ComodoSecurity / OpenEDRRules
☆12Updated 2 years ago
Alternatives and similar repositories for OpenEDRRules
Users that are interested in OpenEDRRules are comparing it to the libraries listed below
Sorting:
- This is a repository that is meant to hold detections for various process injection techniques.☆34Updated 5 years ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆54Updated this week
- Windows (ShadowMove) Socket Duplication☆83Updated 5 years ago
- The project will serve as a central repository for VMware Threat Analysis Unit (TAU) to share threat intelligence with the security commu…☆17Updated 2 years ago
- A simple provider to analyse what gets passed into Microsoft's Anti-Malware Scan Interface☆16Updated 5 years ago
- ssdeep cluster analysis for malware files☆30Updated 4 years ago
- ETWNetMonv3 is simple C# code for Monitoring TCP Network Connection via ETW & ETWProcessMon/2 is for Monitoring Process/Thread/Memory/Ima…☆39Updated last year
- ssdeep for python on windows☆16Updated 7 years ago
- Inject unsigned DLL into Protected Process Light (PPL)☆21Updated last week
- Unpacking and decryption tools for the Emotet malware☆46Updated 3 years ago
- Here is python script I wrote for deobfuscation APT32 sample.☆10Updated 3 years ago
- This project fully automates the process of analyzing and exploiting IoT malware to find live CnC servers.☆41Updated 9 months ago
- Windows API Hashes used in the malwares☆40Updated 9 years ago
- Code for BH21 talk: "Generating YARA Rules by Classifying Malicious Byte Sequences"☆17Updated 3 months ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆83Updated last year
- Open-source EDR kernel-component for system monitoring and DLL injection☆31Updated 4 years ago
- A collection of Tools and Rules for decoding Brute Ratel C4 badgers☆62Updated 2 years ago
- Dynamic PowerShell Analysis Framework Based Upon PowerShell Debugging Functionality☆83Updated 2 years ago
- Repository of Yara rules created by the Stratosphere team☆26Updated 3 years ago
- Symantec EDR Internals☆26Updated 3 years ago
- Telsy CTI Research Team☆57Updated 4 years ago
- ☆42Updated last year
- My scripts to deobfuscate APT32 malware☆26Updated 3 years ago
- Open Dataset of Cobalt Strike Beacon metadata (2018-2022)☆125Updated 3 years ago
- LILO based Pulse Secure appliance disk image decryptor☆13Updated last year
- ☆24Updated last year
- Powershell script deobfuscation using AST in Python☆66Updated last year
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆31Updated 4 years ago
- AVCLASS++: Yet Another Massive Malware Labeling Tool☆14Updated 5 years ago
- A small utility to deal with malware embedded hashes.☆51Updated last year