Velocidex / go-yara
Go bindings for YARA
☆14Updated 10 months ago
Alternatives and similar repositories for go-yara:
Users that are interested in go-yara are comparing it to the libraries listed below
- A collection of shellcode hashes☆17Updated 6 years ago
- ssdeep cluster analysis for malware files☆31Updated 4 years ago
- PE file mapping and manipulation package.☆36Updated 2 years ago
- A Portable Executable parser for Golang☆47Updated 3 weeks ago
- RPC Monitor based on The ETW Microsoft-Windows-Rpc provider☆24Updated 4 years ago
- Windows (ShadowMove) Socket Duplication☆80Updated 4 years ago
- Inject unsigned DLL into Protected Process Light (PPL)☆19Updated last month
- Golang parser for OLE files☆31Updated 7 months ago
- Golang wrapper for the Microsoft Antimalware Scan Interface (AMSI)☆11Updated 2 years ago
- Yapscan is a YAra based Process SCANner, aimed at giving more control about what to scan and giving detailed reports on matches.☆61Updated last year
- Experiments on the Windows Internals☆30Updated 5 years ago
- Malice Windows Defender AntiVirus Plugin☆38Updated last year
- Basic multi platform meterpreter loader module.☆15Updated 4 years ago
- Maintain Windows Persistence with an evil Netshell Helper DLL☆12Updated 6 years ago
- Bypass UAC by abusing the Windows Defender Firewall Control Panel, environment variables, and shell protocol handlers☆17Updated 3 years ago
- YaraSploit is a collection of Yara rules generated from Metasploit framework shellcodes.☆43Updated last year
- ETWNetMonv3 is simple C# code for Monitoring TCP Network Connection via ETW & ETWProcessMon/2 is for Monitoring Process/Thread/Memory/Ima…☆38Updated last year
- Open-source EDR kernel-component for system monitoring and DLL injection☆30Updated 4 years ago
- Files for http://deniable.org/windows/windows-callbacks☆24Updated 4 years ago
- go-atomicredteam is a Golang application to execute tests as defined in the atomics folder of Red Canary's Atomic Red Team project (https…☆48Updated last year
- A small utility to deal with malware embedded hashes.☆49Updated last year
- Package that provides different PE tricks to difficult the reverse engineering of your Windows applications.☆11Updated 4 years ago
- inject or convert shellcode to PE☆37Updated 5 years ago
- ☆33Updated 3 years ago
- defender_database☆17Updated last year
- The plan is to have a replacement for psexec☆30Updated 6 years ago
- Simple PoCs for utilizing Windows syscalls in Go☆15Updated 4 years ago
- Provides a multi-platform Graphical User Interface for hashlookup☆12Updated 6 months ago
- Source files for my posts☆15Updated last year
- Lists of AMSI triggers (VBA, JScript / VBScript)☆32Updated 5 years ago