Matmaus / LnkParse3
Windows Shortcut file (LNK) parser
☆89Updated 3 weeks ago
Alternatives and similar repositories for LnkParse3:
Users that are interested in LnkParse3 are comparing it to the libraries listed below
- ☆105Updated last year
- Windows symbol tables for Volatility 3☆85Updated 10 months ago
- Repository of Yara Rules☆110Updated last month
- Dump quarantined files from Windows Defender☆63Updated 3 years ago
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆175Updated this week
- YARA rule analyzer to improve rule quality and performance☆99Updated last month
- Powershell script deobfuscation using AST in Python☆66Updated last year
- VBScript & VBA source-to-source deobfuscator with partial-evaluation☆76Updated 9 months ago
- Use YARA rules on Time Travel Debugging traces☆90Updated last year
- Elastic Security Labs releases☆63Updated last month
- ☆221Updated 3 months ago
- Windows Registry Knowledge Base☆173Updated 7 months ago
- ☆246Updated last year
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆114Updated 2 years ago
- Collection of rules created using YARA-Signator over Malpedia☆128Updated 6 months ago
- http://moaistory.blogspot.com/2018/10/winsearchdbanalyzer.html☆122Updated 9 months ago
- A C# based tool for analysing malicious OneNote documents☆113Updated 2 years ago
- PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs…☆184Updated last year
- ☆114Updated last week
- ☆19Updated 2 years ago
- Sysmon-Like research tool for ETW☆352Updated 2 years ago
- Rules shared by the community from 100 Days of YARA 2024☆85Updated 4 months ago
- Carve file metadata from NTFS index ($I30) attributes☆64Updated last year
- capemon: CAPE's monitor☆116Updated this week
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) …☆109Updated 4 years ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆68Updated last month
- $MFT directory tree reconstruction & FILE record info☆304Updated 7 months ago
- Volatility3 plugins developed and maintained by the community☆53Updated 2 years ago
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆209Updated 2 years ago