WithSecure Labs
WithSecure Labs
chainsaw
Rapidly Search and Hunt through Windows Forensic Artefacts
awspx
A graph-based tool for visualizing effective access and resource relationships in AWS environments.
ppid-spoofing
Scripts for performing and detecting parent PID spoofing
python-exe-unpacker
A helper script for unpacking and decompiling EXEs compiled from python code.
doublepulsar-c2-traffic-decryptor
A python2 script for processing a PCAP file to decrypt C2 traffic sent to DOUBLEPULSAR implant
CallStackSpoofer
A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)
doublepulsar-detection-script
A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.
doublepulsar-usermode-injector
A utility to use the usermode shellcode from the DOUBLEPULSAR payload to reflectively load an arbitrary DLL into another process, for use in testing detection techniques or other security research.
needle
The iOS Security Testing Framework