Malandrone / PowerDecode
PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs code dynamic analysis, extracting malware hosting URLs and checking http response.It can also detect if the malware attempts to inject shellcode into memory.
☆180Updated 11 months ago
Alternatives and similar repositories for PowerDecode:
Users that are interested in PowerDecode are comparing it to the libraries listed below
- A collection of tools, scripts and personal research☆127Updated 2 weeks ago
- A collection of tools and detections for the Sliver C2 Frameworj☆122Updated last year
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆175Updated this week
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆237Updated 3 weeks ago
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- ☆201Updated 5 months ago
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆208Updated last year
- ☆157Updated last year
- Repository of Yara Rules☆110Updated last week
- ☆241Updated 11 months ago
- Aims to identify sleeping beacons☆585Updated 4 months ago
- Dump quarantined files from Windows Defender☆63Updated 3 years ago
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆158Updated 3 weeks ago
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆310Updated last year
- ☆298Updated 5 months ago
- ☆186Updated last year
- Python tool to check rootkits in Windows kernel☆196Updated last month
- Analyse your malware to surgically obfuscate it☆464Updated last month
- ☆217Updated 2 months ago
- ☆375Updated 2 years ago
- Extracted Yara rules from Windows Defender mpavbase and mpasbase☆395Updated last month
- Find potential DLL Sideloads on your windows computer☆200Updated 3 months ago
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆142Updated 9 months ago
- Extract C2 Traffic☆248Updated 4 months ago
- AV/EDR Lab environment setup references to help in Malware development☆374Updated 2 months ago
- A C# based tool for analysing malicious OneNote documents☆113Updated 2 years ago
- DPAPILAB Next Gen, script collection☆82Updated 2 years ago
- Automated DLL Sideloading Tool With EDR Evasion Capabilities☆469Updated last year
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆256Updated last year
- A repository that maps commonly used attacks using MSRPC protocols to ATT&CK☆323Updated last year