Malandrone / PowerDecodeLinks
PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs code dynamic analysis, extracting malware hosting URLs and checking http response.It can also detect if the malware attempts to inject shellcode into memory.
☆228Updated last year
Alternatives and similar repositories for PowerDecode
Users that are interested in PowerDecode are comparing it to the libraries listed below
Sorting:
- A ProcessMonitor visualization application written in rust.☆184Updated 2 years ago
- ☆213Updated last month
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆211Updated this week
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆250Updated 2 months ago
- Collection of Volatility2 profiles, generated against Linux kernels.☆54Updated 2 months ago
- A collection of tools, scripts and personal research☆154Updated last month
- Repository of Yara Rules☆138Updated this week
- RegRipper4.0☆79Updated last month
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆202Updated 4 months ago
- A curated list of ressources for Volatility 2 & 3☆13Updated last year
- A collection of tools and detections for the Sliver C2 Frameworj☆133Updated 2 years ago
- Volatility3 Linux profiles☆72Updated last month
- ☆250Updated 7 months ago
- ☆171Updated 2 years ago
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆225Updated 2 years ago
- Dump quarantined files from Windows Defender☆73Updated 3 years ago
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. T…☆143Updated last month
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆309Updated 2 years ago
- Memory acquisition for Linux that makes sense.☆217Updated 2 years ago
- ☆260Updated last year
- A repository for additional files related to the book Windows Security Internals with PowerShell from No Starch Press.☆216Updated 5 months ago
- Python tool to check rootkits in Windows kernel☆204Updated 5 months ago
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆167Updated last year
- Windows symbol tables for Volatility 3☆92Updated last year
- Collection of Linux and macOS Volatility3 Intermediate Symbol Files (ISF), suitable for memory analysis 🔍☆250Updated last month
- Extracted Yara rules from Windows Defender mpavbase and mpasbase☆486Updated 3 weeks ago
- ☆125Updated last year
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆476Updated 6 months ago
- ☆517Updated 2 years ago
- Elastic Security Labs releases☆84Updated last month