PhrozenIO / PsyloDbg
User-friendly Microsoft Windows Debugger for Malware Analysts.
☆195Updated 2 years ago
Alternatives and similar repositories for PsyloDbg:
Users that are interested in PsyloDbg are comparing it to the libraries listed below
- Microsoft Windows DLL Export Browser (Enumerate Exports, COM Methods and Properties) with Advanced Search Features.☆214Updated 9 months ago
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆119Updated last year
- Comparing, discussing, and bypassing various techniques for suspending and freezing processes on Windows.☆119Updated 3 years ago
- ☆112Updated last month
- Recon 2023 slides and code☆79Updated last year
- Advanced driver monitoring utility.☆207Updated 2 years ago
- Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows☆206Updated 2 years ago
- Tools and PoCs for Windows syscall investigation.☆359Updated 2 months ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆115Updated last year
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆114Updated 8 months ago
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆158Updated last month
- A dynamic unpacking tool☆133Updated last year
- Some random system tools for Windows☆111Updated 2 years ago
- An automatic unpacker and logger for DotNet Framework targeting files☆252Updated last year
- a PE Loader and Windows API tracer. Useful in malware analysis.☆138Updated 2 years ago
- Kernel Exploits☆250Updated 3 years ago
- MalUnpack companion driver☆95Updated 9 months ago
- Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) …☆108Updated 3 years ago
- Patching "signtool.exe" to accept expired certificates for code-signing.☆276Updated 8 months ago
- ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detecti…☆299Updated last year
- Pascal Offsec repo for malware dev and red teaming 🚩☆178Updated last year
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆244Updated 2 years ago
- Virus Exchange (VX) - Collection of malware or assembly code used for "offensive" purposed.☆180Updated 3 years ago
- My notes while studying Windows exploitation☆186Updated last year
- Bypass Malware Time Delays☆100Updated 2 years ago
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆141Updated 2 years ago
- A helper utility for creating shellcodes. Cleans MASM file generated by MSVC, gives refactoring hints.☆172Updated 3 months ago
- Killing your preferred antimalware by abusing native symbolic links and NT paths.☆357Updated 3 years ago
- Small tool to convert beteween the PE alignments (raw and virtual).☆86Updated 2 years ago
- Advanced static analysis tool☆88Updated last month