airbus-cert / dnYaraLinks
A multi-platform .Net wrapper library for the native Yara library.
☆38Updated 2 years ago
Alternatives and similar repositories for dnYara
Users that are interested in dnYara are comparing it to the libraries listed below
Sorting:
- ☆219Updated 7 years ago
- Full featured, offline Registry parser in C#☆232Updated last month
- Parses the WMI object database....looking for persistence☆33Updated 5 years ago
- A repository that maps API calls to Sysmon Event ID's.☆122Updated 2 years ago
- Log newly created WMI consumers and processes to the Windows Application event log☆124Updated 7 years ago
- Extract common Windows artifacts from source images and VSCs☆65Updated 4 years ago
- Yet another registry parser☆134Updated 3 years ago
- Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files☆119Updated last year
- A modern Python-3-based alternative to RegRipper☆196Updated 5 months ago
- Python bindings for https://github.com/omerbenamram/evtx/☆51Updated 6 months ago
- Reconstruct process trees from event logs☆147Updated 5 years ago
- Invoke-LiveResponse☆148Updated 3 years ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆115Updated 7 months ago
- "Evolving AppCompat/AmCache data analysis beyond grep"☆205Updated 3 years ago
- A rewrite of mactime, a bodyfile reader☆40Updated last year
- Command line access to the Registry☆154Updated this week
- Pure Python parser for Application Compatibility Shim Databases (.sdb files)☆108Updated 4 years ago
- Process Spawn Control is a Powershell tool which aims to help in the behavioral (process) analysis of malware. PsC suspends newly launche…☆264Updated 3 years ago
- .NET wrapper for libyara built in C++ CLI used to easily incorporate yara into .NET projects☆57Updated last year
- A better strings utility!☆138Updated last week
- A mapping of used malware names to commonly known family names☆62Updated 2 years ago
- c2 traffic☆189Updated 2 years ago
- Research indicators and detection rules☆66Updated last year
- Parser for Windows PowerShell script block logs☆99Updated last year
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10☆122Updated 7 months ago
- Lazy Office Analyzer☆122Updated 8 years ago
- VSCode extension for the YARA pattern matching language☆64Updated last year
- Tool suite for inspecting NTFS artifacts.☆224Updated last year
- A VBA parser and emulation engine to analyze malicious macros.☆96Updated 3 weeks ago
- Lnk file parser☆88Updated 3 months ago