Neo23x0 / yarGen-GoLinks
A YARA rule generator
☆61Updated this week
Alternatives and similar repositories for yarGen-Go
Users that are interested in yarGen-Go are comparing it to the libraries listed below
Sorting:
- This Python-based GUI application allows you to track the latest security vulnerabilities (CVEs) using the☆41Updated 10 months ago
- Malware Analysis tools☆26Updated last year
- Keklick - C2 Hunting, Reporting and Visualization Tool☆63Updated 6 months ago
- A curated collection of Living off the Land (LotL) attack demonstrations where trusted binaries go rogue, because if it didn’t launch cal…☆34Updated last month
- Make an Linux Kernel rootkit visible again.☆59Updated 11 months ago
- ☆35Updated 3 weeks ago
- ☆18Updated last year
- Script to chain search parameters for MalwareBazaar☆12Updated last year
- ☆59Updated 2 months ago
- Detonate malware on VMs and get logs & detection status☆76Updated 2 weeks ago
- IDA Python scripts☆40Updated 10 months ago
- Tool that can be used to trim useless things from a PE file such as the things a file pumper would add.☆29Updated 10 months ago
- ☆27Updated last year
- A C++ tool for process memory scanning & suspicious telemetry generation that attempts to detect a number of malicious techniques used by…☆85Updated last year
- AI-based implant feature☆25Updated 9 months ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated 2 years ago
- Configuration Extractors for Malware☆123Updated 9 months ago
- ROPDump is a command-line tool designed to analyze binary executables for potential Return-Oriented Programming (ROP) gadgets, buffer ove…☆87Updated last year
- PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via …☆85Updated 2 weeks ago
- A Repository to Track Anti-Forensic Techniques☆118Updated 2 years ago
- A tool to interact with Windows drivers to perform a raw disk read and parse out target files without calling standard Windows file APIs☆105Updated 5 months ago
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆131Updated 9 months ago
- Covert data exfiltration via DNS☆51Updated last year
- ☆58Updated 7 months ago
- Exfiltrate data over audio output from remote desktop sessions - Covert channel PoC☆64Updated last year
- SRE - Dissecting Malware for Static Analysis & the Complete Command-line Tool☆57Updated last year
- Docker container for running CobaltStrike 4.10☆38Updated last year
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆39Updated 11 months ago
- some leaked src code for known and unknown malwares☆23Updated 5 months ago
- Golang bindings for PE-sieve☆42Updated 2 years ago