Bw3ll / sharemLinks
SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also contains its own custom disassembler, with many innovative features, such as being able to show the deobfuscated disassembly of an encoded shellcode, or integrating emulation data to enhance the disassembly.
☆474Updated 6 months ago
Alternatives and similar repositories for sharem
Users that are interested in sharem are comparing it to the libraries listed below
Sorting:
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆202Updated 3 months ago
- Important notes and topics on my journey towards mastering Windows Internals☆419Updated last year
- Exploring RPC interfaces on Windows☆343Updated last year
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆422Updated last month
- Collect Windows telemetry for Maldev☆449Updated 2 months ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆798Updated last year
- Operating System Design Review: A systematic analysis of modern systems architecture☆336Updated this week
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆167Updated last year
- Vulnerable driver research tool, result and exploit PoCs☆225Updated 2 years ago
- Sysmon-Like research tool for ETW☆381Updated 3 years ago
- PoCs for Kernelmode rootkit techniques research.☆425Updated 2 months ago
- A tutorial on how to write a packer for Windows!☆302Updated 2 years ago
- Dynamic unpacker based on PE-sieve☆791Updated 4 months ago
- A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.ht…☆671Updated 3 years ago
- A Binary Genetic Traits Lexer Framework☆520Updated 5 months ago
- Assortment of hashing algorithms used in malware☆387Updated 2 months ago
- A small x64 library to load dll's into memory.☆454Updated 2 years ago
- Yet another variant of Process Hollowing☆425Updated 5 months ago
- ☆305Updated 4 years ago
- Tools and PoCs for Windows syscall investigation.☆367Updated last month
- PoC Implementation of a fully dynamic call stack spoofer☆886Updated last year
- Aims to identify sleeping beacons☆650Updated 3 weeks ago
- HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.☆716Updated 2 years ago
- Centralized resource for listing and organizing known injection techniques and POCs☆665Updated 3 weeks ago
- Extracted Yara rules from Windows Defender mpavbase and mpasbase☆484Updated 3 weeks ago
- A DTrace on Windows Reimplementation☆369Updated 3 months ago
- PoCs and tools for investigation of Windows process execution techniques☆954Updated this week
- Shoggoth: Asmjit Based Polymorphic Encryptor☆771Updated last year
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆483Updated this week
- Useful scripts for WinDbg using the debugger data model☆427Updated last year