airbus-cert / yara-ttd
Use YARA rules on Time Travel Debugging traces
☆88Updated last year
Alternatives and similar repositories for yara-ttd:
Users that are interested in yara-ttd are comparing it to the libraries listed below
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆114Updated 9 months ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated last year
- ☆105Updated last year
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆114Updated 2 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆70Updated 11 months ago
- Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) …