Proof-of-concept automated baremetal malware analysis framework.
☆14Sep 24, 2015Updated 10 years ago
Alternatives and similar repositories for nvmtrace
Users that are interested in nvmtrace are comparing it to the libraries listed below
Sorting:
- Windows 64-bits driver☆17Dec 1, 2017Updated 8 years ago
- A fuzzer setup to fuzz libc functions.☆16Aug 30, 2022Updated 3 years ago
- Utilities for the memory forensics framework☆22Jul 31, 2018Updated 7 years ago
- A blanket execution/min hash semantic hash tool for binary function identification☆18Apr 22, 2016Updated 9 years ago
- EDK II☆16Apr 30, 2024Updated last year
- Binarly SDK v1☆14Dec 18, 2016Updated 9 years ago
- Python command-line tool that uses nearest neighbor search methods for malware similarity analysis☆16Jan 29, 2019Updated 7 years ago
- A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and sec…☆13Dec 31, 2021Updated 4 years ago
- Extract, defang, resolve names and IPs from text☆23Jan 29, 2026Updated last month
- Command-line Interface for Binar.ly☆39Jan 13, 2017Updated 9 years ago
- Linux-KVM with rVMI extensions☆22Aug 28, 2017Updated 8 years ago
- Virtual machine introspection library based on libvmi - parts of this work have been funded by Deutsche Forschungsgemeinschaft (DFG) – pr…☆31Mar 3, 2022Updated 4 years ago
- A Binary Ninja plugin that uses bruteforced XFG hashes to recover precise function prototypes☆16Feb 7, 2024Updated 2 years ago
- ☆10Oct 22, 2017Updated 8 years ago
- Scripts for communication with Bunitu Trojan C&Cs☆19Oct 29, 2015Updated 10 years ago
- library to decode/parse zeus-like configuration files☆30Mar 19, 2018Updated 8 years ago
- Robust API monitoring system presented in the paper "Designing Robust API Monitoring Solutions" (IEEE TDSC)☆25Dec 8, 2021Updated 4 years ago
- Virtual Machine Introspection (VMI) for memory forensics and machine-learning.☆28Jun 2, 2025Updated 9 months ago
- CLI tool for testing Office documents with macros using MaliciousMacroBot☆12Dec 3, 2023Updated 2 years ago
- ☆28Aug 31, 2014Updated 11 years ago
- UnpacMe IDA Byte Search☆29Nov 20, 2023Updated 2 years ago
- Alcatraz project for Black Hat USA 2021☆78Aug 5, 2021Updated 4 years ago
- CertWatcher is a new take on monitoring for phishing sites. It is meant to be a set and forget service that will send you a daily report …☆10Oct 12, 2020Updated 5 years ago
- MoP - "Master of Puppets" - Advanced malware tracking framework☆84Feb 11, 2026Updated last month
- A feature-complete reference implementation of a modern Xen VMI debugger. ARCHIVED: Development continues at https://github.com/spencermi…☆78Nov 2, 2020Updated 5 years ago
- Linux kernel source tree patched with Hypervisor-Enforced Kernel Integrity☆13Nov 14, 2023Updated 2 years ago
- Investigation Planner for fast running analysis with predictable execution time. For example, static analysis.☆27Jun 2, 2019Updated 6 years ago
- ParrotNG is a tool capable of identifying Adobe Flex applications (SWF) vulnerable to CVE-2011-2461☆48Mar 19, 2015Updated 11 years ago
- Finds sensitive stuff in your git repository by specifying terms to look for☆31Feb 16, 2018Updated 8 years ago
- lite version of glib that only contains ghash, glist, gslist, gqueue, and gmem.☆13Feb 20, 2017Updated 9 years ago
- Sample staging & detonation utility to be used in combination with Cuckoo Sandbox.☆85Dec 5, 2023Updated 2 years ago
- Incident Response Scripts☆30Mar 1, 2020Updated 6 years ago
- Tool to decrypt the configuration of NanoCore and dump all used plugins☆12Dec 8, 2020Updated 5 years ago
- Metadefender Core (Metascan v.4 and v.3) analysis module for Viper malware analysis framework☆10Jan 6, 2021Updated 5 years ago
- Framework for in-VM test execution and monitoring, inspired by Sandsifter☆15Updated this week
- ☆19Dec 1, 2024Updated last year
- Demo of hooking NtCreateFile in Notepad on x64 Windows 10 using EasyHook library☆27Nov 20, 2017Updated 8 years ago
- This is a simple driver with x64 inline assembly☆55Jun 26, 2020Updated 5 years ago
- Simple IP enrichment service and API wrapping PyASN and MaxMind GeoIP.☆71Dec 8, 2022Updated 3 years ago