Velocidex / go-yara
Go bindings for YARA
☆14Updated last year
Alternatives and similar repositories for go-yara
Users that are interested in go-yara are comparing it to the libraries listed below
Sorting:
- A collection of shellcode hashes☆17Updated 6 years ago
- A Portable Executable parser for Golang☆47Updated 4 months ago
- ssdeep cluster analysis for malware files☆30Updated 4 years ago
- RPC Monitor based on The ETW Microsoft-Windows-Rpc provider☆24Updated 5 years ago
- YaraSploit is a collection of Yara rules generated from Metasploit framework shellcodes.☆44Updated last year
- Golang parser for OLE files☆31Updated 2 months ago
- go-atomicredteam is a Golang application to execute tests as defined in the atomics folder of Red Canary's Atomic Red Team project (https…☆49Updated 2 years ago
- Simplified go-cat agent for caldera☆10Updated last year
- Malice Windows Defender AntiVirus Plugin☆38Updated 2 years ago
- Telsy CTI Research Team☆57Updated 4 years ago
- Repository of Yara rules created by the Stratosphere team☆26Updated 3 years ago
- The plan is to have a replacement for psexec☆31Updated 6 years ago
- Is this IP a C2 server?☆28Updated 5 years ago
- Static configuration extractor for the Karton framework☆10Updated 3 months ago
- PE file mapping and manipulation package.☆36Updated 3 years ago
- Dynamic PowerShell Analysis Framework Based Upon PowerShell Debugging Functionality☆83Updated 2 years ago
- Golang based web service to scan files with yara rules☆27Updated 7 years ago
- Tool to decrypt the configuration of NanoCore and dump all used plugins☆10Updated 4 years ago
- Windows Event Log Knowledge Base☆24Updated 6 months ago
- Experiments on the Windows Internals☆30Updated 5 years ago
- A simple provider to analyse what gets passed into Microsoft's Anti-Malware Scan Interface☆16Updated 5 years ago
- The code in this repository which function is to extract the shellcode from the maldoc.☆10Updated last year
- A golang implementation of a prefetch parser.☆19Updated 8 months ago
- Maco - Malware config extractor framework☆34Updated 2 months ago
- Yapscan is a YAra based Process SCANner, aimed at giving more control about what to scan and giving detailed reports on matches.☆61Updated last year
- IoC's, PCRE's, YARA's etc☆24Updated last month
- Inject unsigned DLL into Protected Process Light (PPL)☆21Updated this week
- Basic multi platform meterpreter loader module.☆15Updated 4 years ago
- Specialized tool to dump Position Independent Code.☆22Updated 4 years ago
- Collect autorun records from running system☆61Updated 3 years ago