FarghlyMal / Config-Extractors
☆27Updated 5 months ago
Alternatives and similar repositories for Config-Extractors:
Users that are interested in Config-Extractors are comparing it to the libraries listed below
- Malware Muncher is a proof-of-concept Python script that utilizes the Frida framework for binary instrumentation and API hooking, enablin…☆44Updated 2 years ago
- ☆18Updated last year
- Automatically spider the result set of a Censys/Shodan search and download all files where the file name or folder path matches a regex.☆27Updated 2 years ago
- MITRE TTPs derived from Conti's leaked playbooks from XSS.IS☆37Updated 3 years ago
- Malware Analysis tools☆26Updated 7 months ago
- Golang bindings for PE-sieve☆43Updated last year
- A proof-of-concept re-assembler for reverse VNC traffic.☆25Updated last year
- Get-PDInvokeImports is tool (PowerShell module) which is able to perform automatic detection of P/Invoke, Dynamic P/Invoke and D/Invoke u…☆54Updated 3 years ago
- ☆20Updated last year
- General malware analysis stuff☆36Updated 8 months ago
- Extension functionality for the NightHawk operator client☆27Updated last year
- ☆18Updated 3 months ago
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆82Updated last year
- ☆48Updated last year
- A full analysis report detailing as much as possible of a Malware or a Threat☆29Updated 10 months ago
- powershell script i wrote that can suspend an arbitrary process (with limits)☆20Updated 2 years ago
- ☆22Updated 11 months ago
- A PoC for achieving persistence via push notifications on Windows☆46Updated last year
- Emulates the VirusTotal "vt" YARA module for livehunt rule debugging/testing☆21Updated last year
- Repo containing my public talks☆23Updated last year
- quASAR: ASAR manipulation made easy☆37Updated 2 years ago
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆36Updated 2 months ago
- ☆59Updated last year
- WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.☆54Updated 3 years ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated last year
- Collection of my own detection rules☆20Updated last year
- IAT Unhooking proof-of-concept☆29Updated last year
- Lena's scripts/code/resources for malware analysis☆26Updated 10 months ago
- ☆38Updated 2 years ago
- A tool to exchange decryption keys for command and control (C2) beacons and implants through DNS records.☆39Updated 2 years ago