JPCERTCC / etw-scan
ETW forensic tool for Volatility3 plugin
☆11Updated 4 months ago
Alternatives and similar repositories for etw-scan:
Users that are interested in etw-scan are comparing it to the libraries listed below
- ☆22Updated 5 months ago
- Collection of generic YARA rules☆15Updated 9 months ago
- ☆22Updated 10 months ago
- ☆34Updated 2 years ago
- ☆33Updated 3 years ago
- ☆25Updated 4 months ago
- Lazarus analysis tools and research report☆55Updated last year
- Surface Analysis System on Cloud☆19Updated last year
- Defeating Anti-Debugging Techniques for Malware Analysis☆13Updated 2 years ago
- ☆22Updated last year
- Collection of tips, tools, arsenal and techniques I've learned during RE and other CyberSecStuff☆54Updated last month
- Identifies metadata of .NET binary files.☆21Updated 11 months ago
- Imphash-like calculation on Golang binaries☆49Updated 2 years ago
- Modular malware analysis artifact collection and correlation framework☆53Updated 11 months ago
- Unpacking and decryption tools for the Emotet malware☆46Updated 3 years ago
- ☆14Updated 10 months ago
- Progress of learning kernel development☆14Updated 2 years ago
- Converts exported results of CAPA tool from .json format to another formats supporting by different tools.☆22Updated 3 years ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated last year
- Extension functionality for the NightHawk operator client☆27Updated last year
- ☆12Updated 2 years ago
- A small tool to unmap PE memory dumps.☆11Updated last year
- Linux #rootkit and #malware revealer☆24Updated 7 months ago
- ☆23Updated last year
- Writing Your Own Ticket to the Cloud Like APT: A Deep-dive to AD FS Attacks, Detections, and Mitigations☆12Updated 2 years ago
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆26Updated last month
- Malware Analysis tools☆25Updated 6 months ago
- ☆24Updated 5 years ago
- Tools for offensive security of NetBackup infrastructures☆39Updated last year
- Rapidly building a Windows 10 system to use for dynamic malware analysis (sandbox), sending data to Elastic Cloud.☆48Updated last year