IDA Pro plugin for recognizing known hashes of API function names
☆83May 12, 2022Updated 3 years ago
Alternatives and similar repositories for Apihashes
Users that are interested in Apihashes are comparing it to the libraries listed below
Sorting:
- Currently proof-of-concept☆17Dec 17, 2021Updated 4 years ago
- MalUnpack companion driver☆99Jun 17, 2024Updated last year
- Generates YARA rules to detect malware using API hashing☆17Mar 16, 2021Updated 4 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆119Apr 8, 2023Updated 2 years ago
- .NET deobfuscator and unpacker (with a control flow unflattener for DoubleZero added).☆29Jun 14, 2022Updated 3 years ago
- IDAPatternSearch adds a capability of finding functions according to bit-patterns into the well-known IDA Pro disassembler based on Ghidr…☆66Sep 14, 2021Updated 4 years ago
- Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)☆62Aug 11, 2023Updated 2 years ago
- A debugger backend for IDA Pro built on top of of Intel’s PIN framework☆35Feb 17, 2024Updated 2 years ago
- YARI is an interactive debugger for YARA Language.☆90Sep 10, 2025Updated 5 months ago
- Low budget VirusTotal Intelligence Cosplay☆20Jan 6, 2022Updated 4 years ago
- Các IDA Flirt signatures HTC tạo☆20Oct 21, 2024Updated last year
- Fuzzy search tool for IDA Pro (Update)☆12Mar 18, 2024Updated last year
- Repository of tools, YARA rules, and code-snippets from Stairwell's research team.☆23Jan 31, 2024Updated 2 years ago
- Dynamic unpacker based on PE-sieve☆796Sep 13, 2025Updated 5 months ago
- Time Travel Debugging IDA plugin☆592Jun 27, 2024Updated last year
- A YARA rules repository continuously updated for monitoring the old and new threats from articles, incidents responses ...☆141Nov 19, 2023Updated 2 years ago
- Scans a list of raccoon servers from Tria.ge and extracts the config☆15Jun 5, 2023Updated 2 years ago
- Decoders for 7ev3n ransomware☆17Oct 24, 2016Updated 9 years ago
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Jul 9, 2023Updated 2 years ago
- My malware analysis code snippets☆28Jul 15, 2023Updated 2 years ago
- VBScript & VBA source-to-source deobfuscator with partial-evaluation☆80Aug 7, 2024Updated last year
- IDA-names automatically renames pseudocode windows with the current function name.☆61Dec 24, 2022Updated 3 years ago
- An IDA plugin for making pseudocode better.☆364Dec 10, 2022Updated 3 years ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆60Jan 18, 2023Updated 3 years ago
- Unofficial YARA IDA Pro plugin, along with an unparalleled crypto/hash/compression rule set based on Luigi Auriemma's signsrch signatures…☆83Oct 1, 2025Updated 4 months ago
- VinCSS Reverse Engineering, Malware Analysing Tools & Ultilities☆27Nov 26, 2021Updated 4 years ago
- ☆24Oct 30, 2024Updated last year
- Solarized Theme for IDA Pro 7.3 and above☆15Nov 28, 2024Updated last year
- Script to pull newly-registered domains and check for similarity against a provided word list.☆13Aug 2, 2020Updated 5 years ago
- A /proc/mem IDA loader to snapshot a running process☆169Jun 29, 2025Updated 7 months ago
- Binary Ninja plugin for exploring Structured Exception Handlers☆83Jun 6, 2024Updated last year
- ☆23May 23, 2024Updated last year
- The following repository contains a modified version of SUNBURST with cracekd hashes, comments and annotations.☆56Dec 23, 2020Updated 5 years ago
- Modified python version of Rolf Rolles' https://github.com/RolfRolles/HexRaysDeob to unflatten Emotet'S Control Flow Flattening☆27May 5, 2022Updated 3 years ago
- Analyses in IDA/Hex-Rays☆87Apr 6, 2023Updated 2 years ago
- VB Exe Parser is an IDA script written in Python. This script will help you to parse VB program internal structures. It can find: Event, …☆18Oct 7, 2016Updated 9 years ago
- Very loud vBulletin exploit☆14Aug 12, 2020Updated 5 years ago
- ☆66Jan 27, 2023Updated 3 years ago
- A Python parser for Rich Headers☆15Jun 2, 2015Updated 10 years ago