PhrozenIO / DLest
Microsoft Windows DLL Export Browser (Enumerate Exports, COM Methods and Properties) with Advanced Search Features.
☆197Updated 8 months ago
Alternatives and similar repositories for DLest:
Users that are interested in DLest are comparing it to the libraries listed below
- User-friendly Microsoft Windows Debugger for Malware Analysts.☆193Updated 2 years ago
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆330Updated 3 weeks ago
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- A POC to disable TamperProtection and other Defender / MDE components☆197Updated 8 months ago
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆152Updated last month
- Patching "signtool.exe" to accept expired certificates for code-signing.☆273Updated 6 months ago
- PowerRunAsSystem is a PowerShell script, also available as an installable module through the PowerShell Gallery, designed to impersonate …☆256Updated 4 months ago
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆286Updated last year
- Advanced static analysis tool☆87Updated 2 months ago
- A collection of tools, scripts and personal research☆125Updated 7 months ago
- ☆206Updated 2 weeks ago
- A list of useful tools for Malware Analysis (will be updated regularly)☆136Updated 5 months ago
- ☆154Updated 8 months ago
- A collection of small scripts and tools for deobfuscation and malware analysis.☆66Updated last year
- A C# based tool for analysing malicious OneNote documents☆110Updated last year
- http://moaistory.blogspot.com/2018/10/winsearchdbanalyzer.html☆121Updated 6 months ago
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆203Updated last year
- ☆199Updated 3 months ago
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆333Updated this week
- Microsoft Signed PowerShell scripts☆214Updated last year
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆132Updated last year
- Python tool to check rootkits in Windows kernel☆190Updated 2 weeks ago
- ☆111Updated 2 months ago
- Somes tools and scripts☆144Updated 3 years ago
- ☆112Updated last year
- RPC Monitor tool based on Event Tracing for Windows☆337Updated 5 months ago
- A dynamic unpacking tool☆132Updated last year
- Dump quarantined files from Windows Defender☆60Updated 2 years ago
- Analyse your malware to surgically obfuscate it☆450Updated 3 weeks ago
- Automated DLL Sideloading Tool With EDR Evasion Capabilities☆470Updated last year