R3MRUM / loki-parse
A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security researchers who want to know what data is being exfiltrated to the C2, bot tracking, etc...
☆12Updated 2 years ago
Related projects: ⓘ
- This script is used for extracting DDE in docx and xlsx☆12Updated 6 years ago
- a modified version base on Tracecorn☆20Updated 4 years ago
- Shows command lines used by latest instances analyzed on Hybrid-Analysis☆43Updated 6 years ago
- A Maltego transform for VirusTotal Submitter Information☆30Updated 5 years ago
- Handy scripts to speed up malware analysis☆35Updated 11 months ago
- Collection of my Python Scripts☆41Updated 4 years ago
- A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics☆85Updated 6 years ago
- Various snippets created during malware analysis☆22Updated 6 years ago
- Volatility Framework plugin to detect various types of hooks as performed by banking Trojans☆40Updated 5 years ago
- TA505 unpacker Python 2.7☆45Updated 4 years ago
- Talk given at DerbyCon and RuxCon 2016☆22Updated 7 years ago
- IDA Pro plugin that rename functions on load, based on functionality☆19Updated 6 years ago
- Volatility Plugins☆21Updated 9 years ago
- ☆39Updated this week
- Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003☆20Updated 9 years ago
- An offensive Powershell console☆30Updated 8 years ago
- API functions for Malware Research☆35Updated 5 years ago
- ☆26Updated this week
- ☆61Updated this week
- Hansel - a simple but flexible search for IDA☆25Updated 5 years ago
- Mimikatz HashClash☆12Updated 9 years ago
- ☆15Updated 3 years ago
- ☆37Updated this week
- PIC code gen and loading☆13Updated 7 years ago
- PoC malware built by copy-paste☆24Updated 3 years ago
- ☆19Updated 7 years ago
- Work Fast With the pattern matching swiss knife for malware researchers.☆34Updated 8 years ago
- Resolves DLL API entrypoints for a process w/ remote query capabilities.☆55Updated 7 years ago