arcana-technologies / arcana.elfscan
ELF binary forensics tool for APT, virus, backdoor and rootkit detection
☆45Updated 3 months ago
Alternatives and similar repositories for arcana.elfscan:
Users that are interested in arcana.elfscan are comparing it to the libraries listed below
- Shiva is a programmable dynamic linker for loading ELF microprograms☆28Updated last year
- Binary exploitation by confusing the unwinder☆59Updated last year
- Slides, recordings and materials of my public presentations, talks and workshops.☆75Updated 4 months ago
- A custom ELF linker/loader for installing ET_REL binary patches at runtime☆156Updated this week
- Dynamic-Static binary instrumentation framework on top of GDB☆51Updated last year
- A BinaryNinja plugin for contextual gadget analysis and semantic/hueristic based querying.☆50Updated last week
- Slides and Material for "SymbolicExecutionDemystified" Presentation @ Insomni'Hack 2022☆100Updated 2 years ago
- Slides about HyperDbg☆30Updated 8 months ago
- This framework enables user to discover JOP gagdets and can automate building a complete JOP chain to bypass DEP. JOP ROCKET is the ultim…☆100Updated 5 months ago
- Kernel Read Write Execute☆84Updated 5 months ago
- ☆77Updated 4 months ago
- rp-bf: A library to bruteforce ROP gadgets by emulating a Windows user-mode crash-dump☆112Updated 9 months ago
- ☆59Updated 2 weeks ago
- Python bindings for BochsCPU☆35Updated this week
- Damn Vulenerable Kernel Module for kernel fuzzing☆55Updated 3 months ago
- Highly advanced Linux anti-exploitation and anti-tamper binary protector for ELF.☆156Updated 2 years ago
- Static binary instrumentation for windows kernel drivers, to use with winafl☆66Updated 2 weeks ago
- A fast execution trace symbolizer for Windows that runs on all major platforms and doesn't depend on any Microsoft libraries.☆90Updated 4 months ago
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆147Updated this week
- ☆66Updated 2 years ago
- WinDbg extension written in Rust to dump the CPU / memory state of a running VM☆113Updated 3 months ago
- Leveraging CVEs as North Stars in vulnerability discovery and comprehension.☆64Updated 10 months ago
- Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.0’s idalib☆107Updated this week
- Report and exploit of CVE-2023-36427☆89Updated last year
- This IDA plugin extends the functionality of the assembly and hex view. With this plugin, you can conveniently decode/decrypt/alter data …☆76Updated last month
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆68Updated 3 months ago
- ☆70Updated 2 months ago
- An example of hijacking the dynamic linker with a custom interpreter who loads and executes modular viruses☆62Updated 2 years ago
- ☆143Updated last year