DissectMalware / yaradbg-frontend
☆37Updated 10 months ago
Related projects ⓘ
Alternatives and complementary repositories for yaradbg-frontend
- ☆24Updated 10 months ago
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆80Updated 9 months ago
- Powershell Linter☆46Updated 2 months ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated last year
- Repository of Yara Rules☆89Updated last month
- ☆98Updated 3 weeks ago
- General malware analysis stuff☆35Updated 2 months ago
- Small tool to play with IOCs caused by Imageload events☆38Updated last year
- Repo containing my public talks☆22Updated last year
- quASAR: ASAR manipulation made easy☆24Updated 2 years ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆72Updated 2 months ago
- ☆27Updated 3 months ago
- Malware Muncher is a proof-of-concept Python script that utilizes the Frida framework for binary instrumentation and API hooking, enablin…☆42Updated last year
- Golang bindings for PE-sieve☆40Updated last year
- ☆20Updated 11 months ago
- MITRE TTPs derived from Conti's leaked playbooks from XSS.IS☆35Updated 3 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆111Updated 4 months ago
- ☆22Updated 11 months ago
- Identifies metadata of .NET binary files.☆21Updated 7 months ago
- ☆68Updated last year
- ☆44Updated last year
- Windows API header file parsing tool to generate source code for Windows API hashing☆4Updated last year
- ☆68Updated 3 months ago
- Reverse Engineering and Debugging Malware☆30Updated last year
- Docker container for running CobaltStrike 4.10☆33Updated 2 months ago
- ☆49Updated last year
- IDA Python scripts☆28Updated 10 months ago
- Yara Rules for Modern Malware☆67Updated 8 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 4 months ago
- ☆76Updated this week