4n0nym0us / 4n4lDetector
Advanced static analysis tool
☆88Updated this week
Alternatives and similar repositories for 4n4lDetector:
Users that are interested in 4n4lDetector are comparing it to the libraries listed below
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆38Updated 4 months ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆115Updated 7 months ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆58Updated this week
- VBScript & VBA source-to-source deobfuscator with partial-evaluation☆75Updated 6 months ago
- ☆111Updated this week
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆115Updated last year
- ☆68Updated last year
- Unpacker and Config Extractor for managed Redline Stealer payloads☆40Updated 2 years ago
- Configuration Extractors for Malware☆91Updated 3 weeks ago
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆59Updated 2 months ago
- ☆63Updated 3 weeks ago
- A C# based tool for analysing malicious OneNote documents☆110Updated last year
- Repository of Yara Rules☆100Updated this week
- ☆22Updated 8 months ago
- General malware analysis stuff☆36Updated 5 months ago
- A list of useful tools for Malware Analysis (will be updated regularly)☆137Updated 5 months ago
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- ☆38Updated last year
- Easy XOR string encryption for NET based binaries☆133Updated last year
- A collection of small scripts and tools for deobfuscation and malware analysis.☆66Updated last year
- Invoke-DetectItEasy is a wrapper for excelent tool called Detect-It-Easy. This PS module is very useful for Threat Hunting and Forensics.☆25Updated 3 years ago
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆81Updated last year
- Recon 2023 slides and code☆79Updated last year
- ☆20Updated last year
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆204Updated last year
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated last year
- Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE☆65Updated last year
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆134Updated 7 months ago
- A dynamic unpacking tool☆132Updated last year
- Batch script to compile a binary shellcode blob into an exe file☆83Updated 5 years ago