Skip to content
View tbarabosch's full-sized avatar

Block or report tbarabosch

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tbarabosch/README.md

Thomas Barabosch

Security engineer and researcher turning low-level technical analysis into practical security outcomes: detections, investigations, response workflows, and tools.

My work spans systems security, reverse engineering, threat intelligence, incident response, detection engineering, and AI-enabled security automation.

Website Scholar LinkedIn Email

Selected open-source work

  • fkie-cad/cwe_checker — Former developer and maintainer of a cross-architecture binary-analysis tool that detects vulnerable patterns in compiled code.
  • fkie-cad/FACT_core — Former developer and maintainer of a platform for automated firmware extraction, analysis, and comparison at scale.
  • tbarabosch/pocs — Author and curator of proof-of-concept material for responsibly disclosed FreeBSD, NetBSD, OpenBSD, and VirtualBox issues.
  • tbarabosch/apihash_to_yara — Author of a tool that generates YARA rules from Windows API hashes for malware detection and hunting.
  • telekom-security/malware_analysis — Contributor of analysis scripts, YARA rules, and indicators published alongside threat research.
  • facebookincubator/ForgeArmory — Contributor who added 17 commodity Linux TTPs to its MITRE ATT&CK-aligned catalogue for defensive validation.

Track record

Selected writing

Read all articles →

Public repository languages

Languages in Thomas Barabosch's public GitHub repositories

Based on public repositories owned by this account; organization-owned contributions are not included.

Popular repositories Loading

  1. quincy quincy Public archive

    Implementation of the DIMVA 2017 publication "Quincy: Detecting Host-Based Code Injection Attacks in Memory Dumps"

    Python 69 11

  2. apihash_to_yara apihash_to_yara Public

    Generate YARA rules from Windows API hashes for malware detection and hunting.

    YARA 17 2

  3. macos-re macos-re Public

    Scripts and tools for macOS reversing

    Python 15 3

  4. 1001-injects 1001-injects Public archive

    Tiny research project to understand code injections on Linux based systems

    C 14 4

  5. quincy-complementary-material quincy-complementary-material Public archive

    Complementary material of the DIMVA 2017 publication "Quincy: Detecting Host-Based Code Injection Attacks in Memory Dumps"

    8

  6. w32ShellcodeLoader w32ShellcodeLoader Public archive

    Simple tool to load x86 shellcode on Windows

    C++ 5 2