Cisco-Talos / Nim-IDA-FLIRT-Generator
Nim-IDA-FLIRT-Generator
☆14Updated last year
Alternatives and similar repositories for Nim-IDA-FLIRT-Generator:
Users that are interested in Nim-IDA-FLIRT-Generator are comparing it to the libraries listed below
- Parse .NET executable files.☆76Updated last month
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆59Updated 7 months ago
- ☆31Updated 2 years ago
- ☆142Updated last year
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year
- Go fastcall analysis for ida decompiler☆31Updated last month
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆132Updated 7 months ago
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆33Updated last year
- Binary Ninja plugin for exploring Structured Exception Handlers☆81Updated 9 months ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆70Updated 11 months ago
- A collection of tools, source code, and papers researching Windows' implementation of CET.☆81Updated 4 years ago
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆151Updated last year
- VinCSS Reverse Engineering, Malware Analysing Tools & Ultilities☆27Updated 3 years ago
- A Python script to download PDB files associated with a Portable Executable (PE)☆120Updated last month
- MalUnpack companion driver☆95Updated 9 months ago
- Set of plugins and library for dynamic pdb generation and synchronisation☆38Updated 10 months ago
- Different tools for Microsoft Hyper-V researching☆49Updated 9 months ago
- anti-ransomware file-system filter☆57Updated 6 months ago
- Collection of obfuscation, tamper-proofing, and watermarking algorithms targeting LLVM IR.☆71Updated 5 years ago
- IOCTLpus can be used to make DeviceIoControl requests with arbitrary inputs (with functionality somewhat similar to Burp Repeater).☆88Updated 3 years ago
- This repository contains an IDA processor for loading and disassembling compiled yara rules.☆40Updated 2 months ago
- An IDA plugin which demangles Rust function names☆32Updated last year
- clone of armadillo patched for windows☆47Updated 5 months ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆70Updated last year
- Report and exploit of CVE-2023-36427☆91Updated last year
- devirtualization vmprotect☆62Updated 2 years ago
- Contains all the applications developed for the Second part of the 7th Edition of Windows Internals book☆107Updated 9 months ago
- IDA plugin for quickly copying disassembly as encoded hex bytes☆60Updated 3 years ago
- arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system☆56Updated 3 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆114Updated 8 months ago