ZPetricusic / defender_signature_parserLinks
Short Python script for parsing Defender VDM signature files.
☆9Updated 10 months ago
Alternatives and similar repositories for defender_signature_parser
Users that are interested in defender_signature_parser are comparing it to the libraries listed below
Sorting:
- Contains all the applications developed for the Second part of the 7th Edition of Windows Internals book☆112Updated last year
- Windows kernel PDB data parsed into YAML☆38Updated 9 months ago
- rpv-web is a browser based frontend for the rpv library☆26Updated 2 months ago
- Rule Engine for Dynamic Malware Analysis and Research☆25Updated 3 months ago
- ☆31Updated 5 months ago
- bypassing intel txt's tboot integrity checks via coreboot shim☆78Updated 4 months ago
- Report and exploit of CVE-2024-21305.☆36Updated last year
- Intel 64/Windows low-level experiments☆59Updated 3 weeks ago
- AppContainer tools for launching sandboxed win32 apps, changing ACL permissions and learning from ETW traces.☆22Updated 3 months ago
- ☆88Updated 6 months ago
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆36Updated last year
- A Binary Ninja plugin that uses bruteforced XFG hashes to recover precise function prototypes☆16Updated last year
- ☆19Updated 2 years ago
- Easy encrypt/decrypt data with TPM☆25Updated last year
- Deobfuscation library for PoisionPlug.SHADOW's ScatterBrain obfuscator☆64Updated 4 months ago
- A post-processing script for TinyTracer☆37Updated 2 years ago
- ☆15Updated last year
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆91Updated 2 months ago
- Research-focused hypervisor offering advanced tools for debugging, virtual machine introspection, and automation.☆37Updated last month
- call gates as stable comunication channel for NT x86 and Linux x86_64☆32Updated 2 years ago
- Modular and extensible library for Virtual Machine Introspection☆107Updated 2 months ago
- ☆71Updated 2 years ago
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆156Updated 5 months ago
- Research on obfuscated licensing APIs / CLIP service in the Windows kernel☆118Updated 2 years ago
- Find RSA primes in files☆20Updated 3 years ago
- PDB Rewriting Rust Library☆24Updated last year
- WinDbg installer/updater☆41Updated 2 years ago
- SPI flash read MitM attack PoC☆38Updated 3 years ago
- IFL - Interactive Functions List (plugin for Binary Ninja)☆24Updated last year
- WinDbg extension written in Rust to dump the CPU / memory state of a running VM☆119Updated 2 months ago