MalX Core
Foundational primitives for execution flow, staging, and runtime manipulation.
Malicious by Design.
A research-driven offensive-security initiative focused on malware execution, adversary tradecraft, and the mechanics of real-world exploitation.
MalX is an independent research effort dedicated to understanding how malicious code behaves in real environments. We study execution flow, evasion, staging, and adversarial automation — not as theory, but as hostile systems in motion.
To understand an adversary, you must think like one — and build like one.
MalX provides the structure, tooling, and research needed to explore modern offensive techniques with precision and clarity.
A modular architecture for adversarial experimentation.
Foundational primitives for execution flow, staging, and runtime manipulation.
A controlled environment for malware execution and behavioural experimentation.
Tooling for crafting loaders, stagers, payloads, and execution chains.
Research, PoCs, experiments, and adversarial studies.
The GitHub organization powering the ecosystem.
A precision adversarial fixture generator for PE structures. Produces syntactically valid binaries engineered to test loader edge cases and parser robustness.
Exploring the boundaries of executable formats through adversarial construction, malformed‑but‑valid structures, and parser robustness testing.
Syntactically valid PE files engineered to stress-test loader assumptions, section‑header logic, and boundary conditions.
Discovery of an import‑time crash in Ghidra's PE loader triggered by extreme but syntactically valid SizeOfRawData values. Demonstrates a bounds-checking weakness in section-header handling. Documented as issue #9264.
View Issue →Systematic evaluation of static-analysis, and reverse‑engineering tools under adversarial input conditions, focusing on correctness, stability, and resilience.
Independent PE static-analysis engine used to validate structural anomalies and compare loader behaviour under adversarial conditions.
Visit IOCX →MalX explores the mechanics of malicious execution through:
We build the mechanisms required to study malicious behaviour - practical, minimal, and purpose-driven.
Clarity matters more than aesthetics. The work leads; the visuals follow..
Focused, deliberate engineering.
To understand hostile systems, we model them - safely, intentionally, and in controlled environments.
The MalX ecosystem evolves continuously. Current areas of development include:
MalX exists for research, education, and the advancement of offensive-security understanding. All tools and experiments are intended for authorized environments only.
MalX does not distribute operational malware or offensive tooling. All research artifacts are non-functional, adversarial test fixtures designed for analysis and robustness evaluation.
Misuse is not tolerated. Understanding adversaries does not require becoming one.
MalX is open to researchers, operators, and toolmakers who share a commitment to adversarial clarity.
A segmented, observation-first topology for studying hostile systems in motion — without exposing the host.
192.168.1.0/24
Operator environment
No direct access
INetSim · Zeek · tcpdump
Simulation & observation
Controlled execution surface
Behavioral interaction
Linux testing
Post-execution analysis