YoavLevi / IAT-Tracer
An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (.tag) files.
☆114Updated 8 months ago
Alternatives and similar repositories for IAT-Tracer:
Users that are interested in IAT-Tracer are comparing it to the libraries listed below
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆115Updated last year
- ☆111Updated last month
- Evasion Escaper is a project aimed at evading the checks that malicious software performs to detect if it's running in a virtual environm…☆105Updated last month
- Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider☆169Updated 2 years ago
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆73Updated last year
- Walks the CFG bitmap to find previously executable but currently hidden shellcode regions☆111Updated last year
- VBScript & VBA source-to-source deobfuscator with partial-evaluation☆75Updated 7 months ago
- ☆70Updated 2 years ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆46Updated this week
- A Poc on blocking Procmon from monitoring network events☆100Updated 2 years ago
- Recon 2023 slides and code☆79Updated last year
- Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)☆97Updated last year
- Writeups for CTF challenges☆30Updated last year
- Small PoC of using a Microsoft signed executable as a lolbin.☆136Updated 2 years ago
- ROP ROCKET is an advanced code-reuse attack framework, with extensive ROP chain generation capabilities, including for novel Windows Sysc…☆115Updated last week
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆70Updated 11 months ago
- Implementation of Advanced Module Stomping and Heap/Stack Encryption☆214Updated last year
- ☆73Updated 8 months ago
- ☆49Updated 5 months ago
- ETW based POC to identify direct and indirect syscalls☆180Updated last year
- ☆155Updated 10 months ago
- MalUnpack companion driver☆93Updated 9 months ago
- A tool for detecting manual/direct syscalls in x86 and x64 processes using Nirvana Hooks.☆108Updated 3 years ago
- ☆112Updated 2 years ago
- Finding Truth in the Shadows☆89Updated 2 years ago
- Winbindex bot to pull in binaries for specific releases☆46Updated last year
- ☆135Updated 2 years ago
- Experiment on reproducing Obfuscate & Sleep☆141Updated 4 years ago
- Minifilter Callback Patching Proof-of-Concept☆66Updated 2 years ago
- LPE exploit for CVE-2023-36802☆22Updated last year