discovered 23 Aug 2026
oxide
→ View on GitHubOxide is a cross-platform remote access trojan (RAT) framework designed for security research and detection engineering, allowing users to demonstrate and analyze threat actor tactics, techniques, and procedures (TTPs) at the code level. It includes an implant written in Rust, a C2 panel implemented in Python, and provides comprehensive detection capabilities with paired YARA rules, Sigma rules, and incident response playbooks. The framework facilitates purple team exercises through a structured approach to understanding implant-panel communications and establishing effective detection strategies.