awesome-malware-analysis): A curated list of awesome malware analysis tools and resources.\n- Great online [course](https://malwareunicorn.org/workshops/re101.html) by [MalwareUnicorn](https://github.com/securedorg)\n- [CS6038/CS5138 Malware Analysis, UC](https://class.malware.re/): [Introduction to Malware Analysis and Reverse Engineering](https://github.com/ckane/CS7038-Malware-Analysis)\n- Some other botnets [list](https://github.com/Spacial/csirt/blob/master/botnets.md)\n- [IKARUS anti.virus and its 9 exploitable kernel vulnerabilities](http://www.greyhathacker.net/?p=995)\n- [Digital Certificates Used by Malware](http://www.ccssforum.org/malware-certificates.php)\n- [Signed Malware – The Dataset](http://signedmalware.org/)\n- [Malware Sample Sources for Researchers](https://zeltser.com/malware-sample-sources/)\n- [Indicators: Champing at the Cyberbit](https://github.com/citizenlab/malware-indicators/tree/master/201712_Cyberbit)\n- [Limon - Sandbox for Analyzing Linux Malwares](https://github.com/monnappa22/Limon)\n- [A Dynamic Binary Instrumentation framework based on LLVM](https://github.com/quarkslab/QBDI)\n- [Framework for building Windows malware, written in C++](https://github.com/richkmeli/Richkware)\n- [binary ninja](https://binary.ninja/demo/)\n- Analyzing a New macOS DNS Hijacker: [OSX/MaMi](https://objective-see.com/blog/blog_0x26.html)\n- A PoC \"malware\" application with good intentions that aims to stress your anti-malware system: [al-khaser](https://github.com/LordNoteworthy/al-khaser)\n- Great analysis of [mal100.evad.spre.rans.spyw.troj.winEXE@34/9@31/10](https://www.joesandbox.com/analysis/46216/0/html)\n- [Chaos: a Stolen Backdoor Rising Again](http://gosecure.net/2018/02/14/chaos-stolen-backdoor-rising/)\n- [Malware Indicators of Compromise (IOCs)](https://github.com/GoSecure/malware-ioc)\n- [Puszek](https://github.com/Eterna1/puszek-rootkit): Yet another LKM rootkit for Linux. It hooks syscall table.\n- [Joe Sandbox Cloud](https://github.com/joesecurity/joesandboxcloudapi) is a deep malware analysis platform which detects malicious files - API Wrapper.\n- [Cuckoo Sandbox](https://cuckoosandbox.org): Automated Malware Analysis.\n- [CBG](https://github.com/alainesp/CBG/):  Cuckoo Breeding Ground Hash Table.\n- [EternalGlue part two: A rebuilt NotPetya gets its first execution outside of the lab](https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/february/eternalglue-part-two-a-rebuilt-notpetya-gets-its-first-execution-outside-of-the-lab/)\n- [Malware web and phishing investigation](https://decentsecurity.com/#/malware-web-and-phishing-investigation/) by Decent Security.\n- [A collection of tools for working with TrickBot](https://github.com/MalwareTech/TrickBot-Toolkit)\n- [Forgot About Default Accounts? No Worries, GoScanSSH Didn’t](http://blog.talosintelligence.com/2018/03/goscanssh-analysis.html)\n- [makin](https://github.com/secrary/makin) - reveal anti-debugging and anti-VM tricks.\n- [TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and Time](https://arxiv.org/abs/1807.07838)\n- [colental/byob: BYOB (Build Your Own Botnet)](https://github.com/colental/byob), another [byob](https://github.com/malwaredllc/byob)\n- [Source Code for Exobot Android Banking Trojan Leaked Online](https://www.bleepingcomputer.com/news/security/source-code-for-exobot-android-banking-trojan-leaked-online/)\n- [Ramnit’s Network of Proxy Servers](https://research.checkpoint.com/ramnits-network-proxy-servers/)\n- [snake](https://github.com/countercept/snake): a malware storage zoo\n- [A malware analysis kit for the novice](https://www.computerweekly.com/tip/A-malware-analysis-kit-for-the-novice)\n- [malware-ioc](https://github.com/eset/malware-ioc): Indicators of Compromises (IOC) of our various investigations\n- [pftriage](https://github.com/idiom/pftriage): Python tool and library to help analyze files during malware triage and analysis.\n- [imaginaryC2](https://github.com/felixweyne/imaginaryC2#demo-use-case-simulating-trickbot-servers): Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures HTTP requests towards selectively chosen domains/IPs. Additionally, the tool aims to make it easy to replay captured Command-and-Control responses/served payloads.\n- [When a malware is more complex than the paper.](https://medium.com/@Sebdraven/when-a-malware-is-more-complex-than-the-paper-5822fc7ff257)\n- [Vba2Graph](https://github.com/MalwareCantFly/Vba2Graph): Vba2Graph - Generate call graphs from VBA code, for easier analysis of malicious documents.\n- [malwoverview](https://github.com/alexandreborges/malwoverview): Malwoverview.py is a first response tool to perform an initial and quick triage on either a directory containing malware samples or a specific malware sample.\n- SECT CTF 2018 :: [Gh0st](http://mslc.ctf.su/wp/sect-ctf-2018-gh0st/), More Smoked Leet Chicken\n- [What you need to know about “LoJax”—the new, stealthy malware from Fancy Bear](https://www.eset.com/us/about/newsroom/corporate-blog/what-you-need-to-know-about-lojax-the-new-stealthy-malware-from-fancy-bear/)\n- [Linux.Malware](https://github.com/marcusbotacin/Linux.Malware): Additional Material for the Linux Malware Paper\n- [PHP Malware Examination](https://blog.manchestergreyhats.co.uk/2018/11/07/php-malware-examination/)\n- [Analysis of Linux.Haikai](https://www.securityartwork.es/2018/11/08/analysis-of-linux-haikai-inside-the-source-code/): inside the source code\n- [Cylance vs. MBRKiller Wiper Malware](https://threatvector.cylance.com/en_us/home/cylance-vs-mbrkiller-wiper-malware.html).\n- [Deep Analysis of TrickBot New Module pwgrab](https://www.fortinet.com/blog/threat-research/deep-analysis-of-trickbot-new-module-pwgrab.html)\n- [multiscanner](https://github.com/mitre/multiscanner): Modular file scanning/analysis framework.\n- [FCL](https://github.com/chenerlich/FCL): FCL (Fileless Command Lines) - Known command lines of fileless malicious executions.\n- [Mac malware combines EmPyre backdoor and XMRig miner](https://blog.malwarebytes.com/threat-analysis/2018/12/mac-malware-combines-empyre-backdoor-and-xmrig-miner/)\n- [The Full Guide Understanding Fileless Malware Infections](https://www.peerlyst.com/posts/understanding-fileless-malware-infections-the-full-guide-andra-zaharia)\n- ['Injection' Without Injection](https://secrary.com/Random/injectionwithoutinjection/)\n- [Analysis of Neutrino Bot Sample](http://www.peppermalware.com/2019/01/analysis-of-neutrino-bot-sample-2018-08-27.html) (dated 2018-08-27): In this post I analyze a Neutrino Bot sample.\n- [pafish](https://github.com/a0rtega/pafish): Pafish is a demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as malware families do.\n- [Thunderstrike2 details](https://trmm.net/Thunderstrike2_details): This is the annotated transcript of our DefCon 23 / BlackHat 2015 talk, which presented the full details of Thunderstrike 2, the first firmware worm for Apple's Macs that can spread via both software or Thunderbolt hardware accessories and writes itself to the boot flash on the system's motherboard.\n- [Malboxes](https://gosecure.net/2017/02/16/introducing-malboxes-a-tool-to-build-malware-analysis-virtual-machines/): a Tool to Build Malware Analysis Virtual Machines, [github](https://github.com/GoSecure/malboxes)\n- [Triton is the world’s most murderous malware, and it’s spreading](https://www.technologyreview.com/s/613054/cybersecurity-critical-infrastructure-triton-malware/)\n- [Cloak and Dagger — Mobile Malware Techniques Demystified](https://medium.com/@targetpractice/cloak-and-dagger-malware-techniques-demystified-c4d8a035b94e)\n- [IceBox](https://github.com/thalium/icebox): Icebox is a Virtual Machine Introspection solution that enable you to stealthily trace and debug any process (kernel or user). It's based on project Winbagility.\n- Malware Development:\n  - [Welcome to the Dark Side: Part 1](https://niiconsulting.com/checkmate/2018/02/malware-development-welcome-dark-side-part-1/)\n  - [Welcome to the Dark Side: Part 2-1](https://niiconsulting.com/checkmate/2018/02/malware-development-welcome-dark-side-part-2-1/)\n  - [Welcome to the Dark Side: Part 2-2](https://niiconsulting.com/checkmate/2018/03/malware-development-welcome-dark-side-part-2-2/)\n  - [Welcome to the Dark Side: Part 3](https://niiconsulting.com/checkmate/2018/03/malware-development-welcome-dark-side-part-3/)\n  - [Welcome to the Dark Side: Part 4](https://niiconsulting.com/checkmate/2018/03/malware-development-welcome-to-the-dark-side-part-4/)\n- [Command and Control via TCP Handshake](https://thesw4rm.gitlab.io/nfqueue_c2/2019/09/15/Command-and-Control-via-TCP-Handshake/)\n- Joel Sandbox Analysis Report [wdeQEksXgm](https://www.joesecurity.org/reports/report-78d97c9b50029da32ada8e16e1979b28.html)\n- [emotet](https://www.bleepingcomputer.com/news/security/emotet-revived-with-large-spam-campaigns-around-the-world/): [Daily Emotet IoCs and Notes for 09/18/19](https://paste.cryptolaemus.com/emotet/2019/09/18/emotet-malware-IoCs_09-18-19.html)\n- [Aleph](https://github.com/merces/aleph): OpenSource /Malware Analysis Pipeline System\n- [Aleph](https://github.com/alephre/aleph): File Analysis Pipeline\n- [Anti-VM Technique with MSAcpi_ThermalZoneTemperature](https://medium.com/@DebugActiveProcess/anti-vm-techniques-with-msacpi-thermalzonetemperature-32cfeecda802), [powershell](https://gist.github.com/teixeira0xfffff/36293713c254c69a7ba2353e8d64afce)\n- [AMSI as a Service](https://medium.com/@two06/amsi-as-a-service-automating-av-evasion-2e2f54397ff9) — Automating AV Evasion: AMSI, the “AntiMalware Scan Interface”, has been around for some time. In a broad sense, it’s a component of Windows 10 which allows applications to integrate with AV products, though most people know it for it’s ability to make file-less malware visible to AV engines.\n- [A collection of x64dbg scripts](https://github.com/x64dbg/Scripts). Feel free to submit a pull request to add your script.\n- [CAPA](https://github.com/fireeye/capa/): The FLARE team's open-source tool to identify capabilities in executable files. [capa-rules](https://github.com/fireeye/capa-rules)\n- [DRAKVUF Sandbox](https://github.com/CERT-Polska/drakvuf-sandbox) - automated hypervisor-level malware analysis system.\n- [Unprotect](https://medium.com/@tom_rock/unprotect-project-5f80a88d9bdd): The [search engine](https://search.unprotect.it/map) about Malware Evasion Techniques\n- [HiJackThis Fork v3](https://github.com/dragokas/hijackthis): A free utility that finds malware, adware and other security threats.\n- [FRITZFROG](https://www.guardicore.com/2020/08/fritzfrog-p2p-botnet-infects-ssh-servers/): A NEW GENERATION OF PEER-TO-PEER BOTNETS. [detection script](https://github.com/guardicore/labs_campaigns/tree/master/FritzFrog)\n- [Tracking A Malware Campaign Through VT](https://isc.sans.edu/forums/diary/Tracking+A+Malware+Campaign+Through+VT/26498/)\n- [speakeasy](https://github.com/fireeye/speakeasy): Windows kernel and user mode emulation.\n- [malware analysis and machine learning](https://twitter.com/alg0phelia/status/1303058786446385153) [If you are new to machine learning and want to start learning about building models to classify malware, I recommend the following](https://twitter.com/alg0phelia/status/1302281270496497664)\n- [GhostDNSbusters](https://team-cymru.com/blog/2020/09/08/ghostdnsbusters/): Illuminating GhostDNS Infrastructure\n- [The Tetrade](https://securelist.com/the-tetrade-brazilian-banking-malware/97779/): Brazilian banking malware goes global\n- [Is macOS under the biggest malware attack ever?](https://reverse.put.as/2020/09/17/evilquest-revisited/): EvilQuest/ThiefQuest malware.\n- [Hybrid Analysis](https://www.hybrid-analysis.com/)\n- Evading Static Machine Learning Malware Detection Models – [Part 1: The Black-Box Approach](https://blog.compass-security.com/2020/10/evading-static-machine-learning-malware-detection-models-the-black-box-approach/)\n- [ember](https://github.com/endgameinc/ember): The EMBER dataset is a collection of features from PE files that serve as a benchmark dataset for researchers.\n- [Complementar resources to follow the EHREM course by GoHacking (Malware Reverse Engineering)](https://github.com/nuxmorpheus/EHREM/)\n- [Coldfire](https://github.com/redcode-labs/Coldfire): Golang malware development library\n- [pei](https://github.com/Silva97/pei), the PE Injector - Inject code on 32-bit and 64-bit PE executables\n- [The Art Of Mac Malware: Analysis](https://taomm.org/vol1/analysis.html)\n- [Freki](https://github.com/crhenr/freki): ￼ Malware analysis platform\n- [Ten process injection techniques: A technical survey of common and trending process injection techniques](https://www.elastic.co/pt/blog/ten-process-injection-techniques-technical-survey-common-and-trending-process)\n- [Sandbox detection and evasion techniques. How malware has evolved over the last 10 years](https://www.ptsecurity.com/ww-en/analytics/antisandbox-techniques/)\n- [malware_training_vol1](https://github.com/hasherezade/malware_training_vol1): Materials for Windows Malware Analysis training (volume 1).\n- [Go Assembly on the arm64](https://www.symbolcrash.com/2021/03/02/go-assembly-on-the-arm64/)\n- [Exploit Kit still sharpens a sword](https://nao-sec.org/2021/04/exploit-kit-still-sharpens-a-sword.html)\n- [Pingback](https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel/): Backdoor At The End Of The ICMP Tunnel.\n- [WinAPI-Tricks](https://github.com/vxunderground/WinAPI-Tricks): Collection of various WINAPI tricks / features used or abused by Malware.\n- [pyWhat](https://github.com/bee-san/pyWhat): Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is!\n- [Transacted Hollowing](https://github.com/hasherezade/transacted_hollowing): a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging.\n- [Cuckoo Sandbox Overview](https://www.varonis.com/blog/cuckoo-sandbox/)\n- [Malvuln](https://www.malvuln.com/): Finding and exploiting vulnerable Malware.\n- [Machine Learning for Static Malware Analysis, with University College London](https://research.nccgroup.com/2021/06/07/research-paper-machine-learning-for-static-malware-analysis-with-university-college-london/)\n- [Malware Scarecrow](https://github.com/kaganisildak/malwarescarecrow)\n- [Vigilante malware rats out software pirates while blocking ThePirateBay](https://news.sophos.com/en-us/2021/06/17/vigilante-antipiracy-malware/). [twitter thread](https://twitter.com/SophosLabs/status/1405548622725459970)\n- [Necro Python bot adds new exploits and Tezos mining to its bag of tricks](https://blog.talosintelligence.com/2021/06/necro-python-bot-adds-new-tricks.html)\n- [Too Log; Didn't Read — Unknown Actor Using CLFS Log Files for Stealth](https://www.fireeye.com/blog/threat-research/2021/09/unknown-actor-using-clfs-log-files-for-stealth.html): The Mandiant Advanced Practices team recently discovered a new malware family we have named PRIVATELOG and its installer, STASHLOG.\n- [Made in China: OSX.ZuRu](https://objective-see.com/blog/blog_0x66.html): trojanized apps spread malware, via sponsored search results\n- [DBatLoader: Abusing Discord to Deliver Warzone RAT](https://www.netskope.com/blog/dbatloader-abusing-discord-to-deliver-warzone-rat)\n- [Siloscape](https://unit42.paloaltonetworks.com/siloscape/): First Known Malware Targeting Windows Containers to Compromise Cloud Environments\n- [DRIDEX](https://www.0ffset.net/reverse-engineering/malware-analysis/dridex-veh-api-obfuscation/): Analysing API Obfuscation Through VEH\n- [The Return of the Malwarebytes Crackme](https://matth.dmz42.org/posts/2021/the-return-of-the-malwarebytes-crackme/), [Malwarebytes Crackme 2021](https://github.com/JLeow00/malwarebytes-crackme-3): Writeup and scripts for the 2021 malwarebytes crackme. [Malwarebytes CrackMe 3 2021 Solution](https://rainbowpigeon.me/posts/malwarebytes-crackme-3-2021/)\n- [Corvus](https://corvus.inf.ufpr.br/): is a dynamic analysis system for malware targeting Windows, Linux, Android and PDFs. Behavioral heuristics are also applied to identify suspicious activities exhibited by unknown programs. [API](https://corvus.inf.ufpr.br/docs/api.html)\n- [MalAPI.io](https://malapi.io/) maps Windows APIs to common techniques used by malware.\n- [Malicious Document Analysis: Example 1](https://exploitreversing.com/2021/11/02/malicious-document-analysis-example-1/) [mda](https://exploitreversing.files.wordpress.com/2021/11/mda_1-1.pdf)\n- [APIVADS](https://ieeexplore.ieee.org/document/9690881): A Novel Privacy-Preserving Pivot Attack Detection Scheme Based On Statistical Pattern Recognition\n- [A new secret stash for “fileless” malware](https://securelist.com/a-new-secret-stash-for-fileless-malware/106393/)\n- [Qu1cksc0pe](https://github.com/CYB3RMX/Qu1cksc0pe):  All-in-One malware analysis tool.\n\n### Web Malwares\n\n- [Boa release](https://boa-dev.github.io/) is an experimental Javascript lexer, parser and compiler written in Rust.\n- [midrashim](https://github.com/guitmz/midrashim): x64 ELF infector written in Assembly\n- [d0zer](https://github.com/sad0p/d0zer): Elf binary infector written in Go.\n- [New evasion techniques found in web skimmers](https://blog.malwarebytes.com/threat-analysis/2019/12/new-evasion-techniques-found-in-web-skimmers/)\n- [digital skimming / #magecart technique for injecting convincing PayPal iframes into the checkout process](https://twitter.com/AffableKraut/status/1333258498910588928). [paypal endpoint called via cors-anywhere](https://gist.github.com/krautface/e9fece3a3271bc19bd198a72fa8f363e), [stega-loader](https://gist.github.com/krautface/47144708de5ebf78713db10bb486ea87), [paypal-cors-deob-good.js](https://gist.github.com/krautface/dee181bec40b8e99e21fc932d9922df2), [paypal-cors-deob-with-comments.js](https://gist.github.com/krautface/933b050eb363e20cf1bc925c87a9290f), [fake-paypal.html](https://gist.github.com/krautface/243aabc63f6f7424ff75e8e9cbd35016)\n\n### Malware Samples\n\n- [Automated Malware Analysis Report for D6pnpvG2z7](https://www.joesecurity.org/reports/report-source-fffb8d51838af6bb742e84b8b16239bb.html) - Generated by Joe Sandbox\n- [Mac Malware](https://objective-see.com/malware.html)\n- [virii](https://github.com/guitmz/virii): Collection of ancient computer virus source codes\n- [Detricking TrickBot Loader](https://www.cert.pl/en/news/single/detricking-trickbot-loader/): TrickBot (TrickLoader) is a modular financial malware that first surfaced in October in 20161. Almost immediately researchers have noticed similarities with a credential-stealer called Dyre. It is still believed that those two families might’ve been developed by the same actor. [decoder](https://raw.githubusercontent.com/k-vitali/Malware-Misc-RE/master/2019-07-29-trickbot-decoded-first-loader-template.vk.raw), [tweet](https://twitter.com/VK_Intel/status/1155923795674316801)\n- [Analysis of Emotet v4](https://www.cert.pl/en/news/single/analysis-of-emotet-v4/)\n- [abuse.ch Feodo Tracker Botnet C2 IP Blocklist](https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt)\n- [simple_ransomware](https://github.com/bing0o/simple_ransomware): this script isn't ransomware, it's just script collect all your system files and encrypt it, Can be considered it a simple ransomware\n- [Mirai \"Batkek\"](https://gist.github.com/unixfreaxjp/2bc9100d167992a768642777d850e1c0)\n- [FinFisher Filleted 🐟](https://objective-see.com/blog/blog_0x4F.html), a triage of the FinSpy (macOS) malware\n- [Ryuk’s Return](https://thedfirreport.com/2020/10/08/ryuks-return/)\n- [Ryuk Ransomware](https://community.riskiq.com/article/0bcefe76): Extensive Attack Infrastructure Revealed\n- [Collaboration between FIN7 and the RYUK group, a Truesec Investigation](https://blog.truesec.com/2020/12/22/collaboration-between-fin7-and-the-ryuk-group-a-truesec-investigation/)\n- [Android-Malware-Samples](https://github.com/fouroctets/Android-Malware-Samples):  Android Malware Samples\n- [Architecture of a ransomware](https://medium.com/bugbountywriteup/architecture-of-a-ransomware-1-2-1b9fee757fcb)\n- [TRAFFIC ANALYSIS EXERCISE - OMEGACAST](https://malware-traffic-analysis.net/2020/10/22/index.html)\n- [Malware Samples](https://github.com/jstrosch/malware-samples): Malware samples and other artifacts\n- [After finding skimmers in SVG files last week, we now discovered a #magecart skimmer in perfectly valid CSS.](https://twitter.com/sansecio/status/1336614850047381506)\n- [#Buer #BuerLoader](https://twitter.com/ffforward/status/1338876857647849473)\n- [SoReL-20M](https://github.com/sophos-ai/SOREL-20M): Sophos-ReversingLabs 20 million sample dataset.\n- [minizinh0-FUD](https://github.com/gnxbr/Fully-Undetectable-Techniques/): A Fully Undetectable Ransomware.\n- [Purple Fox Rootkit Now Propagates as a Worm](https://www.guardicore.com/labs/purple-fox-rootkit-now-propagates-as-a-worm/)\n- [How to analyze mobile malware: a Cabassous/FluBot Case study](https://blog.nviso.eu/2021/04/19/how-to-analyze-mobile-malware-a-cabassous-flubot-case-study/)\n- [Malware Analysis of a Password Stealer](https://www.youtube.com/watch?v=MaPXDCq-Gf4): n this video we dive into the analysis of Poulight malware, which is a .net based password stealer.\n- [Guildma](https://isc.sans.edu/forums/diary/Guildma+is+now+using+Finger+and+Signed+Binary+Proxy+Execution+to+evade+defenses/27482/)\n- [Darkside RaaS in Linux version](https://cybersecurity.att.com/blogs/labs-research/darkside-raas-in-linux-version)\n\n### Repos\n\n- [A repository of LIVE malwares for your own joy and pleasure](https://github.com/ytisf/theZoo): [theZoo](http://thezoo.morirt.com)\n- [malware.one](https://malware.one/index.php) is a binary substring searchable malware catalog containing terabytes of malicious code.\n- [Beginner Malware Reversing Challenges](https://www.malwaretech.com/beginner-malware-reversing-challenges), by MalwareTech. [repo](https://github.com/MalwareTech/Beginner-Reversing-Challenges)\n- [MalwareWorld](https://malwareworld.com/): Check for Suspicious Domains and IPs. Repo: [MalwareWorld](https://github.com/carlospolop/MalwareWorld): System based on +500 blacklists and 5 external intelligences to detect internet potencially malicious hosts\n- [C2Matrix](https://www.thec2matrix.com/): The goal of this site is to point you to the best C2 framework for your needs based on your adversary emulation plan and the target environment\n- [LOLBITS](https://github.com/Kudaes/LOLBITS): C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + Dinvoke for EDR user-mode hooking evasion.\n- [MalwareBazaar](https://bazaar.abuse.ch/): is a project from abuse.ch with the goal of sharing malware samples with the infosec community, AV vendors and threat intelligence providers.\n- [What is MWDB Core?](https://www.cert.pl/en/news/single/set-up-your-own-malware-repository-with-mwdb-core/) [mwdb-core](https://github.com/CERT-Polska/mwdb-core): Malware repository component for samples \u0026 static configuration with REST API interface.\n- [Malpedia](https://malpedia.caad.fkie.fraunhofer.de/): The primary goal of Malpedia is to provide a resource for rapid identification and actionable context when investigating malware. Openness to curated contributions shall ensure an accountable level of quality in order to foster meaningful and reproducible research.\n\n### Ransomwares\n\n- [Ransomware decryption tool](https://github.com/newsoft/envoye-special-decryptor)\n- [Schroedinger’s Pet(ya)](https://securelist.com/schroedingers-petya/78870/)\n- [Player 3 Has Entered the Game: Say Hello to 'WannaCry'](http://blog.talosintelligence.com/2017/05/wannacry.html)\n- [WannaCry|WannaDecrypt0r NSA-Cyberweapon-Powered Ransomware Worm](https://gist.github.com/rain-1/989428fa5504f378b993ee6efbc0b168)\n- [Ransomware Overview](https://docs.google.com/spreadsheets/d/1TWS238xacAto-fLKh1n5uTsdijWdCEsGIM0Y0Hvmc5g/pubhtml#)\n- [Analyzing GrandSoft Exploit Kit](http://www.nao-sec.org/2018/02/analyzing-grandsoft-exploit-kit.html) and [code](https://gist.github.com/anonymous/089810f4581b86edf27827a0a4ebeff4)\n- [Rapidly Evolving Ransomware GandCrab Version 5 Partners With Crypter Service for Obfuscation](https://securingtomorrow.mcafee.com/mcafee-labs/rapidly-evolving-ransomware-gandcrab-version-5-partners-with-crypter-service-for-obfuscation/)\n- [hidden-tear](https://github.com/goliate/hidden-tear): It's a ransomware-like file crypter sample which can be modified for specific purposes.\n- [Tracking REvil](https://www.kpn.com/security-blogs/Tracking-REvil.htm): This blog describes our efforts in tracking the REvil ransomware and its affiliates for the past six months. REvil has been around since 2019 and is one of the top variants of ransomware causing havoc at many organizations around the globe ever since. The KPN Security Research Team was able to acquire C2 sinkholes allowing for the tracking of infections across the globe.\n- [Sodinokibi (aka REvil) Ransomware](https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/). [Sodinokibi (aka REvil) Ransomware](https://twitter.com/TheDFIRReport/status/1376481762935767040)\n- [REvil Master Key for Kaseya Attack Posted to XSS](https://www.flashpoint-intel.com/blog/possible-universal-revil-master-key-posted-to-xss/)\n- [After the ransom was paid, the attackers even provided some bonus security advice!](https://twitter.com/jc_stubbs/status/1289200557794553857/photo/1)\n- [Phirautee](https://github.com/Viralmaniar/Phirautee): A proof of concept crypto virus to spread user awareness about attacks and implications of ransomwares. Phirautee is written purely using PowerShell and does not require any third-party libraries. This tool steals the information, holds an organisation’s data to hostage for payments or permanently encrypts/deletes the organisation data.\n- [Sophisticated new Android malware marks the latest evolution of mobile ransomware](https://www.microsoft.com/security/blog/2020/10/08/sophisticated-new-android-malware-marks-the-latest-evolution-of-mobile-ransomware/)\n- [Raccine](https://github.com/Neo23x0/Raccine): A Simple Ransomware Vaccine\n- [Genetic Analysis of CryptoWall Ransomware](https://ryancor.medium.com/genetic-analysis-of-cryptowall-ransomware-843f86055c7f)\n- [Brazilian Justice Court Ransomware: Another piece in the Puzzle](https://secret.inf.ufpr.br/2020/11/17/brazilian-justice-court-ransomware-another-piece-in-the-puzzle/)\n- [A Ransomware has landed! @Embraer](https://secret.inf.ufpr.br/2020/12/15/a-ransomware-has-landed-embraer/) by SECRET\n- [RANSOMWARE GUIDANCE AND RESOURCES](https://www.cisa.gov/ransomware)\n- [No More Ransom!](https://www.nomoreransom.org/en/index.html)\n- [PYSA/Mespinoza Ransomware](https://thedfirreport.com/2020/11/23/pysa-mespinoza-ransomware/)\n- [PYSA Ransomware](https://cyberflorida.org/threat-advisory/pysa-ransomware/)\n- [Mespinoza Analysis — New ransomware variant targets France](https://sapphirex00.medium.com/mespinoza-analysis-new-ransomware-variant-targets-france-d4f82cbee86c)\n- [Some #PYSA / #Mespinoza #Ransomware Samples](https://twitter.com/JAMESWT_MHT/status/1380016670622818309)\n- [Cerber Ransomware](https://twitter.com/dimitribest/status/1376877563214143497)\n- [RansomEXX Trojan attacks Linux systems](https://securelist.com/ransomexx-trojan-attacks-linux-systems/99279/)\n- [FIN7 - Lizar client Interface version 2.0.4](https://m.habr.com/ru/company/bizone/blog/553136/) [tweet](https://twitter.com/CryptoInsane/status/1385019649461477380)\n- [Introducing COLT – Compromise to Leak Time](https://vulnerability.ch/2021/05/colt-compromise-to-leak-time/)\n- [RANSOM MAFIA.ANALYSIS OF THE WORLD’S FIRST RANSOMWARE CARTEL](https://analyst1.com/file-assets/RANSOM-MAFIA-ANALYSIS-OF-THE-WORLD%E2%80%99S-FIRST-RANSOMWARE-CARTEL.pdf)\n- [Sleuthing DarkSide Crypto-Ransom Payments with the Wolfram Language](https://blog.wolfram.com/2021/05/25/sleuthing-darkside-crypto-ransom-payments-with-the-wolfram-language/)\n- [Apostle Ransomware Analysis](https://cyberpunkleigh.wordpress.com/2021/05/27/apostle-ransomware-analysis/)\n- [From Wiper to Ransomware | The Evolution of Agrius](https://labs.sentinelone.com/from-wiper-to-ransomware-the-evolution-of-agrius/)\n- [Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise](https://www.fireeye.com/blog/threat-research/2021/06/darkside-affiliate-supply-chain-software-compromise.html)\n- [Hades Ransomware Operators Use Distinctive Tactics and Infrastructure](https://www.secureworks.com/blog/hades-ransomware-operators-use-distinctive-tactics-and-infrastructure)\n- [Miscellaneous Malware RE](https://github.com/k-vitali/Malware-Misc-RE)\n- [BlackMatter x64 Linux Variant | esxcli variant](https://twitter.com/VK_Intel/status/1423188690126266370), [blackmatter functions](https://github.com/k-vitali/Malware-Misc-RE/blob/master/2021-08-05-blackmatter-ransom-linux-esxcli-func-vk.raww)\n- [Teaching an Old Dog New Tricks: 2017 Magniber Ransomware Uses PrintNightmare Vulnerability to Infect Victims in South Korea](https://www.crowdstrike.com/blog/magniber-ransomware-caught-using-printnightmare-vulnerability/)\n- [RansomExx Renner](https://otx.alienvault.com/pulse/611ecd98c0e17d68bf061a06/)\n- [RANSOMWHERE](https://ransomwhe.re/): Total tracked ransomware payments all time. Ransomwhere is the open, crowdsourced ransomware payment tracker. Browse and download ransomware payment data or help build our dataset by reporting ransomware demands you have received.\n- [BlackByteDecryptor](https://github.com/SpiderLabs/BlackByteDecryptor): This is a decryptor for the ransomware BlackByte.\n- [Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus](https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html): We investigate mhyprot2.sys, a vulnerable anti-cheat driver for the popular role-playing game Genshin Impact. The driver is currently being abused by a ransomware actor to kill antivirus processes and services for mass-deploying ransomware.\n\n### Virus/Anti-Virus\n\n- [Avast open-sources its machine-code decompiler](https://blog.avast.com/avast-open-sources-its-machine-code-decompiler)\n- [Morris worm](https://github.com/arialdomartini/morris-worm)\n- [make a process unkillable?!](https://secrary.com/Random/UnKillable/) (windows 10)\n- [Attack inception](https://cloudblogs.microsoft.com/microsoftsecure/2018/07/26/attack-inception-compromised-supply-chain-within-a-supply-chain-poses-new-risks/): Compromised supply chain within a supply chain poses new risks – Microsoft Secure.\n- [Curtis' Blog: Bypassing Next Gen AV During a Pentest](https://curtbraz.blogspot.com/2018/08/bypassing-next-gen-av-during-pentest.html)\n- [Inception](https://github.com/two06/Inception/): Provides In-memory compilation and reflective loading of C# apps for AV evasion.\n- [Invoke-NeutralizeAV](https://github.com/curtbraz/Invoke-NeutralizeAV): Quick PoC I Wrote for Bypassing Next Gen AV Remotely for Pentesting.\n- [BinariesThatDoesOtherStuff](https://gist.github.com/api0cradle/8cdc53e2a80de079709d28a2d96458c2#file-binariesthatdoesotherstuff-txt).\n- [Circlean](https://github.com/CIRCL/Circlean): USB key cleaner.\n- [The ELF Virus Writing HOWTO](http://www.linuxsecurity.com/resource_files/documentation/virus-writing-HOWTO/_html/index.html).\n- [mcreator](https://github.com/blacknbunny/mcreator): Encoded Reverse Shell Generator With Techniques To Bypass AV's.\n- [metame](https://github.com/a0rtega/metame): is a simple metamorphic code engine for [arbitrary executables](https://www.kitploit.com/2019/09/metame-metame-is-metamorphic-code.html).\n- [rustdsplit](https://github.com/epi052/rustdsplit): At some point, I learned about a method to perform a binary search on a file in order to identify its AV signature and change it to bypass signature-based AV. The tool I used back then is gone, so I wrote this.\n- [Virus Total API in Python](https://github.com/fr0gger/yeti/blob/master/plugins/feeds/public/virustotal_apiv3.py)\n- [VirusTotal CLI](https://github.com/VirusTotal/vt-cli)\n- [rustdsplit](https://github.com/epi052/rustdsplit): At some point, I learned about a method to perform a binary search on a file in order to identify its AV signature and change it to bypass signature-based AV. The tool I used back then is gone, so I wrote this.\n- [Antivirus Event Analysis Cheat Sheet v1.7.2](https://www.nextron-systems.com/2019/10/04/antivirus-event-analysis-cheat-sheet-v1-7-2/)\n- [UglyEXe](https://medium.com/@markmotig/uglyexe-bypass-some-avs-4a10313277aa): [bypass some AVs](https://github.com/fashionproof/UglyEXe)\n- [How to bypass Defender in a few easy steps](https://arty-hlr.com/blog/2021/05/06/how-to-bypass-defender/)\n- [Engineering antivirus evasion](https://blog.scrt.ch/2020/06/19/engineering-antivirus-evasion/)\n- [avcleaner](https://github.com/scrt/avcleaner): C/C++ source obfuscator for antivirus bypass\n- [An Empirical Assessment of Endpoint Security Systems Against Advanced Persistent Threats Attack Vectors](https://papers.vx-underground.org/papers/VXUG/Mirrors/APT_assessment_v3_FINAL.pdf)\n- [VxSig](https://github.com/google/vxsig): Automatically generate AV byte signatures from sets of similar binaries.\n\n### Trojans/Loggers\n\n- [IcedID Banking Trojan Shares Code with Pony 2.0 Trojan](http://www.intezer.com/icedid-banking-trojan-shares-code-pony-2-0-trojan/)\n- [Turla](https://www.welivesecurity.com/2018/08/22/turla-unique-outlook-backdoor/): In and out of its unique Outlook backdoor\n- [QMKhuehuebr](https://github.com/mthbernardes/QMKhuehuebr): Trying to hack into keyboards\n\n### Malware Articles and Sources\n\n- [“VANILLA” malware](https://link.springer.com/article/10.1007/s11416-019-00333-y): vanishing antiviruses by interleaving layers and layers of attacks\n- [A Mix of Python \u0026 VBA in a Malicious Word Document](https://isc.sans.edu/forums/diary/A+Mix+of+Python+VBA+in+a+Malicious+Word+Document/26578/)\n- [MalwareAnalysisForHedgehogs](https://www.youtube.com/c/MalwareAnalysisForHedgehogs/videos): Throw your bat cape over your spikes and get started with malware analysis and reverse engineering.\nI work as a malware analyst and like to share my knowledge.\n- [2020-10-22 - TRAFFIC ANALYSIS EXERCISE - OMEGACAST](https://malware-traffic-analysis.net/2020/10/22/index.html)\n- [EMOTET](https://www.malware-traffic-analysis.net/2018/07/20/index.html): EMOTET INFECTIONS WITH ZEUS PANDA BANKER AND TRICKBOT (GTAG: DEL34)\n- [A MIPS-32 ELF non-resident virus with false disassembly](https://vx-underground.org/papers/VXUG/Exclusive/Bakounin/Linux.Bak0unin.asm), Made with love by S01den (@s01den)\n- [Linux.Kropotkine.asm](https://github.com/vxunderground/MalwareSourceCode/blob/8ce86aa641299d8cfa13ce801bcb6a6b292d6f9b/VXUG/Linux.Kropotkine.asm)\n- [A WILD KOBALOS APPEARS](https://www.welivesecurity.com/wp-content/uploads/2021/01/ESET_Kobalos.pdf), Tricksy Linux malware goes after HPCs. [kobalos iocs](https://github.com/eset/malware-ioc/tree/master/kobalos)\n- [List of victim organizations attacked by Ransomware gangs released on the DarkWeb](https://drive.google.com/file/d/1MI8Z2tBhmqQ5X8Wf_ozv3dVjz5sJOs-3/view?usp=sharing)\n\n## Reverse Engineering\n\n- (pt-br) [Fundamentos de Engenharia Reversa](https://mentebinaria.gitbook.io/engenharia-reversa/)\n- [Reverse Engineer's Toolkit](https://github.com/mentebinaria/retoolkit)\n- [Dangers of the Decompiler](https://blog.ret2.io/2017/11/16/dangers-of-the-decompiler/)\n- [RE guide for beginners: Methodology and tools](https://0x00sec.org/t/re-guide-for-beginners-methodology-and-tools/2242)\n- [REDasm](https://github.com/REDasmOrg/REDasm): Crossplatform, interactive, multiarchitecture disassembler\n- [Reversing ARM Binaries](https://zygosec.com/post1.html)\n- [Programmer De-anonymization from Binary Executables](https://github.com/calaylin/bda)\n- [Reverse engineering WhatsApp Web](https://github.com/sigalor/whatsapp-web-reveng)\n- [BOLO: Reverse Engineering — Part 1 (Basic Programming Concepts)](https://medium.com/bugbountywriteup/bolo-reverse-engineering-part-1-basic-programming-concepts-f88b233c63b7)\n- [BOLO: Reverse Engineering — Part 2 (Advanced Programming Concepts)](https://medium.com/@danielabloom/bolo-reverse-engineering-part-2-advanced-programming-concepts-b4e292b2f3e)\n- [Reverse Engineering for Beginners](https://www.begin.re)\n- [VivienneVMM](https://github.com/changeofpace/VivienneVMM): VivienneVMM is a stealthy debugging framework implemented via an Intel VT-x hypervisor.\n- [Xori](https://github.com/endgameinc/xori): Custom disassembly framework\n- [rattle](https://github.com/trailofbits/rattle): Rattle is an EVM binary static analysis framework designed to work on deployed smart contracts.\n- [starshipraider](https://github.com/azonenberg/starshipraider): High performance embedded systems debug/reverse engineering platform\n- [GBA-IDA-Pseudo-Terminal](https://github.com/LanHikari22/GBA-IDA-Pseudo-Terminal): IDAPython tools to aid with analysis, disassembly and data extraction using IDA python commands, tailored for the GBA architecture at some parts\n- [binja-ipython](https://github.com/ernw/binja-ipython): A plugin to integrate an IPython kernel into Binary Ninja.\n- [PySameSame](https://github.com/DissectMalware/PySameSame): This is a python version of samesame repo to generate homograph strings\n- [Reversing a Japanese Wireless SD Card From Zero to Code Execution](https://docs.google.com/presentation/d/13OJNOb2IMwp79SDrbxSLF3i7StTgWLdD7QlYpic39r8/edit#slide=id.g3d28bb72e8_5_74)\n- [Practical-Reverse-Engineering-using-Radare2](https://github.com/s4n7h0/Practical-Reverse-Engineering-using-Radare2): Training Materials of Practical Reverse Engineering using Radare2\n- [Reverse engineering Go binaries using Radare 2 and Python](https://carvesystems.com/news/reverse-engineering-go-binaries-using-radare-2-and-python/)\n- [r2pipe for V](https://github.com/radare/v-r2pipe): r2pipe for V.\n- [radare2-webui](https://github.com/radareorg/radare2-webui): webui repository for radare2.\n- IDA Pro:\n  - [idaemu](https://github.com/36hours/idaemu): idaemu is an IDA Pro Plugin - use for emulating code in IDA Pro.\n  - [lighthouse](https://github.com/gaasedelen/lighthouse): Code Coverage Explorer for IDA Pro \u0026 Binary Ninja\n  - [IDAPro Cheat Sheet](https://malwareunicorn.org/workshops/idacheatsheet.html)\n  - [Lumen](https://github.com/naim94a/lumen): A private Lumina server for IDA Pro\n  - [EFISwissKnife](https://github.com/gdbinit/EFISwissKnife): An IDA plugin to improve (U)EFI reversing.\n  - [IDA Python](https://medium.com/malware-buddy/reverse-engineering-tips-ida-python-bd0ce64a48ed)\n  - [Tenet](https://github.com/gaasedelen/tenet): [A Trace Explorer for Reverse Engineers](https://blog.ret2.io/2021/04/20/tenet-trace-explorer/).\n  - [TLS callbacks](https://hex-rays.com/blog/tls-callbacks/)\n  - [rename gamemaker handlers](https://github.com/ioncodes/ida_scripts/blob/main/rename_gamemaker_handlers.py)\n- GDB:\n  - [pwndbg](https://github.com/pwndbg/pwndbg): Exploit Development and Reverse Engineering with GDB Made Easy  \n  - [PEDA](https://github.com/longld/peda): Python Exploit Development Assistance for GDB.\n  - [about gef](https://www.offensivethink.com/about-gef.html). [gef](https://github.com/hugsy/gef): GDB Enhanced Features for exploit devs \u0026 reversers.\n  - [some things about gef](https://www.offensivethink.com/about-gef.html)\n  - [Controlling GDB](https://sourceware.org/gdb/current/onlinedocs/gdb/Controlling-GDB.html)\n  - [Low Level Visualization via Debuggers](https://www.vinnie.work/blog/2021-01-08-low-level-debuggers/)\n  - [Faster GDB Startup](https://tromey.com/blog/?p=1084)\n  - [GDB Tutorial for Reverse Engineers](https://slava-moskvin.medium.com/gdb-tutorial-for-reverse-engineers-breakpoints-modifying-memory-and-printing-its-contents-46280ac37aad): Breakpoints, Modifying Memory and Printing its Contents.  \n- Frida:\n  - [Getting Started with Frida Tools](https://medium.com/@int0x33/day-19-getting-started-with-frida-tools-3aeb2f0063c3)\n  - Frida hooking android :[part 1](https://11x256.github.io/Frida-hooking-android-part-1/), [part 2](https://11x256.github.io/Frida-hooking-android-part-2/), [part 3](https://11x256.github.io/Frida-hooking-android-part-3/), [part 4](https://11x256.github.io/Frida-hooking-android-part-4/) and [part 5](https://11x256.github.io/Frida-hooking-android-part-5/)\n  - [fridump3](https://github.com/rootbsd/fridump3): A universal memory dumper using Frida for Python 3.\n  - [r2flutch](https://github.com/as0ler/r2flutch): Tool to decrypt iOS apps using r2frida.\n- Immunity:\n  - [Immunity Debugger](https://www.immunityinc.com/products/debugger/)\n  - [mona](https://www.corelan.be/index.php/2011/07/14/mona-py-the-manual/) site. [mona](https://github.com/corelan/mona): is a python script that can be used to automate and speed up specific searches while developing exploits (typically for the Windows platform). It runs on Immunity Debugger and WinDBG, and requires python 2.7. Although it runs in WinDBG x64, the majority of its features were written specifically for 32bit processes.\n- WinDBG:\n  - [WinDbg-Samples](https://github.com/Microsoft/WinDbg-Samples): Sample extensions, scripts, and API uses for WinDbg.\n  - [windbglib](https://github.com/corelan/windbglib): Public repository for windbglib, a wrapper around pykd.pyd (for Windbg), used by mona.py\n- [LIEF](https://lief.quarkslab.com/): Library to Instrument Executable Formats  ([github](https://github.com/lief-project/LIEF/))\n- [DEBIN](https://debin.ai/): Predicting Debug Information in Stripped Binaries\n- [Analyzing ARM Cortex-based MCU firmwares using Binary Ninja](https://research.kudelskisecurity.com/2018/09/25/analyzing-arm-cortex-based-mcu-firmwares-using-binary-ninja/)\n- [Manticore](https://www.kitploit.com/2018/11/manticore-symbolic-execution-tool-for.html?m=1): Symbolic Execution Tool For Analysis Of Binaries And Smart Contracts. [manticore](https://github.com/trailofbits/manticore):  Symbolic execution tool\n- [Beam me up, CFG.](https://86hh.github.io/cfg.html): Earlier in 2018 while revisiting the Delay Import Table, I used dumpbin to check the Load Configuration data of a file and noticed new fields in it. And at the time of writing this, more fields were added! The first CFGuard caught my attention and I learned about Control Flow Guard, it is a new security feature. To put it simple, it protects the execution flow from redirection - for example, from exploits that overwrite an address in the stack. Maybe they should call it the Security Directory instead.\n- [PBA - Analysis Tools](https://github.com/Fare9/PBA_Analysis_Tools): My own versions from the programs of the book \"Practical Binary Analysis\"\n- [functrace](https://github.com/invictus1306/functrace): is a tool that helps to analyze a binary file with dynamic instrumentation using DynamoRIO\n- [Signature-Base](https://github.com/Neo23x0/signature-base): signature-base is the signature database for my scanners LOKI and SPARK Core.\n  - [Generic Anomalies](https://github.com/Neo23x0/signature-base/blob/master/yara/generic_anomalies.yar#L379): Detects an embedded executable in a non-executable file\n- [Virtuailor](https://github.com/0xgalz/Virtuailor): IDAPython tool for C++ vtables reconstruction.\n- [Linux Reverse Engineering CTFs for Beginners](https://osandamalith.com/2019/02/11/linux-reverse-engineering-ctfs-for-beginners/).\n- [execution-trace-viewer](https://github.com/teemu-l/execution-trace-viewer): Tool for viewing and analyzing execution traces\n- [Reverse Engineering of a Not-so-Secure IoT Device](https://mcuoneclipse.com/2019/05/26/reverse-engineering-of-a-not-so-secure-iot-device/)\n- ELF - Executable and Linkable Format:\n  - [Python for Reverse Engineering 1](https://icyphox.sh/blog/python-for-re-1/): ELF Binaries\n  - [The 101 of ELF files on Linux](https://linux-audit.com/elf-binaries-on-linux-understanding-and-analysis/): Understanding and Analysis - Linux Audit\n  - [On ELF, Part 1](https://kestrelcomputer.github.io/kestrel/2018/01/29/on-elf)\n  - [On ELF, Part 2](https://kestrelcomputer.github.io/kestrel/2018/02/01/on-elf-2)\n  - [binsider](https://github.com/orhun/binsider): Analyze ELF binaries like a boss 😼🕵️‍♂️\n- [Kaitai Struct](https://formats.kaitai.io/): A new way to develop parsers for binary structures.\n- [findLoop](https://github.com/secrary/findLoop): find possible encryption/decryption or compression/decompression code.\n- [Reverse Engineering 'A Link to the Past (GBA)' ep 1](https://sideway.re/Reverse-Engineering-alttp-GBA-ep1/)\n- [wiggle](https://github.com/ChiChou/wiggle): The concepting self hosted executable binary search engine.\n- [uncompyle6](https://github.com/rocky/python-uncompyle6): A cross-version [Python bytecode decompiler](https://www.kitploit.com/2019/07/uncompyle6-cross-version-python.html)\n- [Decompyle++](https://github.com/zrax/pycdc): C++ python bytecode disassembler and decompiler\n- [bearparser](https://github.com/hasherezade/bearparser). [PE-bear](https://github.com/hasherezade/pe-bear-releases)\n- [Reverse-engineering precision op amps from a 1969 analog computer](https://www.righto.com/2019/09/reverse-engineering-precision-op-amps.html)\n- [CPU Adventure – Unknown CPU Reversing](https://www.robertxiao.ca/hacking/dsctf-2019-cpu-adventure-unknown-cpu-reversing/): We reverse-engineered a program written for a completely custom, unknown CPU architecture, without any documentation for the CPU (no emulator, no ISA reference, nothing) in the span of ten hours. Read on to find out how we did it…\n- [pev](https://github.com/merces/pev): pev is a full-featured, open source, multiplatform command line toolkit to work with PE (Portable Executables) binaries.\n- [Sourcetrail](https://github.com/CoatiSoftware/Sourcetrail):  free and open-source cross-platform source explorer.\n- [Qiling Framework](https://www.qiling.io/): Qiling Advanced Binary Emulation Framework. [repo](https://github.com/qilingframework/qiling)\n- Obfuscation/Deobfuscation:\n  - [batch_deobfuscator](https://github.com/DissectMalware/batch_deobfuscator): Deobfuscate batch scripts obfuscated using string substitution and escape character techniques.\n  - [Tales Of Binary Deobfuscation - Part 1](https://ulexec.github.io/ulexec.github.io/article/2020/03/03/Deobfuscation_1.html)\n  - [evilquest_deobfuscator](https://github.com/gdbinit/evilquest_deobfuscator): EvilQuest/ThiefQuest malware strings decrypter/deobfuscator. [evilquest_stats](https://github.com/gdbinit/evilquest_stats): Small utility to hash EvilQuest code and cstrings sections.\n  - [Deobfuscating DanaBot’s API Hashing](https://malwareandstuff.com/deobfuscating-danabots-api-hashing/)\n  - [XLMMacroDeobfuscator](https://github.com/DissectMalware/XLMMacroDeobfuscator): Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)\n  - [syntia](https://github.com/RUB-SysSec/syntia): Program synthesis based deobfuscation framework for the USENIX 2017 paper \"Syntia: Synthesizing the Semantics of Obfuscated Code\"\n  - [Deobfuscation](https://blog.quarkslab.com/deobfuscation-recovering-an-ollvm-protected-program.html): recovering an OLLVM-protected program\n  - [Stadeo](https://github.com/eset/stadeo): Control-flow-flattening and string deobfuscator\n  - [Semi-Automatic Code Deobfuscation](https://github.com/mrphrazer/hitb2021ams_deobfuscation)\n  - [msynth](https://github.com/mrphrazer/msynth): Code deobfuscation framework to simplify Mixed Boolean-Arithmetic (MBA) expressions.\n- [Glasgow Debug Tool](https://github.com/GlasgowEmbedded/glasgow): Scots Army Knife for electronics\n- [VX Underground](https://vx-underground.org/)\n  - [MalwareSourceCode](https://github.com/vxunderground/MalwareSourceCode): Collection of malware source code for a variety of platforms in an array of different programming languages.\n  - [VXUG-Papers](https://github.com/vxunderground/VXUG-Papers): Research code \u0026 [papers](https://vx-underground.org/papers.html) from members of vx-underground.\n- (pt-br) [Como automaticamente atachar um processo a um debugger.](https://diegoalbuquerque.github.io/trick-to-bof-debugger.html)\n- [Taming Virtual Machine Based Code Protection](https://malwareandstuff.com/taming-virtual-machine-based-code-protection-1/)\n- [HyperDbg Debugger](https://github.com/HyperDbg/HyperDbg): The Source Code of HyperDbg Debugger\n- [The HT Editor](https://github.com/sebastianbiallas/ht): A file editor/viewer/analyzer for executables.\n- [ImHex](https://github.com/WerWolv/ImHex): A Hex Editor for Reverse Engineers, Programmers and people that value their eye sight when working at 3 AM.\n- [playing with little endian](https://www.offensivethink.com/little-endian.html)\n- [Finding memory bugs with AddressSanitizer](https://embeddedbits.org/finding-memory-bugs-with-addresssanitizer/)\n- [flare-floss](https://github.com/fireeye/flare-floss): : FireEye Labs Obfuscated String Solver - Automatically extract obfuscated strings from malware.\n- [#BazarBackdoor Group #CobaltStrike Payload](https://twitter.com/VK_Intel/status/1380765652827398148)\n- [The Debugging Book](https://www.debuggingbook.org/): Tools and Techniques for Automated Software Debugging.\n- [Debugging System with DCI and Windbg](https://standa-note.blogspot.com/2021/03/debugging-system-with-dci-and-windbg.html). [Plus, accompanying my first kernel-to-SMM LPE exploit \u0026 demo](https://twitter.com/standa_t/status/1376525000002334725), [SmmExploit](https://github.com/tandasat/SmmExploit).\n- [SCAS/SCASB/SCASW/SCASD](https://c9x.me/x86/html/file_module_x86_id_287.html): Scan String, x86 Instruction Set Reference.\n- [dexcalibur](https://github.com/FrenchYeti/dexcalibur): Android reverse engineering tool focused on dynamic instrumentation automation leveraging Frida. It disassembles dex, analyzes it statically, generates hooks, discovers reflected methods, stores intercepted data and does new things from it. Its aim is to be an all-in-one Android reverse engineering platform.\n- [Reverse-engineering tcpip.sys: mechanics of a packet of the death (CVE-2021-24086)](https://doar-e.github.io/blog/2021/04/15/reverse-engineering-tcpipsys-mechanics-of-a-packet-of-the-death-cve-2021-24086/#bonus-cve-2021-24074)\n- [rr](https://github.com/rr-debugger/rr): Record and Replay Framework.\n- [panda](https://github.com/panda-re/panda): Platform for Architecture-Neutral Dynamic Analysis.\n- [qira](https://github.com/geohot/qira): QEMU Interactive Runtime Analyser.\n- [qemu_blog](https://github.com/airbus-seclab/qemu_blog): A series of posts about QEMU internals.\n- [Reverse engineering (Absolute) UEFI modules for beginners](https://standa-note.blogspot.com/2021/04/reverse-engineering-absolute-uefi.html)\n- [miasm](https://github.com/cea-sec/miasm): Reverse engineering framework in Python\n- [rehex](https://github.com/solemnwarning/rehex):  Reverse Engineers' Hex Editor.\n- [Bless](https://github.com/bwrsandman/Bless): Gtk# Hex Editor (fork)\n- [Reverse Engineering the M6 Smart Fitness Bracelet](https://rbaron.net/blog/2021/07/06/Reverse-engineering-the-M6-smart-fitness-band.html)\n- [Reverse Engineering a Linux executable – hello world](https://www.codementor.io/@packt/reverse-engineering-a-linux-executable-hello-world-rjceryk5d)\n- [rizin](https://github.com/rizinorg/rizin): UNIX-like reverse engineering framework and command-line toolset. [site](https://rizin.re/)\n- [reFlutter](https://github.com/ptswarm/reFlutter): Flutter Reverse Engineering Framework.\n- [OpenSecurityTraining2](https://p.ost2.fyi/): OpenSecurityTraining Inc. (EIN 86-1180701) is a 501c3 non-profit working to create the world's best cybersecurity training.\n- [Nightmare](https://guyinatuxedo.github.io/) is an intro to binary exploitation / reverse engineering course based around ctf challenges.\n- [Breaking Protocol (Buffers): Reverse Engineering gRPC Binaries](https://labs.ioactive.com/2021/07/breaking-protocol-buffers-reverse.html)\n- [Sometimes static analysis of shellcode is annoying or infeasible, And what you really want to do is debug it, I'll show you how](https://twitter.com/notareverser/status/1479456627363401730).\n- [capa](https://github.com/mandiant/capa): The FLARE team's open-source tool to identify capabilities in executable files.\n- [aDLL](https://github.com/ideaslocas/aDLL) - Adventure of Dinamic Lynk Library: aDLL is a binary analysis tool focused on the automatic discovery of DLL Hijacking vulnerabilities. The tool analyzes the image of the binary loaded in memory to search for DLLs loaded at load-time and makes use of the Microsoft Detours library to intercept calls to the LoadLibrary/LoadLibraryEx functions to analyze the DLLs loaded at run-time.\n- [pyc2bytecode](https://github.com/knight0x07/pyc2bytecode): A Python Bytecode Disassembler helping reverse engineers in dissecting Python binaries by disassembling and analyzing the compiled python byte-code(.pyc) files across all python versions (including Python 3.10.*)\n- [Reverse Engineering PsExec for fun and knowledge](https://cybergeeks.tech/reverse-engineering-psexec-for-fun-and-knowledge/)\n- [Reverse Engineering TikTok's VM Obfuscation](https://ibiyemiabiodun.com/projects/reversing-tiktok-pt2/)\n- [Acronis True Image Costs Performance When Not Used](https://randomascii.wordpress.com/2025/05/26/acronis-true-image-costs-performance-when-not-used/)\n\n### Decompilers\n\n- [decompile_java](https://gist.github.com/larshaendler/b0679f6e36e487d00647e2f2a2989c0c), using [CFR](http://www.benf.org/other/cfr/) - another java decompiler.\n- [NoVmp](https://github.com/can1357/NoVmp): A static devirtualizer for VMProtect x64 3.x powered by VTIL.\n- [Awesome IDA, x64DBG \u0026 OllyDBG plugins](https://github.com/fr0gger/awesome-ida-x64-olly-plugin): A curated list of IDA x64DBG and OllyDBG plugins.\n- [edb](https://github.com/eteran/edb-debugger) is a cross-platform AArch32/x86/x86-64 debugger.\n- [Interactive Delphi Reconstructor IDR](https://github.com/crypto2011/IDR): a decompiler of executable files (EXE) and dynamic libraries (DLL), written in Delphi and executed in Windows32 environment.\n- [PyInstaller Extractor](https://github.com/extremecoders-re/pyinstxtractor)\n\n### Yara\n\n- [Yara-Rules](https://github.com/Yara-Rules/rules): Repository of yara rules\n- [Repository containing Indicators of Compromise and Yara rules](https://github.com/advanced-threat-research/IOCs)\n- [YARA in a nutshell](http://virustotal.github.io/yara/)\n- [yara](https://github.com/virustotal/yara): The pattern matching swiss knife\n- [mkYARA](https://blog.fox-it.com/2019/03/28/mkyara-writing-yara-rules-for-the-lazy-analyst/): Writing YARA rules for the lazy analyst ([github](https://github.com/fox-it/mkyara))\n- [Yara-Rules](https://github.com/advanced-threat-research/Yara-Rules): Repository of YARA rules made by McAfee ATR Team.\n- [ReversingLabs YARA Rules](https://github.com/reversinglabs/reversinglabs-yara-rules)\n- [YaraHunts](https://github.com/sbousseaden/YaraHunts): Random hunting ordiented yara rules\n- [YARA Rules for ProcFilter](https://github.com/godaddy/yara-rules)\n- [ThreatHunting](https://github.com/GossiTheDog/ThreatHunting)\n- [yara-validator](https://github.com/CIRCL/yara-validator): Validates yara rules and tries to repair the broken ones.\n- [Vim Syntax Highlighting for YARA Rules](https://github.com/s3rvac/vim-syntax-yara): A Vim syntax-highlighting file for YARA rules covering YARA 4.0\n- Rules DB:\n  - [xored_pefile_mini](https://github.com/tillmannw/yara-rules/blob/main/xored_pefile_mini.yara): detects files with a PE header at uint32(0x3c), xored with a key of 1, 2 or 4 bytes. by [tlansec](https://twitter.com/tlansec/status/1479039005459111936)\n\n### Ghidra\n\n- [ghidra](https://github.com/NationalSecurityAgency/): is a software reverse engineering (SRE) framework\n- [ghidra-firmware-utils](https://github.com/al3xtjames/ghidra-firmware-utils): Ghidra utilities for analyzing firmware\n- [dragondance](https://github.com/0ffffffffh/dragondance): Binary code coverage visualizer plugin for Ghidra\n- [Decompiler Analysis Engine](https://ghidra-decompiler-docs.netlify.com/index.html): Welcome to the Decompiler Analysis Engine. It is a complete library for performing automated data-flow analysis on software, starting from the binary executable.\n- [Working With Ghidra's P-Code To Identify Vulnerable Function Calls](https://www.riverloopsecurity.com/blog/2019/05/pcode/)\n- [GhIDA](https://blog.talosintelligence.com/2019/09/ghida.html): [Ghidra decompiler for IDA Pro](https://github.com/Cisco-Talos/GhIDA).\n- [Ghidraaas](https://github.com/Cisco-Talos/GhIDA): Ghidra as a Service\n- [SVD-Loader for Ghidra](https://leveldown.de/blog/svd-loader/): Simplifying bare-metal ARM reverse engineering. [repo](https://github.com/leveldown-security/SVD-Loader-Ghidra)\n- [GhidraX64Dbg](https://github.com/revolver-ocelot-saa/GhidraX64Dbg): Extract annoations from Ghidra into an X32/X64 dbg database.\n- [Reverse Engineering Go Binaries with Ghidra](https://cujo.com/reverse-engineering-go-binaries-with-ghidra/)\n- [Introduction to Reverse Engineering with Ghidra: A Four Session Course](https://wrongbaud.github.io/posts/ghidra-training/)\n- [Ghidra Plugin Development for Vulnerability Research - Part-1](https://www.somersetrecon.com/blog/2019/ghidra-plugin-development-for-vulnerability-research-part-1)\n- [AngryGhidra](https://github.com/Nalen98/AngryGhidra): Use angr in Ghidra\n- [Defeating Code Obfuscation with Angr](https://napongizero.github.io/blog/Defeating-Code-Obfuscation-with-Angr)\n- [ghidra2frida](https://security.humanativaspa.it/ghidra2frida-the-new-bridge-between-ghidra-and-frida/): The new bridge between Ghidra and Frida. [repo](https://github.com/federicodotta/ghidra2frida) [scripts](https://github.com/federicodotta/ghidra2frida/tree/main/java_python_examples)\n- [ghidra-scripts](https://github.com/federicodotta/ghidra-scripts/): A collection of my Ghidra scripts.\n- [Reversing Raw Binary Firmware Files in Ghidra](https://gist.github.com/nstarke/ed0aba2c882b8b3078747a567ee00520)\n- [Ghidrathon](https://github.com/mandiant/Ghidrathon): The FLARE team's open-source extension to add [Python 3 scripting to Ghidra](https://www.mandiant.com/resources/blog/ghidrathon-snaking-ghidra-python-3-scripting).\n- [IDA Graph view with outlined function included](https://gist.github.com/NyaMisty/790474707209399da643fbe5788191cd)\n- [G-3PO: A Protocol Droid for Ghidra](https://medium.com/tenable-techblog/g-3po-a-protocol-droid-for-ghidra-4b46fa72f1ff) [repo](https://github.com/tenable/ghidra_tools/tree/main/g3po)\n\n## Frameworks\n\n- [Inject code into running Python processes](https://github.com/lmacken/pyrasite)\n- [malspider](https://github.com/ciscocsirt/malspider): Malspider is a web spidering framework that detects characteristics of web compromises.\n- [AIL-framework](https://github.com/CIRCL/AIL-framework): AIL framework - [Analysis Information Leak framework](https://github.com/ail-project/ail-framework):\n\n## Patching\n\n- Did Microsoft Just Manually Patch Their Equation Editor Executable? Why Yes, Yes [They Did](https://0patch.blogspot.com.br/2017/11/did-microsoft-just-manually-patch-their.html). (CVE-2017-11882)\n\n## Hardening\n\n- [BlueWars](https://medium.com/blueops/bluewars-capture-the-flag-defensivo-que-aconteceu-na-h2hc-514c75e3f13c): Capture The Flag Defensivo que aconteceu na H2HC\n- [CCAT](https://github.com/cisco-config-analysis-tool/ccat): Cisco Config Analysis Tool\n- [Ciderpress](https://github.com/da667/Ciderpress): Hardened wordpress installer\n- [debian-cis](https://github.com/ovh/debian-cis): PCI-DSS compliant Debian 7/8 hardening.\n- [Endlessh](https://github.com/skeeto/endlessh): an SSH tarpit.\n- [ERNW Repository of Hardening Guides](https://github.com/ernw/hardening): This repository contains various hardening guides compiled by ERNW for various purposes.\n- [fero](https://github.com/coreos/fero): YubiHSM2-backed signing server\n- [FirewallChecker](https://github.com/Z3Prover/FirewallChecker): A self-contained firewall checker\n- [Get SSH login notification on Telegram](https://8192.one/post/ssh_login_notification_withtelegram/)\n- [Hardentools](https://github.com/securitywithoutborders/hardentools) is a utility that disables a number of risky Windows features.\n- [How To Secure A Linux Server](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server): An evolving how-to guide for securing a Linux server.\n- [kconfig-hardened-check](https://github.com/a13xp0p0v/kconfig-hardened-check): A tool for checking the hardening options in the Linux kernel config\n- [Implementing Least-Privilege Administrative Models](https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/implementing-least-privilege-administrative-models)\n- [Iptables Essentials](https://github.com/trimstray/iptables-essentials): Common Firewall Rules and Commands.\n- [iptables-essentials](https://github.com/trimstray/iptables-essentials): Iptables Essentials: Common Firewall Rules and Commands.\n- [Keyringer](https://keyringer.pw/): encrypted and distributed secret sharing software\n- [Keystone Project](https://keystone-enclave.org/). Github: [Keystone Enclave](https://github.com/keystone-enclave/)\n- [linux-hardened](https://github.com/copperhead/linux-hardened): Minimal supplement to upstream Kernel Self Protection Project changes.\n- [List of sites with two factor auth](https://github.com/2factorauth/twofactorauth)\n- [nftables](https://www.funtoo.org/Package:Nftables): nftables is the successor to iptables. It replaces the existing iptables, ip6tables, arptables and ebtables framework. It uses the Linux kernel and a new userspace utility called nft. nftables provides a compatibility layer for the ip(6)tables and framework.\n- Nice article with a lot of resources: [Common approaches to securing Linux servers and what runs on them.](https://medium.com/@ageis/common-approaches-to-securing-linux-servers-and-what-runs-on-them-dadcacc5388b)\n- [opmsg](https://github.com/stealth/opmsg): is a replacement for gpg which can encrypt/sign/verify your mails or create/verify detached signatures of local files. Even though the opmsg output looks similar, the concept is entirely different.\n- [prowler](https://github.com/toniblyx/prowler): AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and additional checks. Official CIS for [AWS guide](https://d0.awsstatic.com/whitepapers/compliance/AWS_CIS_Foundations_Benchmark.pdf).\n- [reconbf](https://github.com/HewlettPackard/reconbf): Recon system hardening scanner\n- [Sarlacc](https://github.com/scrapbird/sarlacc) is an SMTP server that I use in my malware lab to collect spam from infected hosts.\n- [Secure \u0026 Ad-free Internet Anywhere With Streisand and Pi Hole](https://ifelse.io/2019/01/12/secure-ad-free-internet-anywhere-with-streisand-and-pi-hole/)\n- [Secure Secure Shell](https://stribika.github.io/2015/01/04/secure-secure-shell.html) by [stribika](https://github.com/stribika)\n- [Securing Docker Containers](https://0x00sec.org/t/securing-docker-containers/16913). [The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.](https://github.com/docker/docker-bench-security)\n- [securityonion-docs](https://github.com/Security-Onion-Solutions/securityonion-docs)\n- [security.txt](https://securitytxt.org/): A proposed standard which allows websites to define security policies.\n- [security-txt](https://github.com/securitytxt/security-txt): A proposed standard that allows websites to define security policies.\n- See your site config with [Hardenize](https://www.hardenize.com/)\n- [Set up two-factor authentication for SSH on Fedora](https://fedoramagazine.org/two-factor-authentication-ssh-fedora/)\n- [solo-hw](https://github.com/SoloKeysSec/solo-hw): Hardware sources for Solo\n- [ssh-auditor](https://github.com/ncsa/ssh-auditor): The best way to scan for weak ssh passwords on your network\n- [Streisand](https://github.com/StreisandEffect/streisand) sets up a new server running your choice of WireGuard, OpenConnect, OpenSSH, OpenVPN, Shadowsocks, sslh, Stunnel, or a Tor bridge. It also generates custom instructions for all of these services. At the end of the run you are given an HTML file with instructions that can be shared with friends, family members, and fellow activists.\n- [The Practical Linux Hardening Guide](https://github.com/trimstray/the-practical-linux-hardening-guide): 🔥 This guide details the planning and the tools involved in creating a secure Linux production systems - work in progress.\n- [tls-what-can-go-wrong](https://github.com/hannob/tls-what-can-go-wrong): TLS - what can go wrong?\n- [upvote](https://github.com/google/upvote): A multi-platform binary whitelisting solution\n- [Using a Hardened Container Image for Secure Applications in the Cloud](https://www.cisecurity.org/blog/using-hardened-container-image-secure-applications-cloud/)\n- [Zero-knowledge attestation](https://www.imperialviolet.org/2019/01/01/zkattestation.html)\n- [Reverie](https://blog.trailofbits.com/2020/12/14/reverie-an-optimized-zero-knowledge-proof-system/): An optimized zero-knowledge proof system.\n- RHEL Like systems:\n  - [CentOS7 Lockdown](https://github.com/naingyeminn/CentOS7_Lockdown)\n  - [RHEL7-CIS](https://github.com/radsec/RHEL7-CIS): Ansible RHEL 7 - CIS Benchmark Hardening Script\n  - [cisecurity](https://github.com/cohdjn/cisecurity): Configures Linux systems to Center for Internet Security Linux hardening standard.\n- [bdshemu](https://hvmi.github.io/blog/2020/11/11/bdshemu.html): The [Bitdefender](https://github.com/bitdefender/bddisasm) shellcode emulator\n- [IPv6 Security Best Practices](https://theinternetprotocolblog.wordpress.com/2020/11/28/ipv6-security-best-practices/)\n- [auditd](https://github.com/Neo23x0/auditd): Best Practice Auditd Configuration.\n- [Hardened/PaX Quickstart](https://wiki.gentoo.org/wiki/Hardened/PaX_Quickstart)\n- [tosh](https://github.com/mikroskeem/tosh): Imagine your SSH server only listens on an IPv6 address, and where the last 6 digits are changing every 30 seconds as a TOTP code...\n- Kubernetes:\n  - [9 Kubernetes Security Best Practices Everyone Must Follow](https://www.cncf.io/blog/2019/01/14/9-kubernetes-security-best-practices-everyone-must-follow/)\n  - NSA/CISA [Kubernetes Hardening Guidance](https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF)\n- [CHAPS](https://github.com/cutaway-security/chaps): Configuration Hardening Assessment PowerShell Script (CHAPS)\n- [Awesome Windows Domain Hardening](https://github.com/PaulSec/awesome-windows-domain-hardening): A curated list of awesome Security Hardening techniques for Windows.\n- [NSA/CISA Kubernetes Hardening Guidance](https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF)\n- [Learn and Test DMARC](https://www.learndmarc.com/): Visualizing the communication between email servers will help you understand what SPF, DKIM, and DMARC do and how these mechanisms work.\n- [VideoLan Robots.txt](https://www.videolan.org/robots.txt)\n- [ssh \u0026 linux cheat sheets](https://blowstack.com/cheat-sheets/)\n- [ssh-audit](https://github.com/jtesta/ssh-audit): SSH server \u0026 client auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)\n\n### WebServers\n\n- A lot of good posts by geek flare:\n  - [How to Configure SSL Certificate on Google Cloud Load Balancer?](https://geekflare.com/google-load-balancer-enable-ssl/)\n  - [Nginx Web Server Security \u0026 Hardening Guide](https://geekflare.com/nginx-webserver-security-hardening-guide/)\n  - [IBM HTTP Server Security \u0026 Hardening Guide](https://geekflare.com/ibm-http-server-security-guide/)\n  - [Apache Tomcat Hardening and Security Guide](https://geekflare.com/apache-tomcat-hardening-and-security-guide/)\n  - [How to Enable TLS 1.3 in Nginx, Cloudflare?](https://geekflare.com/enable-tls-1-3/)\n  - [Apache Web Server Hardening \u0026 Security Guide](https://geekflare.com/apache-web-server-hardening-security/) (broken!??)\n- CaCerts\n  - [List of free rfc3161 servers.](https://gist.github.com/Manouchehri/fd754e402d98430243455713efada710) TSA Servers\n  - [certstream-server](https://github.com/CaliDog/certstream-server): Certificate Transparency Log aggregation, parsing, and streaming service written in Elixir\n- Apache:\n  - [Apache Security](https://www.feistyduck.com/library/apache-security/) by [Ivan Ristić](https://twitter.com/ivanristic)\n  - [dotdotslash](https://github.com/jcesarstef/dotdotslash): An tool to help you search for Directory Traversal Vulnerabilities\n  - [A new security header: Feature Policy](https://scotthelme.co.uk/a-new-security-header-feature-policy/)\n  - [How do I prevent apache from serving the .git directory?](https://serverfault.com/questions/128069/how-do-i-prevent-apache-from-serving-the-git-directory/128082#128082)\n- Nginx:\n  - [20 Essential Things to Know if You’re on Nginx Web Server](https://www.ubuntupit.com/essential-things-to-know-if-youre-on-nginx-web-server/)\n  - [Nginx C function](https://nginx-c-function.github.io): Create your desired C application on top of nginx module\n  - [NGINX config for SSL with Let's Encrypt certs](https://gist.github.com/nrollr/9a39bb636a820fb97eec2ed85e473d38)\n  - [How to Configure Nginx SSL Certifcate Chain](https://futurestud.io/tutorials/how-to-configure-nginx-ssl-certifcate-chain)\n- PHP:\n  - [Cheatsheet for finding vulnerable PHP code using grep](https://github.com/dustyfresh/PHP-vulnerability-audit-cheatsheet): This will assist you in the finding of potentially vulnerable PHP code. Each type of grep command is categorized in the type of vulnerabilities you generally find with that function.\n  - [It's All About Time](https://blog.ircmaxell.com/2014/11/its-all-about-time.html). [Time Trial](https://github.com/dmayer/time_trial)- A tool for performing feasibility analyses of timing attacks. [TimingIntrusionTool5000](https://github.com/aj-code/TimingIntrusionTool5000): A tool for performing network timing attacks on plaintext and hashed password authentication.\n  - [snuffleupagus](https://github.com/nbs-system/snuffleupagus): Security module for php7 - Killing bugclasses and virtual-patching the rest!\n  - [FOPO-PHP-Deobfuscator](https://github.com/Antelox/FOPO-PHP-Deobfuscator): A simple script to deobfuscate PHP file obfuscated with FOPO Obfuscator\n  - [Decode.Tools](https://malware.expert/general/decode-tools-decode-php-obfuscator-by-fopo/): Decode PHP Obfuscator by FOPO\n- Ruby:\n  - [TSS - Threshold Secret Sharing](https://github.com/grempe/tss-rb): A Ruby implementation of Threshold Secret Sharing (Shamir) as defined in IETF Internet-Draft draft-mcgrew-tss-03.txt\n- [IT Security Guidelines for Transport Layer Security (TLS)](https://english.ncsc.nl/publications/publications/2021/january/19/it-security-guidelines-for-transport-layer-security-2.1)\n- [A new security header: Feature Policy](https://scotthelme.co.uk/a-new-security-header-feature-policy/)\n- [CAA Mandated by CA/Browser Forum](https://blog.qualys.com/ssllabs/2017/03/13/caa-mandated-by-cabrowser-forum)\n- [dotdotslash](https://github.com/jcesarstef/dotdotslash): An tool to help you search for Directory Traversal Vulnerabilities\n- [ENVOY](https://www.envoyproxy.io/) is an open source edge and service proxy, designed for cloud-native applications. [code](https://github.com/envoyproxy/envoy)\n- [ghp](https://github.com/CurtisLusmore/ghp): A simple web server for serving static GitHub Pages locally\n- [LEAR](https://github.com/Glorf/lear): Linux Engine for Asset Retrieval\n- [NFHTTP](https://github.com/spotify/NFHTTP): A cross platform C++ HTTP library that interfaces natively to other platforms.\n- [Security/Server Side TLS](https://wiki.mozilla.org/Security/Server_Side_TLS) by Mozilla\n- [security.txt](https://securitytxt.org/): A proposed standard which allows websites to define security policies.\n- [urlscan.io](https://urlscan.io/): A sandbox for the web\n- [IT Security Guidelines for Transport Layer Security (TLS)](https://english.ncsc.nl/publications/publications/2021/january/19/it-security-guidelines-for-transport-layer-security-2.1)\n- [QUIC's combined transport- and cryptographic handshake allows it to be 1 Round Trip faster than TCP + TLS and main problems.](https://twitter.com/programmingart/status/1399443052851306503)\n- [Secure Headers](https://github.com/github/secure_headers): Manages application of security headers with many safe defaults.\n- [HTTP/2: The Sequel is Always Worse](https://portswigger.net/research/http2) [blackhat](https://www.blackhat.com/us-21/briefings/schedule/#http2-the-sequel-is-always-worse-22668)\n- RFC 9116: [A File Format to Aid in Security Vulnerability Disclosure](https://www.rfc-editor.org/rfc/rfc9116)\n\n## Credentials\n- [WhiteIntel](https://whiteintel.io): WhiteIntel assists companies in identifying compromised credentials through malware campaigns. \n- Search if your credentials where leaked: [Cr3dOv3r](https://github.com/D4Vinci/Cr3dOv3r)\n- [pw-pwnage-cfworker](https://github.com/detroitenglish/pw-pwnage-cfworker): Deploy a Cloudflare Worker to sanely score users' new passwords with zxcvbn AND check for matches against haveibeenpwned's 5.1+ billion breached accounts\n- [XSS Exploit code for retrieving passwords stored in a Password Vault](https://gist.github.com/shawarkhanethicalhacker/e40a7c3956fdd24b9fb63d03d94c3d34)\n- [login_duress](https://github.com/jcs/login_duress): A BSD authentication module for duress passwords\n- [XSStrike](https://github.com/s0md3v/XSStrike): Most advanced XSS detection suite.\n- [Was my password leaked?](https://davidtavarez.github.io/osint/2019/01/25/pwndb-command-line-tool-python.html) [pwndb](https://github.com/davidtavarez/pwndb): Search for creadentials leaked on pwndb.\n- [bitwarden_rs](https://github.com/dani-garcia/bitwarden_rs/): Unofficial Bitwarden compatible server written in Rust\n- [pcfg_cracker](https://github.com/lakiw/pcfg_cracker): Probabilistic Context Free Grammar (PCFG) password guess generator\n- [Depix](https://github.com/beurtschipper/Depix): Recovers passwords from pixelized screenshots.\n- [pwndb](https://github.com/davidtavarez/pwndb): Search for leaked credentials.\n- [Password Lists](https://github.com/scipag/password-list): Password lists with top passwords to optimize bruteforce attacks.\n- [pwndb.py](https://github.com/davidtavarez/pwndb): [Search for leaked credentials](https://davidtavarez.github.io/2019/tutorial-pwndb-command-line-tool-python/).\n- KeePass [awsome](https://github.com/lgg/awesome-keepass):Curated list of KeePass-related projects\n  - [KeePassium](https://github.com/keepassium/KeePassium): KeePass-compatible password manager for iOS\n  - [Launch PowerShell Script From Within KeePass And Include Password Secure String Credential](https://www.sans.org/blog/launch-powershell-script-from-within-keepass-and-include-password-secure-string-credential/), [PowerShell for KeePass Password Manager](https://www.sans.org/blog/powershell-for-keepass-password-manager/), [PowerShell KeePass](https://github.com/PSKeePass/PoShKeePass).\n  - [libkeepass](https://github.com/libkeepass/libkeepass): Python module to read KeePass 1.x/KeePassX (v3) and KeePass 2.x (v4) files.\n  - [KeepassXC-Pwned](https://github.com/seanbreckenridge/keepassxc-pwned): Check your keepassxc database against previously breached haveibeenpwned passwords.\n\n### Tokens\n\n- [Use YubiKey security key to sign into AWS Management Console with YubiKey for multi-factor authentication](https://aws.amazon.com/pt/blogs/security/use-yubikey-security-key-sign-into-aws-management-console/)\n- [Introducing the Qubes U2F Proxy](https://www.qubes-os.org/news/2018/09/11/qubes-u2f-proxy/)\n- [YubiKey-Guide](https://github.com/drduh/YubiKey-Guide): Guide to using YubiKey for GPG and SSH\n- [Using a Yubikey for GPG and SSH](https://0day.work/using-a-yubikey-for-gpg-and-ssh/): Sebastian Neef - 0day.work\n- [PIN and Management Key](https://developers.yubico.com/yubikey-piv-manager/PIN_and_Management_Key.html)\n- [Improve login security with challenge-response authentication](https://fedoramagazine.org/login-challenge-response-authentication/)\n- [URU Card](https://en.ovcharov.me/2020/06/29/uru-card-arduino-fido2-authenticator/): Arduino FIDO2 Authenticator. [uru-card](https://github.com/uru-card/uru-card)\n- [YubiKey at Datadog](https://github.com/DataDog/yubikey)\n- [This is a practical guide to using YubiKey as a SmartCard for storing GPG encryption and signing keys.](https://github.com/drduh/YubiKey-Guide)\n- [yubikey-ssh-setup](https://github.com/jessfraz/dotfiles/blob/master/bin/yubikey-ssh-setup)\n\n## Secure Programming\n\n- Hardening C/C++ Programs Part II: [Executable-Space Protection and ASLR](http://www.productive-cpp.com/hardening-cpp-programs-executable-space-protection-address-space-layout-randomization-aslr/)\n- [Checklist of the most important security countermeasures when designing, testing, and releasing your API](https://github.com/shieldfy/API-Security-Checklist)\n- [sanitizers](https://github.com/google/sanitizers)\n- [Gitian](https://gitian.org) is a secure source-control oriented software distribution method.\n- [Canary](https://github.com/psecio/canary): Input Detection and Response\n- [Canarytokens](https://www.canarytokens.org/generate) by Thinkst, [Quick, Free, Detection for the Masses](https://blog.thinkst.com/p/canarytokensorg-quick-free-detection.html) [canaryfy](https://github.com/thinkst/canaryfy)\n- [CANARY FILES: GENERATING FAKE FILES TO DETECT CRITICAL DATA LOSS FROM COMPLEX COMPUTER NETWORKS](http://sdiwc.net/digital-library/canary-files-generating-fake-files-to-detect-critical-data-loss-from-complex-computer-networks)\n- [How to Know if Someone Access your Files with Canary Tokens](https://santanderglobaltech.com/en/how-to-know-if-someone-access-your-files-with-canary-tokens/)\n- [Wycheproof](https://github.com/google/wycheproof): Project Wycheproof tests crypto libraries against known attacks.\n- [Web App Security 101](https://kruschecompany.com/blog/post/web-app-security): Keep Calm and Do Threat Modeling\n- SSL/TLS for dummies:\n  - [part 1](https://www.wst.space/ssl-part1-ciphersuite-hashing-encryption/): Ciphersuite, Hashing, Encryption;\n  - [part 2](https://www.wst.space/ssl-part-2-diffie-hellman-key-exchange/): Understanding key exchange algorithm;\n  - [part 3](https://www.wst.space/ssl-part-3-certificate-authority/): Understanding Certificate Authority.\n- [heaphopper](https://github.com/angr/heaphopper): HeapHopper is a bounded model checking framework for Heap-implementations\n- [Ristretto](https://ristretto.group/ristretto.html) is a technique for constructing prime order elliptic curve groups with non-malleable encodings.\n- [SEI CERT C Coding Standard](https://wiki.sei.cmu.edu/confluence/display/c/SEI+CERT+C+Coding+Standard): The C rules and recommendations in this wiki are a work in progress and reflect the current thinking of the secure coding community. Because this is a development website, many pages are incomplete or contain errors. As rules and recommendations mature, they are published in report or book form as official releases. These releases are issued as dictated by the needs and interests of the secure software development community.\n  - [MSC24-C. Do not use deprecated or obsolescent functions](https://wiki.sei.cmu.edu/confluence/display/c/MSC24-C.+Do+not+use+deprecated+or+obsolescent+functions)\n  - [US-CERT: memcpy_s() and memmove_s()](https://www.us-cert.gov/bsi/articles/knowledge/coding-practices/memcpy_s%28%29-and-memmove_s%28%29)\n- [Safe C Library](https://github.com/coruus/safeclib): The Safe C Library provides bound checking memory and string functions per ISO/IEC TR24731. These functions are alternative functions to the existing standard C library that promote safer, more secure programming.\n- [Field Experience With Annex K — Bounds Checking Interfaces](http://www.open-std.org/jtc1/sc22/wg14/www/docs/n1967.htm)\n- [TSLint](https://github.com/palantir/tslint): An extensible linter for the TypeScript language.\n- [rubocop](https://github.com/rubocop-hq/rubocop): A Ruby static code analyzer and formatter, based on the community Ruby style guide.\n- [Librando](https://www.ics.uci.edu/~perl/publication/librando/): transparent code randomization for just-in-time compilers\n- [Checked C](https://www.microsoft.com/en-us/research/publication/checkedc-making-c-safe-by-extension/): Making C Safe by Extension. [github](https://github.com/Microsoft/checkedc)\n- [Practical case: Buffer Overflow 0x01](https://maxkersten.nl/binary-analysis-course/assembly-basics/practical-case-buffer-overflow-0x01/)\n- [pigaios](https://github.com/joxeankoret/pigaios): A tool for diffing source codes directly against binaries.  [slides](https://docs.google.com/presentation/d/1ifvugStGL7Qc8xSFeYXp2MGQ6jQGOOMSolBrJy8kCMY/edit#slide=id.g4453e8add5_0_129)\n- [pigaios](https://github.com/joxeankoret/pigaios): A tool for diffing source codes directly against binaries.  [slides](https://docs.google.com/presentation/d/1ifvugStGL7Qc8xSFeYXp2MGQ6jQGOOMSolBrJy8kCMY/edit#slide=id.g4453e8add5_0_129)\n- [A Git Horror Story](https://mikegerwitz.com/papers/git-horror-story): Repository Integrity With Signed Commits. How to use git securely (signing commits)\n- [An Introduction to Dynamic Symbolic Execution and the KLEE Infrastructure](https://srg.doc.ic.ac.uk/files/slides/symex-tarot-18.pdf)\n- [Tooling for verification of PGP signed commits](https://github.com/bitcoin/bitcoin/tree/master/contrib/verify-commits)\n- [tlse](https://github.com/eduardsui/tlse): Single C file TLS 1.2/1.3 implementation, using tomcrypt as crypto library\n- [tinyalloc](https://github.com/thi-ng/tinyalloc): malloc / free replacement for unmanaged, linear memory situations (e.g. WASM, embedded devices...)\n- [Sandboxed API](https://github.com/google/sandboxed-api): Sandboxed API automatically generates sandboxes for C/C++ libraries\n- [HACL*](https://github.com/project-everest/hacl-star): a formally verified cryptographic library written in F*\n- [Villoc](https://github.com/wapiflapi/villoc): Villoc is a heap visualisation tool, it's a python script that renders a static html file.\n- [How C array sizes become part of the binary interface of a library](https://developers.redhat.com/blog/2019/05/06/how-c-array-sizes-become-part-of-the-binary-interface-of-a-library/)\n- [MazuCC](https://github.com/jserv/MazuCC): A minimalist C compiler with x86_64 code generation\n- [When the going gets tough](https://lambdasec.github.io/When-the-going-gets-tough-Understanding-the-challenges-with-Product-commoditization-in-SCA/): Understanding the challenges with Product commoditization in SCA.\n- [huskyCI](https://github.com/globocom/huskyCI): huskyCI is an open source tool that performs security tests inside CI pipelines of multiple projects and centralizes all results into a database for further analysis and metrics.\n- (pt-br) [GTER 47 | GTS 33 - Dia 2 (parte 1)](https://www.youtube.com/watch?v=7XgwJHOSmoE): nice talk by Daniel Carlier and Silvia Pimpão.\n- [HTTP Security Headers](https://nullsweep.com/http-security-headers-a-complete-guide/) - A Complete Guide\n- [SAFECode](https://safecode.org/): is a non-profit organization exclusively dedicated to increasing trust in information and communications technology products and services through the advancement of effective software assurance methods.\n- [Security Code Review 101](https://medium.com/@paul_io/security-code-review-101-a3c593dc6854)\n- [Elliptic Curve Cryptography Explained](https://fangpenlin.com/posts/2019/10/07/elliptic-curve-cryptography-explained/)\n- [Cheatsheet for finding vulnerable PHP code using grep](https://github.com/dustyfresh/PHP-vulnerability-audit-cheatsheet): This will assist you in the finding of potentially vulnerable PHP code. Each type of grep command is categorized in the type of vulnerabilities you generally find with that function.\n- [How to Process Passwords as a Software Developer](https://dev.to/nathilia_pierce/how-to-process-passwords-as-a-software-developer-3dkh)\n- [QL](https://github.com/Semmle/ql): The libraries and queries that power CodeQL and LGTM.com\n- [Sendy is Insecure](https://victorzhou.com/blog/sendy-recaptcha-security/): How Not to Implement reCAPTCHA\n- Win10 Crypto Vulnerability: [Cheating in Elliptic Curve Billiards 2](https://medium.com/zengo/win10-crypto-vulnerability-cheating-in-elliptic-curve-billiards-2-69b45f2dcab6)\n- [DevSecOps](https://dzone.com/articles/devsecops-securing-software-in-a-devops-world): Securing Software in a DevOps World\n- [GitGuardian Documentation and Resources](https://github.com/GitGuardian/APISecurityBestPractices): Resources to help you keep secrets (API keys, database credentials, certificates, ...) out of source code and remediate the issue in case of a leaked API key. Made available by GitGuardian. [python API Client](https://github.com/GitGuardian/py-gitguardian)\n- [Vuln Cost - Security Scanner for VS Code](https://github.com/snyk/vulncost): Find security vulnerabilities in open source npm packages while you code.\n- [Most Popular Analysis Tools by Programming Language](https://analysis-tools.dev/)\n- [Deepsource](https://deepsource.io): tool that analyzes your repository.\n- [git-wild-hunt](https://github.com/d1vious/git-wild-hunt): A tool to hunt for credentials in github wild AKA git*hunt\n- [shhgit](https://github.com/eth0izzle/shhgit/): Ah [shhgit!](https://www.shhgit.com/) Find GitHub secrets in real time.\n- [A Graduate Course in Applied Cryptography](http://toc.cryptobook.us/)\n- [KaiMonkey](https://github.com/accurics/KaiMonkey): Vulnerable Terraform Infrastructure. KaiMonkey provides example vulnerable infrastructure to help cloud security, DevSecOps and DevOps teams explore and understand common cloud security threats exposed via infrastructure as code.\n- [You don’t need reproducible builds.](https://blog.cmpxchg8b.com/2020/07/you-dont-need-reproducible-builds.html)\n- [Comments on build reproducibility](https://gist.github.com/brl/c55ab5d2633f366b680b5a7cca718f85)\n- DevSecOps – [Integrating Security in the Development Pipeline](https://katanasec.com/devsecops-integrating-security-in-the-development-pipeline/)\n- [SLSA](https://github.com/slsa-framework/slsa): Supply-chain Levels for Software Artifacts, Proposal\n- [DazedAndConfused](https://github.com/salesforce/DazedAndConfused) is a tool to help determine dependency confusion exposure.\n- [Security Scorecards](https://github.com/ossf/scorecard): Security health metrics for Open Source. [Check Documentation](https://github.com/ossf/scorecard/blob/main/docs/checks.md#check-documentation)\n- [kcare-uchecker](https://github.com/cloudlinux/kcare-uchecker): A simple tool to detect outdated shared libraries.\n- [Package Hunter](https://gitlab.com/gitlab-org/security-products/package-hunter): A tool for identifying malicious dependencies via runtime monitoring.\n- [What science can tell us about C and C++'s security](https://alexgaynor.net/2020/may/27/science-on-memory-unsafety-and-security/)\n- [Awesome AppSec](https://github.com/paragonie/awesome-appsec): A curated list of resources for learning about application security.\n- [Comments on build reproducibility](https://gist.github.com/brl/c55ab5d2633f366b680b5a7cca718f85)\n\n### Web Training\n\n- [OWASP Broken Web Applications Project](https://www.owasp.org/index.php/OWASP_Broken_Web_Applications_Project). [OWASP BWA](https://github.com/chuckfw/owaspbwa","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/spacial%2Fawesome-csirt/projects"}