NavyTitanium / Fake-Sandbox-ArtifactsLinks
This script allows you to create various artifacts on a bare-metal Windows computer in an attempt to trick malwares that looks for VM or analysis tools
☆288Updated last year
Alternatives and similar repositories for Fake-Sandbox-Artifacts
Users that are interested in Fake-Sandbox-Artifacts are comparing it to the libraries listed below
Sorting:
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆353Updated 4 months ago
- Deobfuscate batch scripts obfuscated using string substitution and escape character techniques.☆160Updated 3 years ago
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆406Updated 9 months ago
- Encyclopedia for Executables☆456Updated 3 years ago
- A wireshark plugin to instrument ETW☆574Updated 3 years ago
- Dynamic unpacker based on PE-sieve☆775Updated last month
- Immediate Virus Infection Counter Measures☆63Updated 4 years ago
- ☆150Updated last year
- $MFT directory tree reconstruction & FILE record info☆314Updated last year
- Lnk Explorer Command line edition!!☆329Updated 9 months ago
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆182Updated last month
- Windows Registry Knowledge Base☆186Updated 3 weeks ago
- A guide on how to write fast and memory friendly YARA rules☆157Updated 8 months ago
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆584Updated last year
- A tool designed to make physical devices detectable by malware and make system look like virtual machine.☆394Updated 5 years ago
- Windows x64 handcrafted token stealing kernel-mode shellcode☆509Updated last year
- Code snips and notes☆137Updated 3 years ago
- A golang CLI tool to download malware from a variety of sources.☆150Updated 4 months ago
- Collection of private Yara rules.☆372Updated last week
- A VBA parser and emulation engine to analyze malicious macros.☆96Updated 2 months ago
- InviZzzible is a tool for assessment of your virtual environments in an easy and reliable way. It contains the most recent and up to date…☆573Updated 3 years ago
- An NTFS/FAT parser for digital forensics & incident response☆213Updated last month
- Parses $MFT from NTFS file systems☆273Updated 5 months ago
- Sysmon EDR POC Build within Powershell to prove ability.☆226Updated 4 years ago
- Malduck is your ducky companion in malware analysis journeys☆346Updated 4 months ago
- Extract AutoIt scripts embedded in PE binaries☆209Updated last year
- Detection in the form of Yara, Snort and ClamAV signatures.☆238Updated last year
- A python library to parse OneNote (.one) files☆138Updated last year
- Windows Shortcut file (LNK) parser☆103Updated last month
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆204Updated this week