NtQuerySystemInformation / Malware-RE-papers
Here are some of my malware reversing papers that I will be publishing
☆31Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for Malware-RE-papers
- A small tool to unmap PE memory dumps.☆11Updated last year
- ☆25Updated 3 weeks ago
- ☆26Updated 3 weeks ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- Small visualizator for PE files☆67Updated last year
- Invoke-DetectItEasy is a wrapper for excelent tool called Detect-It-Easy. This PS module is very useful for Threat Hunting and Forensics.☆23Updated 2 years ago
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆32Updated last year
- Winbindex bot to pull in binaries for specific releases☆46Updated last year
- ☆14Updated 2 years ago
- Python 3 - Manipulation and conversation with different data type (Bytes operations)☆27Updated 2 years ago
- ☆28Updated 2 years ago
- ☆22Updated 5 months ago
- SPI flash read MitM attack PoC☆36Updated 2 years ago
- An injector that use PT_LOAD technique☆11Updated last year
- Progress of learning kernel development☆14Updated 2 years ago
- ☆12Updated last year
- .NET deobfuscator and unpacker (with a control flow unflattener for DoubleZero added).☆28Updated 2 years ago
- "An Introduction to Windows Exploit Development" is an open sourced, free Windows exploit development course I created for the Southeast …☆39Updated 4 years ago
- A post-processing script for TinyTracer☆37Updated last year
- Slides from various conference talks☆36Updated last year
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Updated last year
- ☆18Updated 4 years ago
- ☆18Updated last year
- call gates as stable comunication channel for NT x86 and Linux x86_64☆30Updated last year
- ☆10Updated 3 years ago
- ☆18Updated last year
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆24Updated last year
- Example for PagedOut!☆24Updated 5 years ago
- Recreating and reviewing the Windows persistence methods☆39Updated 3 years ago