Malandrone / PowerDecodeLinks
PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs code dynamic analysis, extracting malware hosting URLs and checking http response.It can also detect if the malware attempts to inject shellcode into memory.
☆216Updated last year
Alternatives and similar repositories for PowerDecode
Users that are interested in PowerDecode are comparing it to the libraries listed below
Sorting:
- A ProcessMonitor visualization application written in rust.☆184Updated 2 years ago
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆203Updated last week
- ☆203Updated last year
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆198Updated last month
- Repository of Yara Rules☆123Updated last month
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆248Updated 7 months ago
- Dump quarantined files from Windows Defender☆67Updated 3 years ago
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆220Updated 2 years ago
- RegRipper4.0☆72Updated 2 months ago
- Collection of Volatility2 profiles, generated against Linux kernels.☆53Updated 2 months ago
- A collection of tools, scripts and personal research☆145Updated 2 months ago
- A collection of tools and detections for the Sliver C2 Frameworj☆131Updated 2 years ago
- Windows symbol tables for Volatility 3☆91Updated last year
- Memory acquisition for Linux that makes sense.☆211Updated last year
- ☆165Updated 2 years ago
- ☆244Updated 4 months ago
- Python tool to check rootkits in Windows kernel☆201Updated 2 months ago
- ☆254Updated last year
- Collection of Linux and macOS Volatility3 Intermediate Symbol Files (ISF), suitable for memory analysis 🔍☆221Updated last week
- A curated list of ressources for Volatility 2 & 3☆12Updated last year
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆165Updated last year
- ☆511Updated last year
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆682Updated last week
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. T…☆132Updated last week
- Elastic Security Labs releases☆81Updated last week
- IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&…☆367Updated 2 years ago
- Volatility3 Linux profiles☆59Updated last month
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆466Updated 4 months ago
- Windows Shortcut file (LNK) parser☆102Updated last month
- A collection of tools to interact with Microsoft Security Response Center API☆107Updated last year