A repository to store community malware research notes and findings.
☆15Feb 13, 2026Updated last month
Alternatives and similar repositories for community-malware-research
Users that are interested in community-malware-research are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated last year
- Detection rules and threat hunting queries in Defender XDR and Azure Sentinel☆16Mar 13, 2026Updated last week
- Repository with simples C binary samples for beginners REs & Defenders☆10May 29, 2024Updated last year
- Collection of my own detection rules☆20Jan 6, 2026Updated 2 months ago
- Knowledge base for reverse engineering and malware analysis☆15Jan 11, 2026Updated 2 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- Reports in .MD format☆21Jul 8, 2025Updated 8 months ago
- USN Journal full path builder☆67Sep 16, 2024Updated last year
- Information about the open-source-dfir slack community☆30Jun 17, 2023Updated 2 years ago
- ☆12Apr 1, 2023Updated 2 years ago
- CodeHawk Binary Analyzer for malware analysis and general reverse engineering☆39Updated this week
- Writeups for all pwn challenges from HTB Cyber Apocalypse 2023☆18Mar 22, 2023Updated 3 years ago
- A simple script that automates basic pentester reconaissance starting from nmap scans.☆10Dec 10, 2016Updated 9 years ago
- Chrome Logs Events and Protobuf Parser☆39Dec 13, 2022Updated 3 years ago
- Short Python script for parsing Defender VDM signature files.☆10Sep 22, 2024Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- macOS Artifacts☆33Mar 2, 2025Updated last year
- ThingFinder is a tool designed to facilitate searching and analysing code, whether it's source code or compiled binary executables. It pr…☆40Jun 16, 2024Updated last year
- Windows Shell Link (LNK) Proof of Concept☆16Jul 19, 2025Updated 8 months ago
- Network scanning tool designed to detect and report changes in open ports and services over time☆13Oct 16, 2025Updated 5 months ago
- Public exploits☆16May 28, 2018Updated 7 years ago
- Defender Resource Hub☆30Updated this week
- ☆12Jun 3, 2022Updated 3 years ago
- Small and highly portable detection tests based on MITRE's ATT&CK.☆12Jun 24, 2021Updated 4 years ago
- ☆40Aug 27, 2021Updated 4 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Draugnet is a lightweight, open-source tool for anonymous cyber threat reporting. Built for the MISP ecosystem, it lets users submit and …☆20Feb 26, 2026Updated 3 weeks ago
- Browser extension for launching multi-platform OSINT queries from grouped YAML profiles.☆10Apr 25, 2025Updated 11 months ago
- Using MCP is fun with Cyberbro!☆19Jan 27, 2026Updated last month
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆44Jul 18, 2022Updated 3 years ago
- ☆13Oct 24, 2024Updated last year
- IOCs for various malware families☆11Jul 18, 2024Updated last year
- Scans a list of raccoon servers from Tria.ge and extracts the config☆15Jun 5, 2023Updated 2 years ago
- A synergized Visual Studio and Rust development environment☆19Jan 25, 2025Updated last year
- Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions.☆60Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- Framework for Monitoring File Ingestion Source for Yara Matches☆50Mar 10, 2025Updated last year
- Automatically updated lists of Tor Relays.☆19Updated this week
- Automating Security Detection Engineering, published by Packt☆67Oct 12, 2024Updated last year
- ☆48Jun 6, 2025Updated 9 months ago
- Simple Automated Powershell Keylogger☆23May 21, 2020Updated 5 years ago
- The ultimate repository for remotely deploying Crowdstrike sensors quickly and discreetly on any other EDR platform.☆24Aug 12, 2025Updated 7 months ago
- A collection of reports and case studies to understand the threat landscape for UK critical infrastructure☆39Jan 23, 2024Updated 2 years ago