SentineLabs / Memloader
Memory Loader Open Source Project by Sentinel-Labs.
☆20Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for Memloader
- UnpacMe IDA Byte Search☆26Updated last year
- ☆21Updated 3 years ago
- A collection of empty MSVC projects, compiled using various versions and configurations of Visual Studio.☆30Updated 5 months ago
- ☆28Updated 4 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆50Updated 2 years ago
- Resources for the workshop titled "Repacking the unpacker: Applying Time Travel Debugging to malware analysis", given at HackLu 2019☆39Updated 5 years ago
- Python 3 - Manipulation and conversation with different data type (Bytes operations)☆27Updated 2 years ago
- Scripts, Yara rules and other files developed during malware investigations☆24Updated 2 years ago
- IDA Python deobfuscation script for ConfuserEx binaries☆35Updated 2 years ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- ☆31Updated 2 years ago
- Clone running process with ZwCreateProcess☆58Updated 4 years ago
- WIP Emotet Control Flow Unflattening using miasm and radare2☆23Updated last year
- Go Lang Portable Executable Parser☆37Updated 3 years ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆57Updated 3 months ago
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- C# implementation to produce ROR-13 numeric hash for given function API name☆31Updated 5 years ago
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 3 years ago
- Yet another rule generator for Yara☆25Updated 4 years ago
- ☆66Updated last year
- ☆17Updated 2 years ago
- Command like tool to print mitigation flags for running processes in a memory dump☆44Updated 4 years ago
- Invoke-DetectItEasy is a wrapper for excelent tool called Detect-It-Easy. This PS module is very useful for Threat Hunting and Forensics.☆23Updated 2 years ago
- A set of small utilities, helpers for PIN tracers☆31Updated last year
- IDA Pro plugin for recognizing known hashes of API function names☆82Updated 2 years ago
- ☆19Updated 2 weeks ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆62Updated 7 months ago
- Windows API Hashes used in the malwares☆40Updated 9 years ago
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆32Updated last year
- PoC for hiding PE exports☆65Updated 3 years ago