ashemery / REDM
Reverse Engineering and Debugging Malware
☆30Updated last year
Alternatives and similar repositories for REDM:
Users that are interested in REDM are comparing it to the libraries listed below
- Get-PDInvokeImports is tool (PowerShell module) which is able to perform automatic detection of P/Invoke, Dynamic P/Invoke and D/Invoke u…☆53Updated 2 years ago
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆36Updated 4 months ago
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- ☆25Updated 2 months ago
- A collection of Tools and Rules for decoding Brute Ratel C4 badgers☆62Updated 2 years ago
- Repo containing my public talks☆22Updated last year
- ☆71Updated 2 years ago
- Yara Rules for Modern Malware☆73Updated 10 months ago
- General malware analysis stuff☆36Updated 5 months ago
- ☆32Updated 2 years ago
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆53Updated 2 years ago
- MITRE TTPs derived from Conti's leaked playbooks from XSS.IS☆35Updated 3 years ago
- A proof-of-concept re-assembler for reverse VNC traffic.☆25Updated last year
- Tools helpful for malware analysis☆22Updated 5 months ago
- Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation☆30Updated 2 years ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- ☆45Updated last year
- ☆22Updated 8 months ago
- Small visualizator for PE files☆67Updated last year
- Static Decryptor for IcedID Malware☆18Updated 2 years ago
- This repo hosts a poc of how to execute F# code within an unmanaged process☆66Updated 7 months ago
- GhostLoader - AppDomainManager - Injection - 攻壳机动队☆52Updated 4 years ago
- API Hammering with C++20☆44Updated 2 years ago
- Malware Samples that could be used for teaching students about malware analysis.☆52Updated 9 months ago
- The repository accompanying the Buer Emulation workshop☆24Updated 3 years ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆51Updated 8 months ago
- Read ETW Provider events. Inspired by ETWExplorer by Pavel Yosifovich☆14Updated 7 months ago
- Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2☆29Updated last year
- Compile shellcode into an exe file from Windows or Linux.☆60Updated 3 years ago
- My Malware Analysis Reports☆19Updated 2 years ago