Big5-sec / pcode2code
a vba pcode decompiler based on pcodedmp
☆106Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for pcode2code
- A VBA p-code disassembler☆458Updated 3 years ago
- Parsers for custom malware formats ("Funky malware formats")☆92Updated 2 years ago
- ☆107Updated 4 years ago
- A tool for detecting VBA stomping.☆96Updated 2 years ago
- ☆100Updated last year
- A simple utility to list all methods of a given .NET Assembly and to invoke them☆71Updated 3 years ago
- ☆66Updated last year
- FLARE Kernel Shellcode Loader☆176Updated 5 years ago
- Driver Initial Reconnaissance Tool☆120Updated 4 years ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆62Updated 3 years ago
- Transfer EIP control to shellcode during malware analysis investigation☆73Updated 10 years ago
- IDA python plugin to scan binary with Yara rules☆171Updated 9 months ago
- A simple C# executable that invokes an arbitrary method of an arbitrary C# DLL☆129Updated 8 months ago
- API Logger for Windows Executables☆77Updated 4 years ago
- Robust Automated Malware Unpacker☆84Updated last year
- Set of antianalysis techniques found in malware☆129Updated last year
- Official VirusTotal plugin for IDA Pro☆155Updated 10 months ago
- This project aims at simplifying Windows API import recovery on arbitrary memory dumps☆241Updated last year
- Capa analysis importer for Ghidra.☆61Updated 3 years ago
- List of tools to assist in analyzing samples of ISFB/Gozi/Ursnif☆15Updated 5 years ago
- Scripts for disassembling VBScript p-code in the memory to aid in exploits analysis☆83Updated 2 years ago
- My repository to upload drivers from different books and all the information related to windows internals.☆154Updated 5 years ago
- Extract Windows Defender database from vdm files and unpack it☆425Updated 4 years ago
- Debug Child Process Tool (auto attach)☆272Updated last year
- Pure Python parser for Application Compatibility Shim Databases (.sdb files)☆106Updated 3 years ago
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆117Updated 4 years ago
- Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code☆178Updated 4 years ago
- Generating YARA rules based on binary code☆204Updated 3 years ago