NavyTitanium / Fake-Sandbox-ArtifactsLinks
This script allows you to create various artifacts on a bare-metal Windows computer in an attempt to trick malwares that looks for VM or analysis tools
☆286Updated last year
Alternatives and similar repositories for Fake-Sandbox-Artifacts
Users that are interested in Fake-Sandbox-Artifacts are comparing it to the libraries listed below
Sorting:
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆390Updated 5 months ago
- Encyclopedia for Executables☆463Updated 4 years ago
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆417Updated 10 months ago
- ☆151Updated last year
- A wireshark plugin to instrument ETW☆575Updated 3 years ago
- Dynamic unpacker based on PE-sieve☆786Updated 3 months ago
- A tool designed to make physical devices detectable by malware and make system look like virtual machine.☆396Updated 5 years ago
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆584Updated last year
- Detection in the form of Yara, Snort and ClamAV signatures.☆242Updated last year
- Deobfuscate batch scripts obfuscated using string substitution and escape character techniques.☆165Updated 3 years ago
- A guide on how to write fast and memory friendly YARA rules☆159Updated 10 months ago
- A GUI and CLI tool for removing bloat from executables☆435Updated 5 months ago
- Sysmon EDR POC Build within Powershell to prove ability.☆225Updated 4 years ago
- Evasions encyclopedia gathers methods used by malware to evade detection when run in virtualized environment. Methods are grouped into ca…☆435Updated last year
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆183Updated 2 months ago
- $MFT directory tree reconstruction & FILE record info☆321Updated last year
- Collection of private Yara rules.☆374Updated this week
- Windows x64 handcrafted token stealing kernel-mode shellcode☆510Updated last year
- Immediate Virus Infection Counter Measures☆63Updated 4 years ago
- ☆513Updated 2 years ago
- InviZzzible is a tool for assessment of your virtual environments in an easy and reliable way. It contains the most recent and up to date…☆576Updated 3 years ago
- Lnk Explorer Command line edition!!☆331Updated 11 months ago
- A golang CLI tool to download malware from a variety of sources.☆151Updated 5 months ago
- Living Off The Land Drivers☆1,348Updated last week
- Parses $MFT from NTFS file systems☆281Updated 7 months ago
- Malduck is your ducky companion in malware analysis journeys☆347Updated 5 months ago
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆660Updated 2 weeks ago
- Live hunting of code injection techniques☆383Updated 6 years ago
- The multi-platform memory acquisition tool.☆903Updated 2 months ago
- An NTFS/FAT parser for digital forensics & incident response☆218Updated last month