bridgeythegeek / ndispktscanLinks
NDISPktScan is a plugin for the Volatility Framework. It parses the Ethernet packets stored by ndis.sys in Windows kernel space memory.
☆12Updated 9 years ago
Alternatives and similar repositories for ndispktscan
Users that are interested in ndispktscan are comparing it to the libraries listed below
Sorting:
- Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research☆53Updated 7 years ago
- Recover event log entries from an image by heurisitically looking for record structures.☆27Updated 10 years ago
- Volatility Framework plugin to detect various types of hooks as performed by banking Trojans☆41Updated 6 years ago
- Resolves DLL API entrypoints for a process w/ remote query capabilities.☆56Updated 8 years ago
- Yaras Random☆22Updated 6 years ago
- a collection of yara rules for binary analysis☆24Updated 8 years ago
- r2yara - Module for Yara using radare2 information☆36Updated 2 years ago
- Print the strings of encoded printable characters in files☆12Updated 10 years ago
- Code for the DIMVA 2018 paper: "MemScrimper: Time- and Space-Efficient Storage of Malware Sandbox Memory Dumps"☆27Updated 6 years ago
- Plugins for the Viper Framework☆14Updated 6 years ago
- My manual analysis of malware families☆13Updated 8 years ago
- Scripts targeting specific families☆13Updated 8 years ago
- Analysis PE file or Shellcode☆50Updated 9 years ago
- This script is used for extracting DDE in docx and xlsx☆12Updated 7 years ago
- ☆43Updated 7 years ago
- ☆24Updated 6 years ago
- Rekall Memory Forensic Framework☆33Updated 6 years ago
- Portable utility to check if a machine has been infected by Shamoon2☆15Updated 8 years ago
- GSAudit at Symantec, ExeAudit at RIM, RECX Binary Assurance for Windows at Recx etc. - core library now WinBinaryAudit☆24Updated 10 years ago
- Handy scripts to speed up malware analysis☆35Updated 2 years ago
- ☆35Updated 7 years ago
- Script to parse Process Monitor XML log file, and give you a summary report.☆23Updated 9 years ago
- ☆10Updated 7 years ago
- Linux-KVM with rVMI extensions☆22Updated 8 years ago
- Malware analyses and helpful scripts☆29Updated 3 years ago
- simple plugin to detect shellcode on Bro IDS with Unicorn☆33Updated 8 years ago
- Network detector for Winnti malware☆20Updated 7 years ago
- ☆15Updated 4 years ago
- Pcaps for PeddleCheap and implant communication + script for interpreting and decrypting pcaps.☆16Updated 7 years ago
- ☆32Updated last year