BinaryDefense / IcedDecrypt
IcedID Decryption Tool
☆28Updated 3 years ago
Alternatives and similar repositories for IcedDecrypt:
Users that are interested in IcedDecrypt are comparing it to the libraries listed below
- ☆44Updated last year
- C# User Simulation☆32Updated 2 years ago
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- Links to malware-related YARA rules☆14Updated 2 years ago
- A simple command line program to help defender test their detections for network beacon patterns and domain fronting☆69Updated 3 years ago
- Carbon Black Response IR tool☆53Updated 4 years ago
- ☆34Updated 2 years ago
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆76Updated 3 years ago
- ☆26Updated 3 years ago
- ☆38Updated 3 years ago
- Generate YARA rules for OOXML documents.☆38Updated last year
- BloodHound Cypher Queries Ported to a Jupyter Notebook☆53Updated 4 years ago
- ☆55Updated 4 years ago
- ☆41Updated 10 months ago
- Machine Interrogation To Identify Gaps & Techniques for Execution☆32Updated 2 years ago
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆72Updated 3 years ago
- See adversary, do adversary: Simple execution of commands for defensive tuning/research (now with more ELF on the shelf)☆102Updated 2 years ago
- Old home of LimaCharlie, open source EDR☆30Updated last year
- Malware similarity platform with modularity in mind.☆78Updated 3 years ago
- Code and Slides of my BSides London 2019 presentation about Attacker Emulation using CALDERA☆22Updated 5 years ago
- An experimental script to perform bulk parsing of arbitrary file features with YARA and console logging.☆21Updated 2 years ago
- This repo is dedicated to a powerpoint exploit☆35Updated 4 years ago
- Collection of YARA signatures from individual research☆42Updated last year
- Scripts and tools accompanying HP Threat Research blog posts and reports.☆50Updated 10 months ago
- TA505+ Adversary Simulation☆65Updated 4 years ago
- Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable…☆17Updated 3 years ago
- Detect possible sysmon logging bypasses given a specific configuration☆107Updated 6 years ago
- Babel-Shellfish deobfuscates and scans Powershell scripts on real-time right before each line execution.☆42Updated 6 years ago
- Presentation materials for talks I've given.☆20Updated 5 years ago
- THOR MITRE ATT&CK Framework Coverage☆24Updated 4 years ago