Hunts for ransomware precursor behavior that precedes encryption — shadow-copy and backup deletion, recovery disabling, security-tool tampering, and mass file modification — so the attack can be stopped before payload detonation. Activates for requests to hunt ransomware precursors, detect shadow-copy deletion, or…
Hunts for malicious scheduled task persistence by analyzing task registration events (4698) and schtasks process creation for suspicious actions, triggers, and hidden tasks. Activates for requests to hunt scheduled task abuse, detect malicious schtasks usage, or find persistence via the Task Scheduler.
Hunts malicious PowerShell using script-block (EID 4104) and module logging: scoring encoded commands, download cradles, AMSI/logging bypass, and in-memory execution, then decoding payloads for triage. Activates for requests to hunt malicious PowerShell, analyze script-block logs, or detect encoded command abuse.
Hunts for unusual outbound network connections by flagging direct-to-IP traffic, uncommon ports, rare destinations, high data-egress ratios, and connections from unexpected processes in network telemetry. Activates for requests to hunt unusual outbound traffic, detect suspicious egress, or find anomalous external…
Hunts for malicious WMI permanent event subscription persistence by correlating EventFilter, CommandLineEventConsumer/ActiveScriptEventConsumer, and FilterToConsumerBinding records from Sysmon Event IDs 19/20/21 or WMI repository exports. Activates for requests to hunt WMI persistence, detect event consumer backdoors…
Identifies and bypasses anti-debugging and anti-analysis checks in malware: PEB flags, debugger-detection APIs, timing checks, and exception tricks, then neutralizes them to continue analysis. Activates for requests to identify anti-debugging, bypass anti-debug checks, or analyze evasion that blocks a debugger.
Identifies cryptographic algorithms embedded in a binary by scanning for well-known constants and tables (AES S-box, SHA-256/MD5 init constants, ChaCha sigma, CRC32 table, base64 alphabet). Activates for requests to identify crypto in a binary, find AES/SHA constants, or detect which encryption algorithm a sample uses.
Identifies a sample's true file type independent of its extension: matching magic bytes and structural signatures, detecting container/archive formats, and flagging extension-content mismatches used to disguise malware. Activates for requests to identify a file type, check magic bytes, or detect a disguised/spoofed…
Manually unpacks a runtime-packed Windows binary by finding the original entry point (OEP) through tail-jump and entropy analysis, then guiding a memory dump at OEP. Activates for requests to manually unpack a sample, find the OEP, or unpack a custom/unknown packer that generic tools cannot handle.
Maps hunts and detections to MITRE ATT&CK for coverage analysis: tagging hypotheses with techniques, building a coverage matrix from completed hunts, and identifying high-risk gaps to prioritize next. Activates for requests to map hunts to ATT&CK, build a coverage heatmap, or find detection gaps by technique.
Detects packing and encryption by measuring Shannon entropy across a binary's sections and regions: flagging high-entropy executable sections, entropy spikes, and size/raw-vs-virtual anomalies that indicate compression or encryption. Activates for requests to measure entropy, detect packing, or assess whether a sample…
Summarizes runtime behavior of a sample from Procmon-style operation logs — process and thread creation, file and registry writes, and network-related operations — to build a behavioral profile. Activates for requests to analyze Procmon output, summarize sample behavior, or profile process/file/registry activity from…
Converts a successful threat hunt into a durable detection by extracting the discriminating logic, defining data sources and thresholds, and emitting a Sigma rule plus a test and tuning plan. Activates for requests to operationalize a hunt, turn a finding into a detection rule, or productionize hunt logic as a Sigma…
Runs a sample in an instrumented sandbox to observe behavior: process tree, file and registry changes, network activity, and persistence, then summarizes the behavioral report into capabilities and IOCs. Activates for requests to detonate a sample, do dynamic or behavioral analysis, or interpret sandbox output.
Extracts structure and indicators from a Windows PE file without executing it: headers, sections, imports/exports, resources, entropy, and embedded strings to infer capability and packing. Activates for requests to statically analyze a PE, EXE, or DLL, or inspect imports and headers.
Pivots on indicators of compromise across multiple data sources by correlating a seed set of IOCs against logs to find co-occurring indicators, hosts, and timeframes that expand the investigation. Activates for requests to pivot on IOCs, correlate indicators across data sources, or expand an investigation from a seed…
Profiles a threat actor by aggregating observed ATT&CK techniques into a TTP profile and comparing it against known-group technique sets to estimate similarity and candidate attribution. Activates for requests to profile a threat actor, compare observed TTPs to known groups, or estimate attribution from technique…
Carves injected PE images and position-independent shellcode from a memory dump or carved region, identifies the payload type, and prepares it for disassembly or emulation. Activates for requests to recover injected code, carve shellcode from memory, or reconstruct a dumped payload for analysis.
Resolves dynamically hashed Windows API names by brute-forcing observed hash constants against a wordlist of API/DLL names using common malware hashing algorithms (ROR13, djb2, FNV, CRC32). Activates for requests to resolve API hashes, identify hashed imports, or reverse an API hashing routine.
Reverse engineers ARM/AArch64 malware by identifying the architecture and instruction set state (ARM/Thumb), parsing ELF/Mach-O ARM headers, and orienting analysis around the ARM calling convention. Activates for requests to reverse ARM binaries, analyze AArch64 malware, or handle ARM/Thumb instruction-set decoding.
Reverse engineers binaries with Binary Ninja using its analysis stack and Python API to enumerate functions, navigate IL levels (LLIL/MLIL/HLIL), and automate annotation and extraction. Activates for requests to reverse a binary with Binary Ninja, script the Binary Ninja API, or work with its intermediate languages.
Uses Ghidra to disassemble and decompile a binary, navigate to key routines via imports and strings, annotate decompiled code, and run headless scripts to automate extraction of C2, crypto, and config. Activates for requests to reverse engineer with Ghidra, decompile a binary, or script Ghidra headless analysis.
Reverse engineers binaries using radare2/rizin interactively, covering analysis initialization, navigation, disassembly and graph views, patching, and the visual mode workflow. Activates for requests to reverse a binary with radare2 or rizin, learn r2 commands, or navigate and disassemble a sample in r2.
Reverses proprietary command-and-control protocols: locating send/recv routines, recovering the message framing and encryption/encoding, and reconstructing the command set to build a decoder or emulator. Activates for requests to reverse a custom C2 protocol, decode beacon traffic, or document a malware command…
★not rated 22 1mo agoA70 tokens
Apache-2.0
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: