Use YARA rules on Time Travel Debugging traces
☆99Jul 11, 2023Updated 3 years ago
Alternatives and similar repositories for yara-ttd
Users that are interested in yara-ttd are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Tools for offensive security of NetBackup infrastructures☆48Jun 6, 2023Updated 3 years ago
- Extract data of TTD trace file to a minidump☆32Jul 31, 2023Updated 3 years ago
- $I30 INDX Carver☆18Jun 23, 2025Updated last year
- A program to read and modify the memory of other processes.☆20May 19, 2023Updated 3 years ago
- VBScript & VBA source-to-source deobfuscator with partial-evaluation☆80Aug 7, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Automatically generate AV byte signatures from sets of similar binaries.☆288May 4, 2026Updated 5 months ago
- This tool calculates tricky canonical huffman histogram for CVE-2023-4863.☆25Dec 20, 2023Updated 2 years ago
- ☆58Oct 12, 2024Updated last year
- Bindings for Microsoft WinDBG TTD☆243Aug 5, 2023Updated 3 years ago
- Powershell/Javascript deobfuscator based on tree-sitter☆102Aug 19, 2026Updated last month
- Python tool to check rootkits in Windows kernel☆211Aug 20, 2025Updated last year
- Automation script to download JSON MISP files from a SFTP server and import them via API to a MISP instance.☆15May 12, 2023Updated 3 years ago
- ☆88Feb 12, 2025Updated last year
- Time Travel Debugging IDA plugin☆595Jun 27, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Windows Kernel Mode PCRE☆10Feb 4, 2015Updated 11 years ago
- ☆21Oct 4, 2015Updated 11 years ago
- Official VirusTotal plugin for IDA Pro☆180Sep 14, 2026Updated 3 weeks ago
- PoC compilation of libyara into WASM, for potential future CyberChef integration☆14Sep 18, 2022Updated 4 years ago
- Rust binding for Keystone assembler framework☆11Dec 9, 2018Updated 7 years ago
- Lightweight WINAPI tracing with Pin☆26Aug 22, 2019Updated 7 years ago
- Monitor ETW events for Windows process mitigation policies, with stack traces☆30Oct 7, 2022Updated 4 years ago
- 一款linux下的安全产品目的是满足个人安全需求有SSH爆破防护和SYN攻击扫描防护功能,基于netfilter,☆23Dec 2, 2023Updated 2 years ago
- A python library for generate ida pro files (*.idb/*.i64) in batch mode & compare executable files use bindiff in batch mode.☆33Jul 9, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Scanner for CVE-2024-4040☆55May 17, 2024Updated 2 years ago
- 关于intel和amd指令行为不一样这件事☆57Apr 15, 2022Updated 4 years ago
- 基于UC的启发式杀毒引擎[还没做完]☆37Mar 28, 2021Updated 5 years ago
- ☆17Jun 30, 2020Updated 6 years ago
- ☆23Dec 15, 2022Updated 3 years ago
- ☆10Sep 11, 2021Updated 5 years ago
- ☆17Apr 4, 2019Updated 7 years ago
- The hidden mstsc recorder player☆27Mar 9, 2020Updated 6 years ago
- POC for CVE-2023-29360☆11Aug 31, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Blogpost about optimizing binary-only fuzzing with AFL++☆69Oct 7, 2023Updated 3 years ago
- Suricata rules to detect Winnti communication☆16Mar 5, 2018Updated 8 years ago
- An eBPF detection program for CVE-2022-0847☆29Jul 5, 2022Updated 4 years ago
- IDA Pro plugin for recognizing known hashes of API function names☆87May 12, 2022Updated 4 years ago
- machofile is a module to parse Mach-O binary files☆99Feb 10, 2026Updated 7 months ago
- System Call Integrity Layer - experimental security research☆28Apr 14, 2026Updated 5 months ago
- A Rust crate for parsing Windows user minidumps.☆43May 13, 2026Updated 4 months ago