JPCERTCC / QuasarRAT-Analysis
QuasarRAT analysis tools and research report
☆25Updated last year
Alternatives and similar repositories for QuasarRAT-Analysis:
Users that are interested in QuasarRAT-Analysis are comparing it to the libraries listed below
- ☆34Updated 2 years ago
- Unpacking and decryption tools for the Emotet malware☆46Updated 3 years ago
- ☆22Updated last year
- A collection of Tools and Rules for decoding Brute Ratel C4 badgers☆62Updated 2 years ago
- A small utility to deal with malware embedded hashes.☆49Updated last year
- Links to malware-related YARA rules☆14Updated 2 years ago
- Specialized tool to dump Position Independent Code.☆21Updated 4 years ago
- The repository accompanying the Buer Emulation workshop☆23Updated 3 years ago
- ☆15Updated 3 years ago
- Tool to manage user privileges☆28Updated 5 years ago
- Scripts, Yara rules and other files developed during malware investigations☆25Updated 2 years ago
- Tool to decrypt the configuration of NanoCore and dump all used plugins☆11Updated 4 years ago
- Adapt practically persistence steadiness strategies working at Windows 10 utilized by sponsored nation-state threat actors, as Turla, Pro…☆20Updated 4 years ago
- ☆13Updated 11 months ago
- PoC that manipulates Windows file times using SetFileTime() API☆58Updated 5 years ago
- Tweettioc Splunk App☆20Updated 4 years ago
- ☆23Updated 4 years ago
- A library to parse, modify, and implement Malleable C2 profiles☆21Updated 5 years ago
- Scripts to aid analysis of files obfuscated with ScatterBee.☆17Updated 2 years ago
- This is a repository that is meant to hold detections for various process injection techniques.☆33Updated 4 years ago
- ProcDot Malware Sandbox☆22Updated last month
- Building ActiveDirectory Lab for practicing various attack vectors used during Red Team engagement.☆36Updated 4 years ago
- This is a group of tools that I was planning on releasing During Derbycon 2019 talk if it was accepted or with a blogpost if not.☆43Updated 3 years ago
- Create a Run registry key with direct system calls. Inspired by @Cneelis's Dumpert and SharpHide.☆74Updated 4 years ago
- Python3 script to generate a macro to launch a Mythic payload. Author: Cedric Owens☆45Updated 3 years ago
- open source malware analysis and research notes dump☆26Updated last year
- Modular malware analysis artifact collection and correlation framework☆53Updated 8 months ago
- Tracking APT IOCs☆25Updated 4 years ago
- Just another useless C2 occupying space in some HDD somewhere.☆20Updated last year
- Data from analysis of the custom sample from the chapter "Practical Analysis and Test"☆12Updated 4 years ago