Maff1t / InjectionTracer
PINTool to help analyzing malware that uses process injection
☆14Updated 3 years ago
Alternatives and similar repositories for InjectionTracer:
Users that are interested in InjectionTracer are comparing it to the libraries listed below
- Process Injection without R/W target memory and without creating a remote thread☆19Updated 2 years ago
- ☆68Updated last year
- A small utility to deal with malware embedded hashes.☆49Updated last year
- Recreating and reviewing the Windows persistence methods☆37Updated 3 years ago
- Evasion Escaper is a project aimed at evading the checks that malicious software performs to detect if it's running in a virtual environm…☆99Updated last year
- IDA Pro plugin to aid with the analysis of native IIS modules☆17Updated 5 months ago
- ☆34Updated 2 years ago
- Golang bindings for PE-sieve☆42Updated last year
- Embed an executable as a PE resource, drops and launches it in runtime.☆57Updated 3 years ago
- Malware Muncher is a proof-of-concept Python script that utilizes the Frida framework for binary instrumentation and API hooking, enablin…☆43Updated last year
- One Click Tool to Scan All the Enabled Protection of current Windows NT Kernel☆43Updated last year
- OFFZONE 2024 Malware Persistence workshop☆17Updated last month
- Sentello is python script that simulates the anti-evasion and anti-analysis techniques used by malware.☆72Updated 3 years ago
- ☆22Updated 8 months ago
- Small visualizator for PE files☆67Updated last year
- ☆25Updated 2 months ago
- Malware AV evasion via disable Windows Defender (Registry). C++☆35Updated 2 years ago
- An injector that use PT_LOAD technique☆12Updated 2 years ago
- NT AUTHORITY\SYSTEM☆37Updated 4 years ago
- Standalone Metasploit-like XOR encoder for shellcode☆46Updated 8 months ago
- Get-PDInvokeImports is tool (PowerShell module) which is able to perform automatic detection of P/Invoke, Dynamic P/Invoke and D/Invoke u…☆53Updated 2 years ago
- A attempt at replicating BLACKLOTUS capabilities, whilst not acting as a direct mimic.☆87Updated last year
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆115Updated 6 months ago
- (Sim)ulate (Ba)zar Loader☆29Updated 4 years ago
- ☆28Updated 2 years ago
- Windows (ShadowMove) Socket Duplication☆80Updated 4 years ago
- Collection of source code for Polymorphic, Metamorphic, and Permutation Engines used in Malware☆25Updated 5 years ago
- A multi-staged malware that contains a kernel mode rootkit and a remote system shell.☆71Updated 3 years ago
- 2022 Updated Kernelmode-Code☆31Updated 10 months ago
- A Bumblebee-inspired Crypter☆80Updated 2 years ago