Velocidex / go-yara
Go bindings for YARA
☆14Updated last year
Alternatives and similar repositories for go-yara:
Users that are interested in go-yara are comparing it to the libraries listed below
- Simplified go-cat agent for caldera☆10Updated last year
- Yapscan is a YAra based Process SCANner, aimed at giving more control about what to scan and giving detailed reports on matches.☆61Updated last year
- A collection of shellcode hashes☆17Updated 6 years ago
- Golang parser for OLE files☆31Updated last week
- ssdeep cluster analysis for malware files☆31Updated 4 years ago
- PE file mapping and manipulation package.☆36Updated 2 years ago
- RPC Monitor based on The ETW Microsoft-Windows-Rpc provider☆24Updated 4 years ago
- go-atomicredteam is a Golang application to execute tests as defined in the atomics folder of Red Canary's Atomic Red Team project (https…☆49Updated 2 years ago
- Basic multi platform meterpreter loader module.☆15Updated 4 years ago
- Dynamic PowerShell Analysis Framework Based Upon PowerShell Debugging Functionality☆83Updated 2 years ago
- Malice Windows Defender AntiVirus Plugin☆38Updated 2 years ago
- A Portable Executable parser for Golang☆47Updated 2 months ago
- Inject unsigned DLL into Protected Process Light (PPL)☆21Updated 3 months ago
- Lists of AMSI triggers (VBA, JScript / VBScript)☆33Updated 5 years ago
- Telsy CTI Research Team☆57Updated 4 years ago
- The plan is to have a replacement for psexec☆31Updated 6 years ago
- Is this IP a C2 server?☆28Updated 4 years ago
- A ready-made template for a project based on libpeconv.☆45Updated 3 weeks ago
- ETWNetMonv3 is simple C# code for Monitoring TCP Network Connection via ETW & ETWProcessMon/2 is for Monitoring Process/Thread/Memory/Ima…☆39Updated last year
- Binary to shellcode from an object/executable format 32 & 64-bit PE , ELF☆71Updated 4 years ago
- ☆49Updated 4 years ago
- The code in this repository which function is to extract the shellcode from the maldoc.☆10Updated last year
- Golang based web service to scan files with yara rules☆27Updated 7 years ago
- Windows API/constants, identity, and WinHTTP/WinINet for Go.☆18Updated last month
- Files for http://deniable.org/windows/windows-callbacks☆24Updated 4 years ago
- Go library to allow native inline hooking in windows at runtime☆13Updated last year
- QuasarRAT analysis tools and research report☆27Updated last year
- Collect autorun records from running system☆61Updated 3 years ago
- An command-line RPC method enumerator, born out of RPCView's awesomeness☆103Updated 5 years ago
- IBM RedCON 2020 - Throwing an AquaWrench into the Kernel☆44Updated 4 years ago