badhive / alca
Rule Engine for Dynamic Malware Analysis and Research
☆23Updated 3 weeks ago
Alternatives and similar repositories for alca:
Users that are interested in alca are comparing it to the libraries listed below
- ☆29Updated 2 months ago
- ☆45Updated last month
- An improved version of Patch Guard that I implemented, that includes integrity checks and other protection mechanisms I added.☆62Updated last month
- ☆25Updated 6 months ago
- ☆54Updated 2 weeks ago
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆62Updated 3 weeks ago
- Report and exploit of CVE-2024-21305.☆34Updated last year
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆35Updated last year
- Dll injection through code page id modification in registry. Based on jonas lykk research☆17Updated 2 years ago
- ☆30Updated 5 months ago
- ☆24Updated last year
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆46Updated last week
- All LLVM binaries scrambled with SigBreaker and used to test against llvm-lit☆14Updated 3 weeks ago
- "Service-less" driver loading☆154Updated 5 months ago
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆76Updated last year
- Callstack spoofing using a VEH because VEH all the things.☆21Updated last month
- Finding Truth in the Shadows☆92Updated 2 years ago
- Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussio…☆75Updated last week
- call gates as stable comunication channel for NT x86 and Linux x86_64☆31Updated last year
- Exploiting the KsecDD Windows driver through Server Silos☆70Updated 6 months ago
- Intelligent Malware that takes screenshots for entire monitors and exfiltrate them through Trusted Channel Slack to the C2 server that's …☆29Updated this week
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆36Updated 2 months ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆109Updated 8 months ago
- Aplos an extremely simple fuzzer for Windows binaries.☆68Updated 2 months ago
- A more reliable way of resolving syscall numbers in Windows☆49Updated last year
- Mentally ill EtwTi parser☆36Updated last month
- A few examples of how to trap virtual memory access on Windows.☆30Updated 4 months ago
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆26Updated last year
- A set of LLVM and GCC based plugins that perform code obfuscation.☆123Updated 2 months ago
- Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)☆100Updated last year