digital purrr... and Reddit refugee ...
blueteamsec @infosec.pub gentlemen-decryptor: First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35 files decrypted.
blueteamsec @infosec.pub nuitka-static-unpacker: Nuitka Static Unpacker — a static-first research tool for analyzing Nuitka-compiled binaries (constants/module extraction, .pyc recovery, reports).
blueteamsec @infosec.pub StegoForge: steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run 11 detection engines to uncover hidden payloads.
blueteamsec @infosec.pub claude-code-backdoor: Backdooring Claude Code via hooks in settings.json. Authorized use only!
blueteamsec @infosec.pub Beatrice.py: Modify machine code in binaries with alternative x64 assembly opcodes for AV evasion
blueteamsec @infosec.pub PSI_BOF: A BOF designed to inspect processes memory and addresses
blueteamsec @infosec.pub Launch WSL Applications from Windows with WslLaunch
blueteamsec @infosec.pub Atomic BOFs
blueteamsec @infosec.pub ohmypcap: A standalone web application for analyzing PCAP files using Suricata
blueteamsec @infosec.pub KernelToUserInjector: Sample code that demonstrates code injection from kernel-mode into a user-land process using user-mode APC
blueteamsec @infosec.pub MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876)
blueteamsec @infosec.pub auditd rules - v0.2.0 - The goal of audit.rules is to collect broad, attributable, reusable host telemetry. It should not try to encode every suspicious binary, shell, admin tool, or attacker workflow
blueteamsec @infosec.pub Tropic Trooper Reloaded: Unraveling the Invisible Supply Chain Mystery
blueteamsec @infosec.pub Bitwarden Statement on Checkmarx Supply Chain Incident
blueteamsec @infosec.pub Inside Lazarus: How North Korea uses AI to industrialize attacks on developers
blueteamsec @infosec.pub Shai-Hulud: The Third Coming — Bitwarden CLI Backdoored in Latest Supply Chain Campaign
blueteamsec @infosec.pub Foxit Impersonation: Fake PDF Installer Deploys VNC Malware
blueteamsec @infosec.pub CVE-2026-34159: Exploiting llama.cpp’s RPC Server - From Null Buffer to RCE Against PIE + Full RELRO + NX
blueteamsec @infosec.pub zig-pe: Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.
blueteamsec @infosec.pub FAQs on Recent Updates to FCC Covered List Regarding Routers Produced in Foreign Countries

















yep, still working