Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely
-
Updated
Jul 27, 2022 - C#
Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely
Thumper is an open-source tripwire for the Shai-Hulud npm worm. Plant fake-but-realistic credentials where the worm scans - the instant one is read, you know the box might be breached. Free and built in the open by Jesta.
GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.
This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger retry storms, bypass TLS validation, and request unauthorized entitlements. Confirmed on iOS 18.6.2 with potential iCloud-based propagation.
Android overlay attack & SMS OTP stealer PoC using AccessibilityService — security research only
Runtime dependency-behavior monitor for Node.js. Two engines: in-process telemetry + an out-of-process (strace) trust boundary that sees native egress & persistence. Defense-in-depth for npm supply-chain attacks — SARIF, GitHub Action, zero deps.
Educational malware research - award-winning thesis on Windows credential theft and detection techniques
Analysis, IOCs, detection rules, and removal scripts for the ChatGPT Plus Free Trial cross-platform info-stealer (macOS + Windows)
Forensic dataset + live dashboard for the 2026-04-29 'A Mini Shai-Hulud has Appeared' npm supply-chain worm by TeamPCP. 1,117 dropbox repos, 22 compromised accounts, 47 IOCs across 14 kinds. Trojaned: @cap-js, mbt, @bitwarden/cli. C2 attribution to AS209101 IP Vendetta Inc. JSONL data · kinetic dashboard · CC-BY-4.0.
Proof of Concept: NTLMv2 Hash Capture via Microsoft Teams onenote:// URI
A DLL injection of RdpThief.dll to perform API hooking and extract RDP credentials
Object-first file access control for Linux: make ~/.ssh, ~/.aws and other secrets readable only by the tools that own them. Enforced in-kernel with eBPF (BPF-LSM), in Rust. Early development.
Cross-platform personal browser credential DLP monitor. Linux: fanotify blocking | Windows: NtQueryInfo polling. Blocks infostealers from reading cookies/passwords in real-time.
AD (Active Directory) Service Account Manager is an enterprise-grade PowerShell framework that codifies identity lifecycle management and eliminates identity debt within Active Directory. It transitions organizations away from fragmented, manual service account management into a structured, audited, and automated governance model.
Investigación técnica sobre vectores de ataque comunes en infraestructura cloud.
This case study documents a stealthy credential-harvesting technique in which the attacker used a lightweight binary (browserdump.exe) to extract stored credentials from browser cache files—specifically Chrome and Edge—without elevating privileges or triggering persistence indicators.
Detect, remove, and recover from the PolinRider npm supply-chain malware that injects an obfuscated loader into JS/TS config files (macOS). Field-tested step-by-step guide.
🛡️ SkillsSafe: A security scanner for SKILL.md, MCP configs, and system prompts to detect exfiltration, shell injection, and hidden threats.”
Threat-intel teardown + keyless live tracker of a multi-brand marketplace phishing-as-a-service (PhaaS) operation (Classiscam/Telekopye class) impersonating OLX, Subito, Kleinanzeigen & ~120 brands to steal card data + 3-D Secure/OTP. IOCs, kit analysis, detection signatures.
To associate your repository with the credential-theft topic, visit your repo's landing page and select "manage topics."