Research & Development
We tear malware apart and build the tools to keep your code from getting torn apart. Every writeup, YARA rule, and reverse-engineering note we produce lives on GitHub — free, no paywall, no signup.
Latest research
This is my first time reverse engineering a captcha, so some of the technical claims in this article might be wrong. If Cloudflare wants this post taken down, I will...
This case started from a https://tria.ge MSI sample: Endpoint_Agent_Setup_v5.1.75.msi. I treated it as a staged container immediately, not an endpoint installer, because the file…
is a two-component infostealer. The managed loader (CripStealer.exe) is responsible for process selection, privilege adjustments, reflective injection, and local IPC collection, w…
What We Do
The research stays open. The tools we'd want to buy ourselves are what we plan to sell.
Everything we publish — malware writeups, YARA rules, reverse-engineering notes — lives in a public GitHub repo. No paywall, no signup, no email capture.
A protection SDK, automated unpackers, and analysis utilities — the same engineering, productized. Sold separately when they're ready, not before.
Commercial license — priced independently
Network